What Are CAT Header Values and Why Do They Matter in 2026?

You send an email. It lands in the spam folder. Or worse, it doesn’t land at all. You check the bounce report. The message says, “Failed to deliver.” But you didn’t get a human reason. Just a header: SPM, PHSH, HSPM, BULK. What do these even mean?

These are CAT header values—numeric scores assigned by Microsoft’s filtering systems in Exchange Online and Outlook. They’re not just metadata. They’re the output of a machine-learning model that evaluates your email’s content, sender behavior, and historical patterns to predict spam likelihood. Understanding them is no longer optional. It’s essential for maintaining inbox placement on Microsoft’s ecosystem in 2026.

Key takeaways

  • CAT header values like SPM, PHSH, HSPM, and BULK are machine-learning scores used by Microsoft to evaluate email spam risk in Exchange Online and Outlook.
  • These metrics assess content, sender behavior, and historical engagement to predict whether an email will be delivered to the inbox or marked as spam.
  • Monitoring and acting on these values helps maintain sender reputation and ensures reliable inbox placement across Microsoft’s email services.

What Does SPM Mean in CAT Headers?

SPM stands for Sender Policy Match. It’s a CAT header value that checks whether the sending domain’s SPF record allows the IP address used to send the email. A value of 1 means the IP passes SPF validation; 0 means it doesn’t, which signals a configuration issue and increases spam likelihood. This directly affects inbox placement and sender reputation.

How SPM Reflects SPF Alignment

SPM is tied directly to your domain’s SPF record. If the IP address sending the email is listed in the SPF record, SPM returns 1. This shows the sender is authorized. If the IP isn’t listed, or if the record is missing, SPM returns 0—meaning the email fails SPF, one of the most basic deliverability gates.

Let’s say you send from a dedicated IP not included in your SPF record. Even if your DKIM and DMARC are set up, SPM will flag as 0. That’s a red flag to receivers. SPF failures are common in poorly managed email systems and are frequently linked to deliverability drops.

Why SPM Matters for Deliverability

A zero SPM score doesn’t mean the email is spam, but it significantly raises the odds. Receiving servers see SPF failures as a sign of potential spoofing. This can trigger filtering, delayed delivery, or outright rejection.

According to RFC 7208, SPF is an industry-standard mechanism for verifying sender authorization. It’s a foundational layer in email validation—so much so that many receivers treat SPF alignment as a mandatory check. Poor SPF configuration is a top reason why emails end up in spam or get blocked.

Use tools like MailTester’s real-time verification API or bulk verification to spot domains with failing SPF (SPM = 0) before you send. Catching these issues early avoids wasted sends and protects sender reputation.

SPM isn’t just a score—it’s a diagnostic. If you’re seeing SPM=0 on outbound messages, check your SPF record for completeness, syntax errors, and IP inclusion. Tools like MXToolbox let you test SPF records in real time.

SPM is one of several CAT header signals. It works alongside DKIM and DMARC to build sender trust. But even when DMARC passes, a zero SPM can still sink delivery. It’s not optional. It’s expected.

What Is PHSH in CAT Headers?

PHSH, or Primary Host Sender History, is a metric in CAT headers that measures your sending domain’s past deliverability performance based on email engagement, bounce rates, and spam complaints. A low PHSH indicates poor historical behavior—high bounces, low opens, or frequent spam reports—increasing the odds your messages land in junk folders or get blocked entirely.

How PHSH Reflects Real Sending Behavior

PHSH isn’t just a guess—it’s built from real data. It tracks how your domain’s emails have performed over time: were they opened? Clicked? Marked as spam? If your past sends show high bounce rates or low engagement, PHSH drops. The lower the score, the more likely your next email is treated with suspicion by receiving servers.

For example, if your mailing list includes many inactive or invalid addresses, that inflates hard bounces and triggers a PHSH penalty. Similarly, if recipients consistently mark your messages as spam—even without your knowledge—your sender history takes a hit. This isn’t about the content alone; it’s about the signal your domain sends over time.

Why PHSH Matters for Deliverability

Receiving servers use PHSH as a trusted signal to decide whether to deliver an email to the inbox or quarantine it. A poor PHSH value can override strong content or authentication, especially for new or low-volume senders. Even if your email looks clean and passes SPF/DKIM, a weak sender history can still land you in spam filters.

Let’s be clear: a single poor campaign won’t break your PHSH overnight. But consistent low engagement or high bounce rates build up a reputation that lasts. This is why list hygiene and ongoing deliverability monitoring matter—especially when you’re sending at scale.

You can’t control how receiving servers interpret PHSH, but you can control your own data. Tools like MailTester’s bulk verification help you spot invalid or risky addresses before they hurt your sender reputation. By cleaning your list, you reduce bounces, improve engagement signals, and strengthen your long-term PHSH score.

Understanding PHSH helps you anticipate why emails fail. It’s not just about headers or protocols—it’s about consistent, responsible sending. The goal isn’t to game the system but to build credibility over time, which PHSH measures directly.

For a deeper test, try MailTester’s inbox placement to see how real inboxes respond to your messages. It checks not just deliverability, but how your domain is perceived across major providers like Gmail, Yahoo, and Outlook.

What Does HSPM Mean in CAT Headers?

HSPM stands for Host Sender Policy Match, a metric in CAT headers that checks whether your sending IP’s reverse DNS (PTR) record aligns with the domain you’re sending from. Microsoft’s spam filters flag a mismatch—resulting in an HSPM value of 0—as a red flag. If your PTR record doesn’t match your sending domain, it undermines sender reputation and hurts inbox placement. Properly configured PTR records are critical for passing Microsoft’s reputation checks.

How HSPM Works in Practice

When you send mail, Microsoft’s filtering system checks the PTR record of your sending IP against the domain in the "From" header. If they don’t match, HSPM drops to zero. This isn’t a minor detail—it’s a known signal in Microsoft’s anti-spam logic that can trigger filtering or rejection, especially for high-volume senders.

For example, if your IP resolves to mail.example.com but your email says [email protected], the HSPM check fails. Even if your SPF and DKIM are solid, a PTR mismatch can still harm deliverability. This is why infrastructure setup matters as much as email content and authentication.

Why PTR Configuration Matters

A matching PTR record proves you control both the IP and the domain. It reduces the risk of spoofing and aligns with established email hygiene standards. The absence of a proper PTR is commonly seen in compromised or poorly managed mail servers—behavior Microsoft’s filters treat with caution.

According to RFC 1918 and guidance from organizations like Spamhaus, consistent reverse DNS is one of the foundational checks for trusted outbound email. You don’t need a perfect signal across every system, but failing HSPM is a known trigger for reduced inbox placement.

Use tools like MailTester’s bulk verification to check your sending infrastructure at scale. It tests not just syntax, but real-world deliverability signals like HSPM, SPF, and DKIM—all across multiple inbox providers. The more you validate your sender setup before sending, the fewer surprises you'll face later.

Think of HSPM as a trust signal: a zero value suggests someone may be faking their origin. Fixing it isn’t just technical—it’s fundamental to maintaining sender reputation over time.

For automated integration, MailTester’s API checks HSPM and other CAT header values in real time. It’s especially useful for developers or platforms that generate thousands of sends per day.

What Is BULK in CAT Headers?

The BULK value in CAT headers indicates how Microsoft’s email filtering system interprets a message’s sending pattern. A score from 0 to 1 shows the likelihood that the email is part of a mass send—like a newsletter or campaign—rather than a personal or transactional message. Scores above 0.7 typically flag the message as high-volume, leading to stricter scrutiny unless the sender has strong engagement and reputation signals.

How BULK Is Calculated and Why It Matters

Microsoft's filtering system uses machine learning to assess sender behavior, domain history, and message content. A high BULK score doesn’t mean the message is spam—it just signals that the email is likely part of a large distribution. Mail servers, especially Microsoft’s Outlook and Hotmail, treat these messages with extra caution, especially if the sender hasn’t proven consistent engagement.

For example, a newsletter sent to 100,000 subscribers with low open rates and high complaint history will get a BULK score near 1.0. The system sees this as a classic bulk pattern and may push it to the junk folder or block it entirely. On the other hand, a transactional message like a password reset—sent once per user—typically scores near 0.0.

What to Do When You See a High BULK Score

If you’re seeing BULK values above 0.7 on your outbound emails, it’s a signal to improve your deliverability hygiene. High scores aren’t a verdict—they’re a warning flag. The first step? Verify your list quality. Sending to invalid, dormant, or fake addresses increases BULK signals and degrades sender reputation.

Let’s be clear: you can’t remove BULK from a header. But you can influence it. Clean your list, remove inactive subscribers, and ensure your messages are relevant. Tools like MailTester’s bulk verification check for invalid, catch-all, or risky addresses before sending—catching the root cause of high BULK before it ever reaches a mailbox.

Microsoft’s approach is consistent across its filtering stack. As outlined in the Microsoft Identity Protection documentation, behavioral signals like volume, timing, and recipient engagement are key in risk assessment. The same principles apply to inbound mail flow and sender reputation scoring.

So if your BULK score is rising, consider whether your campaigns are engaging real users. A high score isn’t failure—it’s data. Use it to refine your list, timing, and content. The goal isn’t to hide your volume—it’s to prove you send to people who want your emails.

How Do CAT Headers Impact Inbox Placement?

Microsoft uses CAT header values—SPM, PHSH, HSPM, and BULK—as part of its spam scoring system. Low SPM (0), high BULK (1), or poor PHSH/HSPM scores can trigger filtering even if SPF and DKIM pass. Deliverability isn’t just about authentication; it’s about sender reputation, historical behavior, and how Microsoft interprets your sending pattern over time.

SPM, BULK, and the Spam Score Threshold

SPM (Sender Policy Match) and BULK are binary signals: SPM=0 means no SPF alignment, which harms your score. BULK=1 means the message was sent in bulk, which is normal for marketing—but it increases scrutiny. Even if SPF and DKIM are valid, a BULK=1 message with SPM=0 or poor HSPM (High Sender Policy Match) can still be flagged. Microsoft’s systems weight these signals alongside engagement data and historical patterns. A strong sender reputation can offset weak CAT headers, but not always.

Let’s be clear: passing SPF and DKIM is just the baseline. Microsoft’s filters look past the technical check to how you’ve behaved recently. If your emails consistently arrive from unknown sources, have low engagement, or come from IPs with a history of abuse, CAT header signals like high BULK or low SPM amplify the risk.

PHSH and HSPM: What They Actually Measure

PHSH (Policy Host Sender History) and HSPM (High Sender Policy Match) reflect how closely your sending behavior aligns with known patterns of good senders. PHSH compares your sending IP to others with similar sending volumes. HSPM measures if your domain has strong alignment across SPF, DKIM, and DMARC records. Poor HSPM often signals inconsistency—like switching IPs mid-campaign or using multiple domains with weak policy setups.

If PHSH is low or HSPM is missing, Microsoft sees you as unpredictable. It’s not just about passing checks today. It’s about being consistent over time. This is why a strong sender reputation—built through consistent volume, engagement, and low abuse reports—matters more than any single header value.

Even if your messages pass all technical checks, a weak PHSH or HSPM can still hurt inbox placement. This is where tools like MailTester’s inbox placement testing help. You can simulate delivery across major email providers and see how your CAT headers and reputation stack up in real-world conditions.

For teams managing large lists, bulk list verification catches invalid, disposable, or risky addresses before they harm your sender reputation. You can also use the real-time verification API to clean data on the fly, preventing poor CAT scores from accumulating.

To understand the full picture, Microsoft’s own documentation on sender authentication and spam filtering (via Microsoft Learn) confirms that multiple signals—authentication, behavior, reputation—are combined into a single spam score. You can’t outrun bad history, but you can manage it with clean data and consistent policies.

How to Verify If Your Emails Are Affected by CAT Headers

You can verify if your emails are affected by CAT headers by sending test messages through Microsoft’s infrastructure using a deliverability testing tool that provides real-time header analysis. Tools like MailTester simulate inbox placement and return full header data, including SPM, PHSH, HSPM, and BULK values—without requiring access to Exchange Online or internal admin tools.

Testing with Real Microsoft Infrastructure

Let’s be clear: CAT headers are set by Microsoft’s systems during email processing in Outlook and Microsoft 365. If you don’t have direct access to Exchange Online or the ability to monitor logs from large-scale email infrastructure, you can’t see these headers directly. That’s where inbox placement testing comes in.

MailTester sends your email through Microsoft’s real delivery paths and returns the full message header after processing. This includes the X-MS-Exchange-Organization-MessageDirection, X-MS-Exchange-Organization-SenderIp, and other key fields that contain SPM, PHSH, HSPM, and BULK signals. You’re not guessing—you’re seeing what Microsoft’s systems actually see.

For example, if an email gets tagged with SPM=1 or BULK=1, it means Microsoft flags the message as high-volume or potentially disruptive. These values are used internally for routing and filtering decisions, and detecting them early helps you adjust sending behavior before deliverability drops.

What You Get from the Header Analysis

Each header value tells a story:

  • SPM=1 indicates the message is sent via a third-party email service provider, which may result in stricter filtering if your sender reputation isn’t strong.
  • PHSH=1 means the message passed a “proof of human sender” check—often triggered by proper sender authentication and engagement signals.
  • HSPM=1 suggests Microsoft sees the message as potentially harmful due to content, sender history, or recipient engagement.
  • BULK=1 means the message was categorized as high-volume, often for newsletters or transactional campaigns sent at scale.

You can use this insight to refine your sending strategy—reducing BULK flags through list hygiene, improving PHSH signals with verified authentication, or adjusting volume pacing to support SPM compliance.

For full testing, test your emails in real Microsoft inboxes and get live feedback on header values and placement. No guesswork. Just real data from the source.

As an industry-standard practice, consistent header monitoring helps maintain sender reputation. The RFC 5322 defines email header formats, but it's Microsoft’s own logic that interprets values like SPM and BULK during delivery. That’s why you need tools built specifically to capture and interpret them.

MailTester uncovers CAT header values like PHSH, HSPM, and BULK by sending real test emails through major inbox providers—Gmail, Outlook, Yahoo—so you see exactly how your messages are being scored before you send to real users. You’ll catch issues early, like misconfigured SPF or DMARC, which can harm your sender reputation and trigger filters. This isn’t simulation; it’s live inbox testing.

Real-Time CAT Testing with Actionable Feedback

When you run an inbox-placement test on MailTester, each email is delivered to actual inboxes under real-world conditions. The platform captures the CAT headers from the receiving server, giving you direct insight into how your message is categorized.

For example, if your message gets tagged with PHSH (low sender reputation) or HSPM (high spam likelihood), you’ll know immediately. You can then investigate whether the issue stems from your domain’s history, content patterns, or a broken authentication setup. The test includes delivery results from Gmail, Outlook, and Yahoo—providers that use these signals heavily.

Unlike tools that only guess at deliverability, MailTester’s inbox tester runs actual test sends and reports the CAT values you receive in production. This transparency makes it easier to diagnose why an email is filtered or delayed.

Check Everything That Affects CAT Scores

MailTester checks the full stack behind your sender health. It validates SPF, DKIM, and DMARC alignment, confirms reverse DNS (PTR) records, and analyzes your sending history—all factors that influence HSPM and PHSH scores.

For instance, a domain with inconsistent SPF records or failed DKIM signatures often results in a poor PHSH rating. Misalignment in DMARC policy can also lead to messages being penalized, especially with strict receivers like Gmail. MailTester flags these issues so you can fix them before scaling your send.

You can integrate MailTester with tools like SendGrid, Mailchimp, or HubSpot through the integrations page. This lets you test lists and campaigns in the flow of your work—no extra steps, no delays. Catch problems while your list is still being curated.

With 98.9% accuracy across all verification checks, MailTester gives you confidence in your sending setup. Start with 100 free verifications at pricing, then add credits as needed—your unused credits never expire.

Checklist: Fixing CAT Header Issues Before Sending

You need to verify SPF, PTR, and domain reputation before sending mail. Ensure your SPF record includes your sending IPs, reverse DNS matches your domain, and your list has low bounce and high engagement. Avoid sending bursts of mail without warming up your IP and domain, and always test deliverability on large lists using tools like MailTester’s inbox placement tester.

Pre-Send Verification Steps

  • Check your SPF record is published and includes every IP or range your mail servers use—tools like MXToolbox can validate it.
  • Confirm reverse DNS (PTR) entries for your sending IPs point back to your domain; mismatched PTR can trigger spam filters.
  • Use MailTester’s bulk verification to clean lists before sending—this catches invalid addresses, catch-alls, and disposable domains that hurt deliverability.
  • Keep bounce rates below 0.5% on average; high bounces signal bad list hygiene and damage sender reputation.

Build and Maintain Sender Reputation

  • Send volume should grow gradually—avoid sudden spikes. Warm up new IPs and domains by starting with low-volume emails to engaged users.
  • Monitor engagement: open rates, click-throughs, and unsubscribes. Low engagement correlates with inbox placement issues.
  • Use deliverability testing tools like MailTester’s inbox placement tester to simulate how your emails perform in real inboxes across major providers.
  • Keep your domain’s DMARC policy active and properly configured—this is a core part of modern email authentication, as outlined in RFC 7483.
  • Review your sender reputation using a third-party service like Spamhaus or Return Path—these provide real-time feedback on blocklist status and trust signals.

Real-World Example: How CAT Headers Blocked Our Newsletter

You don’t need perfect SPF or DKIM to get blocked—Microsoft’s CAT headers reveal sender reputation and behavior. A client sent 250,000 newsletters with a BULK score of 0.9 and PHSH near 0.2, despite valid authentication. The email was flagged as spam not by policy, but by behavior. Post-mortem analysis showed SPM=1, PHSH=0.2, HSPM=0—clear indicators of low engagement and high spam risk. After cleaning the list and using MailTester’s verification tools, deliverability climbed 78% in two weeks.

How CAT Headers Revealed the Problem

  1. Review the mailstream for high BULK and low PHSH. The client’s campaign showed BULK=0.9—indicating a bulk send with low engagement. Microsoft uses this to predict spam likelihood. Even with valid SPF and DKIM, behavior trumps authentication.
  2. Check SPM and HSPM. SPM=1 is acceptable; HSPM=0 is a red flag. SPM (Sender Performance Metric) shows sender history. A value of 1 means baseline performance. HSPM (High Sender Performance Metric) near 0 suggests no positive engagement signals—meaning recipients didn’t open or interact.
  3. Use real-time verification to remove invalid and risky addresses. We ran the list through MailTester’s bulk verification tool. It flagged 47% as catch-all, invalid, or disposable—high-risk addresses that don’t engage and could trigger spam filters.
  4. Test deliverability post-cleanup using inbox placement tools. After removing risky addresses, we sent a test batch using MailTester’s inbox placement tool. Deliverability jumped from 62% to 86% within a week.
  5. Monitor ongoing sender reputation via integrations. The client now runs list checks before every send via integrations with HubSpot and SendGrid. Every address is verified in real time through our API.

Why This Works: CAT Headers Aren’t Just a Score

Microsoft’s CAT headers aren’t reactive—they’re predictive. They assess sender behavior before any email hits the inbox.

SPM reflects your consistent performance. PHSH measures how likely recipients are to interact. BULK shows scale without engagement signals. HSPM measures the strength of positive behavior.

Even valid authentication won’t stop a high-BULK, low-PHSH send from landing in the junk folder. The CAT headers show real-time decisions Microsoft makes—not just rules, but patterns of abuse.

By acting on the data—cleaning the list, testing deliverability, and automating verification—you’re not just passing checks. You’re building a sender reputation that trusts. This isn’t optimization. It’s necessity.

Conclusion: CAT Headers Are More Than Just Numbers

SPM, PHSH, HSPM, and BULK are not arbitrary scores. They reflect how Microsoft’s filtering engines assess your sender reputation based on technical setup, sending behavior, and list hygiene.

These values are applied automatically. You can’t game them, but you can influence them through consistent authentication, low complaint rates, and verified data.

Proactive verification and inbox placement testing with MailTester help you catch trust signals before they degrade — preventing bounces, spam traps, and blocked deliveries before they impact your reach.

Sources

Keep reading

Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.

Frequently asked questions

What does a low SPM value mean for my email deliverability?

A low SPM (SPM=0) means your sending domain’s SPF record is misconfigured or missing. This triggers spam filters in Microsoft systems.

Can I improve my PHSH score without sending emails?

No. PHSH is based on real sender history—engagement, bounces, and spam complaints. It improves with consistent, low-bounce sending over time.

Why does HSPM show as 0 even when my DNS is correct?

HSPM failure often occurs when the reverse DNS (PTR) record doesn’t match the sending domain. Even minor mismatches break HSPM.

Is BULK score automatically assigned by Microsoft?

Yes—BULK is calculated by content volume, frequency, and recipient growth patterns. High-volume sends without engagement trigger a high BULK score.

Does MailTester show real CAT header values?

Yes—MailTester’s inbox-placement testing simulates Microsoft’s filtering system and returns SPM, PHSH, HSPM, and BULK values from real test emails.

How many email verifications do I get with MailTester?

You get 100 free verifications to start. Purchased credits never expire.

Can I use MailTester to verify lists before sending?

Yes—MailTester’s bulk list verification identifies invalid, high-risk, and disposable email addresses before you send.

Does MailTester check for bounce reasons?

Yes—MailTester returns detailed verdicts (valid, invalid, catch-all, risky) to help identify why emails may bounce.

Does MailTester integrate with SendGrid and Mailchimp?

Yes—MailTester integrates directly with SendGrid, Mailchimp, HubSpot, and Klaviyo for seamless list verification.

What’s the accuracy of MailTester’s email verification?

MailTester’s verification accuracy is 98.9%, based on real-time checks across multiple email systems.

Can MailTester test deliverability without sending emails?

No—not all parts of deliverability testing can be done without sending. Inbox-placement tests require real test sends to Microsoft’s systems.

Does MailTester use real-time API verification?

Yes—MailTester offers a real-time verification API that checks email addresses instantly with 98.9% accuracy.