What content filters actually weigh
The widespread idea that there is a list of forbidden words is misleading. What gets scored is an interplay:
- Linked domains. By far the strongest single factor. If a domain linked in the body is on a URI blacklist, the whole message falls — even when your own domain is spotless. Link shorteners and tracking domains shared with many other senders are especially exposed.
- Image-to-text ratio. A message consisting almost entirely of one embedded graphic is a classic evasion pattern and is scored accordingly.
- Divergence between link text and link target. A visible
yourdomain.compointing at a foreign host is the basic pattern of phishing. - A missing or empty text part. HTML-only mail without a
text/plainalternative reads as machine-generated. - Attachment types. Executable formats, macro-capable Office files and password-protected archives trigger regardless of the text.
Narrow it down rather than guess
The quickest route is elimination: send the same message once without attachments, once without links and once as plain text. Whichever variant gets through names the cause more precisely than any hypothesis.
If the message appears for a single recipient only, look at their filter — Microsoft 365 and Google Workspace let administrators define their own rules that are stricter than the defaults. The suffix “by Content Filtering” frequently points at exactly that.
What does not help here
SPF, DKIM and DMARC do not solve this problem. They prove the mail genuinely came from you — they say nothing about whether its content is wanted. A perfectly authenticated message carrying a listed link domain still gets rejected, and that is by design.