Spam Trigger Words in Cold Email, Checked Against the Rules

Short answer

The word lists cite nothing. One spam filter publishes its rules and its point values, so here is what it matches, what each hit costs, and what outweighs all of it.

Artem Smirnov
Artem Smirnov

Last updated · 10 min read

Artem Smirnov in a dark suit against a charcoal studio backdrop, next to the line 'The word free scores zero. Your sender reputation does not.'

SpamAssassin, the open-source spam filter that publishes its rules and scores, keeps its general phrase rules in one small file. That file has about 40 rules. None of them fires on the word "free" by itself, and none of them touches "opportunity", "quick call" or "no cost".

For cold email, spam trigger words barely matter, and not in the way the word lists claim. A documented filter scores a short list of scam phrases and old bulk-mail lines. The heavy points come from the sender: authentication, what the receiving server's own trained filter thinks of mail like yours, blocklisted link domains and copies of your message already reported elsewhere.

A soft word in an authenticated, well-targeted email costs nothing. A sender with a bad reputation lands in spam with spotless copy.

Below: the real rules and their point values, one cold email scored three ways, and what Gmail and Outlook publish. Every source was checked in September 2026.

Where do spam trigger word lists come from?

A spam trigger word is a word that supposedly sends your email to spam on sight: "free", "guarantee", "act now", "urgent", "risk-free". The lists ranking for this query sort them into money, urgency, health and overpromise groups, and some run to hundreds of entries.

The pages ranking in September 2026 share one habit. None of them names a source for its list: no filter documentation, no test, no dataset.

There is a reason. Gmail and Outlook do not publish how they score content. SpamAssassin does: its rules are plain text files with a score file next to them, so "does this word get flagged?" finally has an answer you can check.

It is not Gmail's filter. It is a public, checkable record of how one rule-based filter treats words.

What does SpamAssassin actually score?

SpamAssassin tests both the headers and the body. Per the project's home page, it mixes pattern rules, a Bayesian classifier, DNS blocklist lookups and shared databases of spam that others have already seen. Each test that fires adds or subtracts points. The total decides the verdict.

Three things in the source files matter for cold email:

  1. Phrase rules live apart. The general body test file tells rule writers that a rule looking for a phrase belongs in 20_phrases.cf instead (20_body_tests.cf). What stays in the body file is structure: HTML-only messages, text hidden in base64 encoding, bodies that are 80 to 90% blank lines, HTML and text versions that say different things.
  2. The phrase file is short and aimed at consumer scams. The roughly 40 rules in 20_phrases.cf look for "100% guaranteed", "unclaimed" next to money or prizes, "male enhancement", "strong buy", "refinance your home" and "Dear Friend" at the start of a line. Beyond it, the rules folder has separate files named for drugs, advance-fee fraud and porn.
  3. The default spam line is 5 points, and it is strict. The configuration docs call 5.0 "quite aggressive" and suggest an ISP set 8.0 or 10.0 instead.

Every rule gets its points in 50_scores.cf. Many carry four numbers, one per setup, depending on whether Bayes and network tests are on. The tables below use the fourth, the full setup with both on; a single number applies everywhere. Admins can override any of it locally, so treat these as defaults.

Which spam words actually match a rule?

Here are the words the lists warn about most, run against the phrase file and the default scores.

Word or phrase on the listsMatching ruleWhat the rule needs to firePoints
free (on its own)nonenothing matches the word alone0
freeFIN_FREE"financial" followed by "free" or "independent"0.1
freeFREE_QUOTE_INSTANT"free" close to "instant", "express", "online" or "no obligation", then "quote"1.297
guaranteeGUARANTEED_100_PERCENT"100% guaranteed"2.699
guaranteeBANG_GUAR"guaranteed!" with the exclamation mark1.0
act nowACT_NOW_CAPS"Act Now" with both capitals0.1
urgentURG_BIZ"urgent" within 16 characters of business, proposal, reply, request or a few similar words0.573
one time offerONE_TIME"one time" plus charge, investment, offer or promotion0.714
lowest priceLOW_PRICE"low" plus "Price" with a capital P0.1
Dear Sir or MadamDEAR_SOMETHING"Dear" plus sir, madam, investor, candidate and a few others1.973
unsubscribe, removeEXCUSE_REMOVE"to be removed from" followed by "mailings" or "offers"3.299
opportunity, quick call, no costnoneno rule in the file0

Two things jump out.

Most matches need a whole phrase, and some need exact capitals. ACT_NOW_CAPS fires on "Act Now" and ignores "act now". LOW_PRICE wants "Price" with a capital P. A word list cannot capture that, which is partly why the lists keep growing.

The most expensive line in the table belongs to the old bulk-mail opt-out. "To be removed from our mailings" or "from future offers" costs 3.299 points, two thirds of the way to the default spam line on its own. Its cousin "To be removed, please" (EXCUSE_4) costs 1.325.

If your cold email closes with an opt-out, write it the way a person talks: "If the timing is wrong, say so and I will not email again." An all-caps subject line adds 0.5 (SUBJ_ALL_CAPS), and exclamation marks only cost points in combinations such as "guaranteed!".

How many points does a real cold email score?

Take one plain-text email, sent from a domain with SPF and DKIM set up:

Subject: implementation hires in Brno

Hi Jana, I saw you are hiring 3 implementation engineers in Brno. When a software team grows that fast, onboarding is usually the first thing to slip.

We put together a free onboarding checklist for teams at this stage. Worth a quick call next week to see if it fits?

If the timing is wrong, say so and I will not email again.

(signature with a link to the company website)

Version A is that email, from a sender with a clean history.

Version B is the same email with two lines swapped: "Get your free, no-obligation quote today" and "To be removed from future offers, reply STOP."

Version C is version A word for word, from a sender with a bad history. The receiving server's Bayes filter has learned to rate mail like it as 99% spam, and the domain in the signature link sits on the Spamhaus domain blocklist.

Signal (rule)ABC
DKIM valid and aligned (DKIM_VALID, DKIM_VALID_AU)-0.2-0.2-0.2
SPF passes (SPF_PASS)-0.001-0.001-0.001
Bayes has no strong opinion (BAYES_50)0.80.80
Bayes rates it 99% spam (BAYES_99)003.5
"free, no-obligation quote" (FREE_QUOTE_INSTANT)01.2970
"to be removed from future offers" (EXCUSE_REMOVE)03.2990
Link domain on the Spamhaus DBL (URIBL_DBL_SPAM)002.5
Total0.5995.1955.799

Version A says "free" and "quick call" and scores 0.599. The two swapped lines in B add 4.596 points and push it over the default line of 5. Version C uses exactly the same words as A and still crosses the line, by more than B does.

C can get worse without a single word changing. If a template goes out in bulk and people report it, two collaborative checks join in. Razor adds 2.808 when it lists your message with more than 50% confidence (per 25_razor2.cf and 50_scores.cf). DCC, which collects and counts checksums of millions of messages, adds 1.1 more.

The example is simplified. A real report lists more rules, most worth 0.001 to 0.1. Bayes only switches on after a server has trained it. And at an ISP threshold of 8, all three versions would pass. What changes on a strict server is which email crosses first, and it is not the one that just says "free".

What do Gmail and Outlook publish about content?

Neither publishes a word list. Here is what their written rules cover, checked September 2026.

Gmail's sender guidelines require at least one of SPF or DKIM from everyone, plus working forward and reverse DNS records, TLS, and a user-reported spam rate under 0.3% as Postmaster Tools measures it. Once daily volume to Gmail passes 5,000, DMARC, From alignment and a one-click unsubscribe in marketing mail are added.

On content, Gmail's rules are about honesty. Subject lines and display names must not mislead. No "Re:" or "Fwd:" unless the message really is a reply or a forward. No emojis used to imitate graphic elements in order to deceive.

Microsoft's rules for Outlook.com apply once a domain sends 5,000 or more messages to its consumer services. SPF and DKIM must pass, a DMARC record must exist (the page's example uses p=none), and at least one of SPF or DKIM must align with the From domain. The page says nothing about content.

So the one content rule the big providers do publish is about deception. A fake "Re:" on a first cold email breaks it. The word "free" does not. I compared what each provider requires, next to real placement data, in the inbox placement numbers for Gmail, Outlook and Yahoo.

Why are the "spam words don't matter" pages only half right?

A newer set of pages flips the myth: words are obsolete, only infrastructure counts. That conclusion sits closer to the evidence, but the two pages ranking for "do spam words still matter" in September 2026 weigh copy against infrastructure in numbers with no method, source or dataset behind them. Same gap as the lists they correct.

The rule files support a narrower answer. Content is scored, just not the way either side says. A few dozen specific phrases cost real points, some more than 2 each. Common B2B sales words cost nothing.

Bayes is the one part of SpamAssassin that learns from ordinary words, and it learns them from the receiving server's own mail. The sa-learn docs describe training it on incoming mail sorted into spam and ham, and recommend at least 1,000 of each before the results are useful.

So a word can hurt you when people on that server have marked enough mail containing it as spam. That is a reputation signal measured through words. Swapping "free" for "complimentary" will not fix it: if people keep marking your emails as spam, a trained filter learns the new word too.

What moves a cold email out of spam if the words do not?

Start with authentication, which Gmail asks of every sender and Outlook of every high-volume one. Then the domain: a new one needs warm-up time, and one sitting on a blocklist needs cleaning up and a removal request before anything else.

Then the list, because a dirty list brings bounces and spam complaints, and Gmail counts the complaints. Then volume per mailbox, so one address is not pushing the same template into thousands of inboxes. I laid out that setup, from separate domains to mailbox limits, in my notes on domains, inboxes and warm-up.

Copy comes last, and the copy check takes five minutes. Remove fake "Re:" and "Fwd:" subjects, "Dear Sir or Madam", all-caps subject lines, "100% guaranteed" and any opt-out that starts "to be removed from". Leave "free" and "quick call" alone if they are the right words for the offer.

The copy is the last thing I would touch

"Copy cannot fix a bad list or a weak sender." That is my position on copy in general, and the rule files back it up for spam folders too. The copy that costs real points reads like a scam or an old mass mailing. The biggest numbers in the file belong to the sender.

Smirnov Consulting Group is a Prague-based B2B outbound lead generation agency that runs cold email and LinkedIn campaigns for founder-led B2B companies and books qualified sales calls. The order my team works in does not change: "Set up SPF, DKIM and DMARC before sending at any volume." Then verify every address and hold bounces under 0.5%.

If replies are still low after that, check who is actually on the list before touching a word, as I argued in why the list usually fails before the email does.

Other questions about spam trigger words

Does the word "free" still send cold email to spam?

Not on its own in SpamAssassin's published rules. The phrase rules that use "free" need it inside a longer pattern, such as "free, no-obligation quote" at 1.297 points. Gmail and Outlook publish no word rules, so nobody can prove their filters ignore it, but their written requirements cover authentication, spam rates and honest subject lines.

Is there an official list of spam trigger words?

Gmail and Microsoft do not publish one. The closest thing is SpamAssassin's 20_phrases.cf: about 40 rules anyone can read, with points in 50_scores.cf. It catalogs consumer scam patterns such as unclaimed money and enhancement pills, and says very little about B2B sales copy.

Are spam word checkers worth using?

Only the ones that show the full SpamAssassin report. Read which rules fired and how many points each added. If your hits are 0.001 and 0.1 lines, the copy is fine and the problem is somewhere else. A checker that paints "free" red without naming a rule is repeating the word list back to you.

Can an email with no trigger words still go to spam?

Yes. Version C above uses the same words as the clean email and scores 5.799 from Bayes and a blocklisted link domain alone. Gmail's own ceiling for reported spam is 0.3% for any sender, and rewording does not bring a high rate down.

Want to get more B2B clients for your business?

I help B2B companies book 10 to 100+ qualified sales calls per month with outbound. Let's see if it fits yours.

Artem Smirnov
Artem Smirnov

I help B2B companies book qualified sales calls with cold email and LinkedIn outbound.