Spam signups, bot clicks, or deliverability trouble? How to tell what's actually going on
Hey community,
"Spam problem" can mean a few very different things.
Maybe your profile count suddenly jumped. Maybe your click rate looks suspiciously good. Maybe clicks are higher than opens. Maybe customers are saying your emails landed in spam. Those issues can feel related when you're staring at a dashboard, but they usually have different causes and different fixes.
Here's a symptom-led way to diagnose what's happening before you start panic-changing things.
Start with what changed
Use the first clue you noticed to pick your path:
| What you're seeing | Most likely issue | First place to check |
|---|---|---|
| A sudden surge of strange new profiles | list bombing or bot signups | Signup source, form activity, and list-growth timing |
| Repeated fake-looking form submissions | Signup form abuse | The form, checkout source, opt-in settings, and shared profile patterns |
| Click rate spikes without more orders or site sessions | bot clicks | Clicked Email/SMS metrics and bot-click filters |
| Clicks are higher than opens | Security scanners or link previews | Bot-click reporting settings and click behavior by domain |
| Bounces, complaints, or low opens increase | List quality or sender reputation | Deliverability Hub, campaign trends, and mailbox-provider patterns |
| Test emails aren't received or messages are rejected | Authentication or domain setup | branded sending domain, SPF, DKIM, and DMARC |
| SMS messages fail or SMS clicks look inflated | Carrier filtering or automated link previews | SMS failure reasons, message content, consent records, and bot-click reporting |
The goal is not to solve every deliverability mystery in one sitting. It's to avoid applying the wrong fix to the wrong problem.
1. Are fake people joining your list?
This is the path to investigate when you see a large number of signups in a short window, patterned email addresses, gibberish names, unusual locations, or new profiles with no meaningful site behavior.
I’ve seen people in the community describe this as "my list suddenly grew by hundreds of people" or "a bot keeps joining my email list." That points toward bot signups or list bombing: fake or unauthorized submissions through a form, checkout page, or subscribe source.
Start here:
- Identify the affected form, page, integration, or checkout source.
- Look for shared patterns: timing, domain, location, first name, last name, source, or profile property.
- Pause sends to the suspicious group while you investigate.
- Build a segment around the timing and shared characteristics so you can keep the group out of campaigns and flows if needed.
- Review the list's double opt-in setup and any protections available on the form.
A few things I'd avoid: don't assume every email address with a plus sign is fake, don't delete a large group based only on "looks weird," and don't let suspicious signups qualify for welcome flows or engagement segments just because they triggered an event.
If you're seeing repeated submissions from one source, it's also worth checking whether list bombing protection may already be filtering some activity.
2. Did your clicks suddenly become too good to be true?
A suspiciously high click rate can be a real dopamine hit. Then you compare it to purchases, sessions, or replies and the numbers start side-eyeing you.
Bot clicks happen when inbox security tools, mailbox providers, corporate filters, mobile carriers, or link-preview tools follow links to check whether they're safe. The click is real in the sense that a link was followed, but it may not represent a person intentionally clicking.
Common signs:
- One profile clicks every link almost immediately.
- Click rates spike, but conversions don't move.
- Your click rate is higher than your open rate.
- Activity is concentrated among government, education, corporate, or security-heavy domains.
- SMS clicks increase without a matching lift in purchases or sessions.
In Klaviyo, check the clicked email metric and filter for bot-click behavior. Also review whether bot clicks are included or excluded from reporting and attribution, especially if your team recently changed those settings.
For segmentation and automation, I'd be careful about treating one click as strong purchase intent. A click plus a human behavior, like viewed product, added to cart, placed order, or replied, is much sturdier ground.
3. Are real subscribers marking your emails as spam?
This is a different issue from bots. A spam complaint is a human reputation signal, and it deserves a different kind of audit.
Look at the basics first:
- Did subscribers knowingly opt in?
- Are you sending what the form promised?
- Has frequency increased recently?
- Are campaigns going to inactive profiles?
- Is the unsubscribe option easy to find?
- Did an import, giveaway, or promotion introduce lower-intent subscribers?
Then look at the health signals together: complaint rate, hard bounce rate, unsubscribe rate, open and click trends by mailbox provider, domain reputation, and rejection codes.
If a chunk of your campaigns are landing in spam filters, the fix usually isn't swapping out "free" for "complimentary" in your subject line. Start with consent, engagement, authentication, and send quality. Inbox providers care a lot more about whether people want your mail than whether your copy passed a superstition checklist.
4. Are messages being filtered or rejected?
When emails are rejected or quietly disappear, check authentication before you start diagnosing content.
- SPF helps show which systems are allowed to send for your domain.
- DKIM helps show the message has a valid signature.
- DMARC tells receiving inboxes what to do when authentication or alignment fails.
- A branded sending domain helps inboxes connect your messages back to your brand.
For SMS, separate "a bot clicked my link" from "a carrier filtered my message." Carrier filtering can relate to sender registration, consent, opt-out handling, message content, link reputation, or frequency. SMS bot clicks, meanwhile, may come from automated link previews or safety checks.
Same dashboard symptom, different plumbing.
Quick prevention checklist
Before collecting consent:
- Protect forms and checkout pages.
- Use the right opt-in method for the risk level.
- Set clear expectations about content and frequency.
- Keep SMS consent clean and documented.
Before sending:
- Target engaged, properly consented audiences.
- Check authentication and branded sending setup.
- Review complaint and bounce trends.
- Decide how bot clicks should be handled in reporting and attribution.
After sending:
- Watch for sudden changes in profile growth or engagement metrics.
- Compare clicks against conversions and site behavior.
- Investigate mailbox-provider or carrier-specific failures.
- Document odd incidents so your team recognizes the pattern next time.
When to contact Support
Bring in Support when the issue is moving fast, unclear, or affecting delivery at scale. A few good triggers:
- Thousands of unexpected profiles appear quickly.
- You can't identify where the signups came from.
- A sender domain is being rejected or appears blocklisted.
- Authentication-related rejection codes show up.
- SMS delivery failures suddenly increase across multiple campaigns.
- Suspicious activity continues after you secure the form or source.
A good rule of thumb: diagnose by symptom, then act by evidence. Your profile count, click rate, spam complaints, and bounce codes are telling different parts of the story. Read them together before you make a big list decision.
