Your campaign sent. Your open rate tells a partial story. But what about the contacts who never saw the email at all?

Most Canadian small businesses track opens and clicks. Very few track whether their emails are reaching the inbox in the first place. Those are different metrics — and the gap between them is wider than most business owners realise.

15–20%
of commercial emails in Canada never reach the inbox — for a list of 10,000 contacts, that's up to 2,000 people who wanted your emails and didn't receive them.
Source: State of Email Marketing in Canada 2026, Cyberimpact [1]

This isn't a content problem. It's a system problem. And it's fixable — but only after you know where the failure is happening.


Why Canadian SMBs Face a Dual Compliance Challenge

Most deliverability guides are written for the US or UK market. Canadian businesses operate under an additional layer: CASL — Canada's Anti-Spam Legislation — which is one of the strictest email consent laws in the world.[2]

The CRTC, which has primary enforcement responsibility under CASL, has issued over $3.2 million in administrative monetary penalties since the legislation came into force in 2014.[3] Three government agencies share enforcement: the CRTC handles commercial electronic messages, the Competition Bureau handles misleading commercial practices, and the Office of the Privacy Commissioner handles address harvesting and spyware.[4]

⚠️ CASL Penalty Range — CRTC Official Source

Administrative monetary penalties under CASL reach $1 million per violation for individuals and $10 million per violation for corporations. Everyday SMB settlements in 2025 landed between $5,000 and $250,000. Directors of corporations who authorised violations may be held personally liable.[5]

The connection between CASL compliance and deliverability is direct: CASL's consent requirements push senders toward permission-based, engaged lists that inbox providers reward. Sending only to contacts who genuinely consented reduces spam complaints, improves engagement, and strengthens sender reputation — all of which improve inbox placement.


The Four-Part Audit: What to Check and in What Order

Four-part email deliverability audit process for Canadian small businesses: authentication, CASL compliance, complaint rate monitoring, and list hygiene
1 Critical
Email Authentication — SPF, DKIM, and DMARC with Alignment

The foundation. Without passing authentication, inbox providers treat your mail as suspicious regardless of content or list quality. Check that all three records are present and that DKIM alignment is confirmed — the signing domain must match your visible From: address. Verify DMARC has a rua= reporting tag so you receive data when something fails. A DMARC policy at p=none satisfies minimum requirements but enforces nothing; the target for serious senders is p=quarantine or p=reject.

2 Critical for Canada
CASL Consent Compliance

Verify consent documentation for every contact segment. Express consent requires a clear opt-in checkbox, a form that identifies your business, and a description of what subscribers will receive. Implied consent from a business relationship lasts two years from the last transaction — an inquiry grants only six months. Both must be tracked with expiry dates. Confirm double opt-in is enabled in your ESP and that your audience export shows populated OPTIN_TIME and OPTIN_IP fields — this is your documentation if the CRTC asks. Check that consent checkboxes are unchecked by default; pre-ticked boxes are a CASL violation.

3 Required — Gmail / Yahoo / Microsoft
Spam Complaint Rate

Set up Google Postmaster Tools for your sending domain if you haven't already. It's free and shows domain reputation, IP reputation, spam complaint rate, and delivery errors directly from Gmail's infrastructure. The working ceiling for stable inbox placement is 0.10%. Enforcement begins at 0.30% — above that, Gmail throttles sending and holds recovery until the rate stays below 0.10% for seven consecutive days. Nearly 40% of Canadian unsubscribers cite "never subscribed" as their reason — reinforcing that consent gaps directly drive complaint rates.

4 Ongoing Maintenance
List Hygiene

Remove hard bounces after every campaign — they're permanent delivery failures that damage sender reputation if left in place. Suppress contacts with no engagement (no open or click in 12 months) before large sends rather than broadcasting to them. Validate email syntax on all manual imports. Confirm RFC 8058 one-click unsubscribe headers are present in all marketing email — required by Gmail and Yahoo — and that unsubscribe requests are processed within two days. Roughly 30% of bulk senders are still missing one-click unsubscribe two years after the February 2024 deadline.

Google Postmaster Tools domain reputation dashboard showing healthy email deliverability metrics for a Canadian business after a deliverability audit

What the Audit Reveals in Practice

Most Canadian SMB audits surface the same patterns. Authentication is usually partially correct — SPF and DKIM are present, but DMARC is at p=none with no reporting tag, which means failures are invisible. CASL consent documentation exists for new contacts but is missing for contacts imported before the business adopted proper opt-in practices. Complaint rate is unknown because Google Postmaster Tools was never set up.

The list hygiene situation is typically the most time-consuming to fix. Contacts accumulated over years often include hard bounces that were never removed, imported addresses with no consent documentation, and large segments of unengaged contacts who haven't opened an email in over a year. Sending to all of them without segmentation produces complaint rates that compound over time.

The fix order matters. Authentication first — a broken SPF or misaligned DKIM record makes everything else irrelevant. CASL compliance second — not because deliverability depends on it directly, but because a compliance gap that the CRTC finds costs more than the cost of fixing it now. Complaint rate monitoring third — you need visibility before you can manage. List hygiene last, because it only produces reliable signal once authentication is clean and monitoring is in place.


Key Takeaways

  • 15–20% of commercial emails in Canada never reach the inbox — the gap between sending and arriving is wider than most SMBs realise.
  • CASL compliance and deliverability are connected: proper consent practices produce engaged lists that inbox providers reward with better placement.
  • CRTC CASL penalties reach $1M per violation for individuals — documentation is not optional.
  • Audit in order: authentication → CASL compliance → complaint rate monitoring → list hygiene.
  • Google Postmaster Tools is free and essential — if it's not set up, you're managing deliverability without instrumentation.
  • Implied consent from a business relationship expires in two years; from an inquiry, six months. Both must be tracked.
  • Nearly 40% of Canadian unsubscribers say they never subscribed — a CASL consent gap that directly drives complaint rates.

Frequently Asked Questions

A CASL-compliant deliverability audit covers four areas: email authentication (SPF, DKIM, DMARC with alignment), CASL consent documentation (express vs implied consent, expiry tracking, double opt-in setup), spam complaint rate monitoring via Google Postmaster Tools, and list hygiene (hard bounces, unengaged contacts, import validation, one-click unsubscribe headers).
According to the State of Email Marketing in Canada 2026 by Cyberimpact, an estimated 15 to 20 percent of commercial emails in Canada never reach the inbox. A healthy inbox placement rate is generally considered 95 percent or above. The gap is primarily driven by authentication failures, high complaint rates, and non-compliant sending practices.
Under CASL, administrative monetary penalties can reach $1 million per violation for individuals and $10 million per violation for corporations, as confirmed by the CRTC's FAQ. The CRTC has issued over $3.2 million in penalties since 2014. Three agencies share enforcement responsibility: the CRTC (commercial electronic messages), the Competition Bureau (misleading practices), and the Office of the Privacy Commissioner (address harvesting).
Implied consent from an existing business relationship (purchase, contract, or membership) lasts two years from the last transaction or interaction. Implied consent from an inquiry or application lasts only six months. Both must be tracked with expiry dates, and re-consent automation must be built to contact the person before expiry — once implied consent expires, you no longer have the authority to send any commercial message to that contact.