Brand operations

Diagnosing a deteriorating email programme: signals, fix order and what replaces open rate

Open rate and a Postmaster reputation badge no longer tell you whether a Shopify Klaviyo account is leaking. Read the signals that survived privacy changes, then fix integration, cart timing, segmentation and hygiene in that evidence order.

Four-rung ladder against a frosted mail drum: copper wiring, clockwork cart, click-trace sieve and charcoal filter, with false pixel flares on the drum skin.

Key takeaways

Do not wait for email revenue to fall, and do not treat open rate as the engagement gate. Read weekly: complaint-rate trend against Google and Yahoo's 0.3% ceiling and Google's tighter 0.1% target, authentication pass rate, delivery errors and deferrals, compliance status, click-recency share of the send-eligible list, and revenue per send. Google Postmaster Tools v2 is reported as having removed the on-screen reputation score, so health has to be inferred from those remaining views, and a clean spam rate can be a symptom of filtering rather than inbox health. Fix a leaking Klaviyo account in measurement order: (1) Shopify integration and event completeness, (2) Added to Cart versus Started Checkout as separate machines, (3) campaign eligibility rebuilt on click, purchase and on-site recency, (4) Never Engaged sunset and suppression as a standing exclusion, not a one-off clean. Demote open rate to a contaminated, domain-level diagnostic; do not use it in KPIs, flow logic or engaged segments, and do not replace it with click-to-open rate. Express marketing consent still governs who may be mailed; open-tracking consent, including French and Italian pixel rules, only governs whether opens are recorded.

Can we still trust the email programme if revenue has not moved?

The operator decision is not whether Klaviyo still 'works'. It is whether this week's campaigns and flows should still go to the same list, on the same domain, using the same definition of engaged, while open rate looks respectable and email contribution is only slightly softer.

That is an inventory and cash-flow decision dressed as a reporting debate. Paid media is still buying sessions. Inventory is still being committed against expected conversion. Cart and checkout recovery are still assumed to catch what the site does not. If the inbox layer is decaying, those assumptions fail before the revenue line makes the failure obvious.

Two dashboards used to make the call feel easy. Open rate told you whether people were looking. Google Postmaster Tools showed a domain reputation score. Both have degraded as instruments. Apple Mail Privacy Protection preloads images on delivery, which fires the tracking pixel even when the message is never opened, so open rate inflates. That is not an 'iOS segment' problem. It applies to any address, including Gmail, Yahoo or Hotmail, if the inbox is opened in Apple Mail. Delivery, bounce and click metrics are not affected in the same way.

Separately, practitioner write-ups of Google Postmaster Tools v2 state that the visible reputation score has gone. Gmail still uses reputation internally, but senders are told to assess health through spam complaint rate, authentication, delivery errors and compliance status. Other 2026-dated guides still tell operators to watch a High-to-Medium reputation shift. Treat that disagreement as a warning. If the weekly ritual still starts with a reputation badge, you may be reading a view that is no longer there, or a secondary article that has not caught up.

Diagnosis has to move to signals that survived those changes. Otherwise the brand keeps sending, keeps buying traffic, and keeps treating a measurement failure as a creative problem.

What does a leaking Klaviyo account cost across cash flow and the wider operation?

A leaking email account taxes the rest of the operation. Abandoned-cart and checkout flows are the cheap recovery layer after acquisition. If Started Checkout and Added to Cart events are late, missing, or quietly suppressed by Shopify's native abandoned emails and tight entry filters, paid clicks convert on site and then vanish from the lifecycle machine. You do not need a published lead time versus revenue to see the commercial shape: contribution that should have arrived as flow revenue has to be re-bought in ads, or it does not arrive at all, and stock sits against a conversion path that is partly dark.

That is why the email diagnosis belongs next to what to check before increasing Meta ad spend. Scaling spend into a store whose recovery mail is not firing is a margin decision, not a media one. The same leak also distorts blended media efficiency: MER looks worse because email stopped finishing the job, and the instinct is to chase the ad account.

Bulk-sender rules add a second cost, on the domain rather than on this week's campaign. Secondary guides on Gmail and Yahoo requirements put a 0.3% complaint ceiling on bulk senders, with Google publishing a tighter 0.1% target. Crossing 0.3% is described as making a sender ineligible for delivery mitigation. Enforcement on Gmail is described as having moved, in November 2025, from temporary 4.7.x rate-limiting toward permanent 5.7.x rejections, with the numeric thresholds unchanged. Microsoft's parallel bar, from May 2025, is that senders of more than 5,000 emails a day to Outlook.com, Hotmail and Live must pass SPF, DKIM and DMARC, with DMARC at least p=none aligned to SPF or DKIM. None of that is a subject-line brief. It is a constraint on how large a list you can still mail without damaging the domain every future campaign depends on.

The cost, then, is not a tidy percentage against last year's email dashboard. Cash conversion arrives late. Paid media is asked to replace a flow that never entered, against a conversion path that is partly dark, while the complaint rate can close the inbox for the next send.

Why do open rate, Postmaster reputation and a one-off list clean fail us?

The usual responses are tidy and insufficient.

Reporting harder on open rate, or on click-to-open rate, does not restore a clean engagement gate. Click-to-open still uses the contaminated open as its denominator. Open rate can still be compared directionally, inside the same audience, and it can still be used as a domain-level diagnostic. It cannot decide who is safe to mail, and it cannot tell you whether a flow underperformed because nobody clicked or because Apple Mail preloaded the pixel.

Watching Postmaster 'reputation' as the early-warning light collides with the v2 change already noted. Even where spam rate is available, it is a blunt instrument. Practitioner guidance notes that the rate is aggregated at the root sending domain, so it cannot identify which segment, campaign or subdomain produced the complaints. A clean spam rate next to suspected poor placement is not a contradiction: filtering can keep complaints off the dashboard because the mail never reached the people who would have marked it. Confirming placement then needs seed testing against a real panel, which Postmaster does not provide.

A one-off list clean is the other false ending. Klaviyo's help centre describes building a Never Engaged segment (manually, or generated from the Action Center under Analytics > Deliverability), sending one final re-engagement attempt through a sunset flow, then suppressing non-responders, including via bulk suppression of current members. It also states the line most operators skip: unengaged segments must continue to be excluded from campaigns. Hygiene that is run once and forgotten re-accumulates the same unengaged volume. It also cannot repair a broken event stream. If Added to Cart is not registering, cleaning the list will not make the cart flow fire.

Agency checklists already name a four-part order: integration gaps, abandoned-cart timing, under-built segmentation, then list hygiene. Restating that sequence is not the gap. The gap is that operators still start at the end, hygiene and open rate, because those screens are familiar, while the two screens that used to justify starting there have been contaminated or withdrawn.

Should the fix order follow what we can still measure?

The useful reframe is this: fix the layer whose data you can still trust, in the order that makes the next layer measurable.

If Shopify events are incomplete, flow entry rate is not a performance metric. It is a partial count. If cart and checkout are treated as one machine, you cannot tell whether timing, payload or trigger is wrong. If 'engaged' is still defined on opens, Mail Privacy Protection recruits people who never looked at the mail into the safe-to-send audience. If you then suppress on that definition, you delete on a fiction.

So the sequence is not a taste in project management. It is an evidence ladder:

  1. Event completeness, integration and registration lag
  2. Flow entry rate, cart and checkout as separate triggers
  3. Click-recency distribution, the send-eligibility rule
  4. Complaint and delivery-error trend, hygiene as a standing process

Each rung is a metric that the privacy changes did not poison in the same way as opens. Open rate is demoted from KPI to a contaminated diagnostic, used only for like-for-like, domain-level comparison.

That is also how this differs from audit-guide versions of the same four steps. The order is justified by what can still be measured honestly after Postmaster reputation ceased to be a reliable on-screen score and after Mail Privacy Protection broke the open pixel, not by a claimed revenue share from a private audit set.

In what order should we fix a leaking Klaviyo account?

What do Google and Yahoo bulk-sender rules require in practice?

Before the ladder, the floor. For Gmail and Yahoo, the non-negotiables in the secondary guides are authentication (SPF, DKIM, DMARC), a one-click unsubscribe path, and the complaint ceiling already noted. Google is described as accepting only RFC 8058 List-Unsubscribe headers; Yahoo also accepts a mailto fallback. Microsoft, as above, does not mandate RFC 8058 one-click unsubscribe in the same way, but does require authentication once daily volume to its consumer inboxes exceeds 5,000.

Treat 0.3% as a ceiling, not a cliff. Coverage that treats the number as a binary fail is weaker than Google's own FAQ as reported, which describes a graduated impact that begins building before the threshold. One secondary guide stresses that the rates are recalculated daily, so a single bad campaign can move the number. Another tells practitioners to treat 0.10% as a warning and rates approaching 0.30% as systemically serious, read as rolling averages over days or weeks. Those two operationalisations cannot both be run as written. Until you have checked Google's current FAQ yourself, use both as bounds: do not wait for a 0.3% 'fail', and do not over-react to a single-day print without a trend.

Authentication breaks are worth reading before placement. Postmaster v2 commentary says an authentication failure shows up before placement collapses, and that rising delivery errors are an early symptom of list decay or a blocklisting event. The dashboard is also described as reporting on the primary domain, not subdomains, even though subdomain data informs Gmail's decisions. If you send on a subdomain and stare at the root, you are looking at an aggregate.

Which early-warning signals still work?

A weekly panel that does not depend on opens or a reputation badge:

  • Complaint-rate trend against the 0.1% and 0.3% bands, with the measurement-window disagreement in mind.
  • Authentication pass rate.
  • Delivery errors and deferrals.
  • Compliance status, unsubscribe headers and authentication alignment.
  • Click-recency share of the mail-able list.
  • Revenue per send.

Do not infer how many days these lead a revenue decline. No source in this set measures that lead time, and there is no measured lead time from complaint-rate or delivery-error movement to email revenue on branded versus shared sending domains either. In practice those signals would still be treated as leading, especially on a branded domain, without waiting for revenue to confirm a delivery problem. Klaviyo complaint data and Postmaster are not interchangeable. Read them because they are still honest, not because they are a forecast.

A clean complaint rate with falling email contribution is a diagnostic, not a reassurance. Filtering can hide the people who would have complained. The metric also cannot isolate the guilty segment. That is when seed testing can still help, and when you stop using Postmaster as a campaign debugger. A seed panel is not a cut trigger on its own when Postmaster is clean. Cut volume only when a domain-level panel agrees with complaint or delivery movement, not when a seed looks ugly by itself. Placement feel is not enough.

Step one: is the integration complete enough to trust any other number?

Start under Integrations > Shopify: the store should show as Connected, and behavioural event tracking should be enabled. Then check Analytics > Metrics for Started Checkout and Added to Cart in the last 24 hours, at volumes that are even roughly plausible against site traffic. If those metrics are thin relative to sessions, every downstream flow rate is lying.

On a recent profile, compare the event's occurrence time with Klaviyo's registration time. If events are delayed by many hours, metric-triggered flows can skip them. Theme edits, app changes and silent pixel failure produce exactly this pattern. Shopify's native abandoned emails and strict entry filters can also suppress flow entries without a 'broken flow' alert.

This is why integration comes first. You cannot judge which lifecycle flow to fix first if the trigger is not arriving. Creative, offer and delay tests on a dark event stream are theatre.

Step two: are cart and checkout timed as separate machines?

Started Checkout fires when someone enters checkout. Added to Cart fires earlier, before checkout is reached. They are separate flows, not branches of one flow. The dynamic product block in each pulls from different event data; a checkout block cannot be reused for cart. That is a build error, not a copy error.

Timing should follow intent stage, not a single default delay. Practitioner guidance, agency opinion, not a measured benchmark, suggests cart abandoners often need more touchpoints over a longer window, while checkout abandoners should be contacted faster, with a first email inside a short window after the event. Treat those timings as a hypothesis to test on click and conversion, not as a platform rule. Do not import another agency's default delay, or a discount ladder timed to 48 hours, as if it were evidence.

If entry volume is plausible and still low, audit suppression next: native Shopify abandoned mail, too-tight profile filters, and flows that require a product payload the event does not carry. Only then open the template.

Step three: what engagement gate replaces open rate?

The gate that still measures a human is click recency, combined with purchase recency and on-site recency, applied as the send-eligibility rule for campaigns. Bounce, delivery and click remain usable under Mail Privacy Protection. Send-time tests should use click rate as the success metric for the same reason.

Open-based 'engaged' segments now recruit Mail Privacy Protection ghosts, profiles whose pixel fired on preload, into the audience you have labelled safe. That is how a list looks engaged while complaint rate and click-recency quietly worsen.

Click-to-open rate is not a safe substitute: it keeps the contaminated open in the denominator. Revenue per send is the outcome line; click-and-purchase recency is the eligibility rule. No public source in this set gives an auditable D2C benchmark for the share of list that should pass that gate, or for the correct recency window. Set a window, hold it constant, and report the share that qualifies. Changing the window every week to make the chart look stable is another way of lying.

I do not have a locked click-recency window as send-eligibility. Common practice is a 60 to 90 day click window, not opens. I would lock it when the eligible list still covers the people who actually buy, and stop moving it every time the list looks small.

Useful for

  • Open rate can still be read directionally, like-for-like, inside the same audience
  • It can still sit beside clicks and complaints as a domain-level diagnostic

Watch for

  • Apple Mail image preload inflates opens for any address opened in Apple Mail
  • Open-based engaged segments recruit false engagement into the safe-to-send pool
  • Click-to-open inherits the same contaminated denominator
  • Open-tracking consent and account-level tracking toggles make the series structurally incomplete in some markets

Klaviyo still recommends emailing only profiles with express marketing consent, which is a deliverability posture as much as a legal one. That consent is not the same as open-tracking consent.

French CNIL guidance, and in some cases Italian Garante guidance, now requires prior, specific consent for tracking pixels in most marketing emails, separate from general marketing opt-in. That is regulatory commentary from Klaviyo and trade reporting, not legal advice, and the specific calendar deadlines are not restated here because they were not captured cleanly in the source pack.

Klaviyo has shipped controls: an account-level toggle under Settings > Email > Tracking that stops the platform recording opens across every email the account sends; and a per-recipient open-tracking consent status, separate from marketing consent, which can be set individually or in bulk via CSV, SFTP, data-warehouse sync or API. Opting out stops open recording immediately and going forward. A profile can still be mailed. Where account open tracking is on and a recipient has an explicit open-tracking value, Klaviyo shows a read-only Email open tracking row as Subscribed or Unsubscribed.

Garante guidance is reported as appearing to permit combined consent where processing purposes are identical, and requiring separate consent where purposes differ. Preserve that hedge rather than collapsing it into a single EU rule.

The operational consequence is larger than compliance. In affected cohorts, open data is opted out at source. Even without Apple Mail, the open rate is structurally incomplete. That is a second, independent reason the engagement gate cannot rest on opens.

For mixed UK and EU lists, keep one marketing programme and turn the open pixel off where pixel consent is missing. Do not split the list or rewrite historical opens. Pixel consent is not marketing consent. Judge the programme on clicks and revenue.

Step four: can hygiene be a one-off?

No. Build a Never Engaged segment. Send one final re-engagement attempt via a sunset flow. Suppress non-responders. Then keep excluding those unengaged cohorts from campaigns. The last step is the one that determines whether next month's complaint rate is the same argument again.

Hygiene last is not because it is unimportant. It is because suppressing on a broken event stream and an open-based segment deletes the wrong profiles and leaves the leak in place. Unengaged volume is a standing input to a D2C list, not a project with an end date.

What belongs on the weekly panel?

  1. Complaint-rate trend against the 0.1 per cent caution band and the 0.3 per cent ceiling, read as a trend not a single print
  2. Authentication pass rate plus delivery errors and deferrals
  3. Share of the mail-able list with a recent click, purchase or on-site session
  4. Revenue per send, with open rate retained only for directional domain-level comparison

Ban open rate from KPI dashboards, flow logic and engaged-segment definitions. Keep it in a footnote chart if you need a like-for-like directional read against last year on the same domain, and annotate it as contaminated.

Where does the public evidence stop?

Supported, from the sources above:

  • Complaint ceilings and Google's tighter 0.1% target, with graduated rather than purely binary impact, plus the November 2025 Gmail enforcement shift toward permanent rejections.
  • Authentication and unsubscribe requirements, including the Google versus Yahoo header difference and Microsoft's 5,000-a-day consumer-inbox bar.
  • Postmaster v2 described as removing the on-screen reputation score, with health read from spam rate, authentication, delivery errors and compliance, contested by guides that still narrate High, Medium and Low.
  • Mail Privacy Protection inflating opens via image preload, applying whenever Apple Mail is the client, leaving clicks, bounces and delivery intact.
  • Klaviyo first-party mechanics for Never Engaged, sunset, bulk suppress, ongoing exclusion, and the split between marketing consent and open-tracking consent.
  • The structural distinction between Added to Cart and Started Checkout, and the occurrence-versus-registration lag that skips metric-triggered flows.

Not supported, and not filled in:

  • How many days any of these signals move before revenue.
  • A benchmark distribution of click recency for D2C lists, or a defensible share of list to gate out.
  • Verified inbox-placement rates by compliance status.
  • Apple Mail's current share of opens from a primary, dated study.
  • How Klaviyo's own complaint reporting relates to Postmaster figures on shared versus branded sending domains.
  • Pixel-consent calendar dates.

Where another agency asserts the same four-part fix order with a revenue-share outcome attached, treat the sequence as prior art and the outcome as unaudited. The justification here is measurement reliability, not a private scoreboard. Filling the gaps with a generated answer would still be a guess; AI can organise evidence, it does not replace judgement about what is unproven.

What should change before the next campaign send?

Confirm Shopify is connected, behavioural events are on, and Started Checkout and Added to Cart fired in the last day at a volume that matches the store. On one recent profile, check occurrence time against registration time. Turn off native Shopify abandoned mail if it is double-suppressing Klaviyo. Rebuild campaign eligibility on click, purchase and on-site recency rather than opens. Exclude Never Engaged going forward, not as a clean-up project.

If complaint rate is climbing toward the published bands, stop arguing about subject lines and cut the unengaged volume. If authentication or delivery errors are rising, stop adding send volume until the domain is aligned. If the event stream is dark, do not 'optimise' the cart flow.

The next useful action is a smaller, better-gated send measured on clicks and cash, not a prettier open-rate slide.

Useful answers

Questions operators ask

Should we still report open rate at all?
Yes, but demoted. Retain it for like-for-like directional comparison inside the same audience, and as a domain-level diagnostic read beside clicks and complaints. Remove it from KPI dashboards, flow logic and engaged-segment definitions. Apple Mail Privacy Protection preloads images on delivery and inflates opens for any address opened in Apple Mail; delivery, bounce and click metrics are not affected in the same way. Click-to-open rate is not a safe replacement because it keeps the contaminated open as the denominator.
What replaces open rate as the engagement gate?
Click recency combined with purchase recency and on-site recency, applied as the send-eligibility rule for campaigns, with revenue per send as the outcome measure. No sourced D2C benchmark exists for the correct recency window or for the share of list that should qualify, so the window is an operator judgement that must then be held constant. Do not use click-to-open rate. Klaviyo still recommends mailing only profiles with express marketing consent; that is separate from open-tracking consent.
What complaint rate should we treat as the alarm level?
Secondary guides put a 0.3% ceiling on Gmail and Yahoo bulk senders, with Google publishing a tighter 0.1% target. Crossing 0.3% is described as making a sender ineligible for delivery mitigation, and impact is graduated rather than a single cliff. Sources disagree on the measurement window: one stresses daily recalculation, another tells operators to read 0.10% and 0.30% as rolling averages. Use both as bounds, do not wait for 0.3%, and do not treat a single-day print as a verdict, and check Google's current FAQ before operationalising either rule.
In what order should we fix a leaking Klaviyo account?
Integration and event completeness first, then cart and checkout timing as separate machines, then segmentation on a click-and-purchase gate, then hygiene as a standing exclusion. You cannot judge flow performance on a partial event stream, and you cannot define an engaged segment before the events that define engagement are arriving. Other agency guides already publish this sequence; the reason to keep the order is measurement reliability after opens and Postmaster reputation ceased to be honest on-screen diagnostics, not a private revenue-share claim.
How do we tell whether a flow underperforms because of data or because of content?
Confirm under Integrations > Shopify that the store is Connected and behavioural event tracking is enabled. Check Analytics > Metrics for Started Checkout and Added to Cart in the last 24 hours at volumes plausible for site traffic. On a recent profile, compare event occurrence time with Klaviyo registration time, multi-hour lag can cause metric-triggered flows to skip the event. Audit entry and exclusion filters and Shopify's native abandoned emails before touching creative.
Does open-tracking consent affect whether we can email someone?
No. Open-tracking consent is separate from marketing consent and controls only whether Klaviyo records opens, not whether the profile can receive messages. Account-level tracking can be switched off under Settings > Email > Tracking, and per-recipient open-tracking consent can be set in bulk. In France, and in some cases Italy, prior specific consent is required for tracking pixels in most marketing emails. The practical consequence is that open data becomes structurally incomplete, which is a further reason the engagement gate cannot rest on opens. That is not legal advice.

About the author

Eddie Cheng

Eddie Cheng founded Penang Media and co-owns VIBAe. He writes from the agency and brand sides of ecommerce growth, connecting paid acquisition with stock, margins, cash flow and contribution profit.

More from Eddie Cheng

The operating context

Growth from the agency and brand sides.

Eddie Cheng writes about profit-first ecommerce growth from both sides of the work: Penang Media, the performance agency he founded, and VIBAe, the footwear brand he co-owns. His articles connect paid acquisition with stock, margins, cash flow and the decisions that determine profitable growth.

About the publication