Email Marketing

Why your emails go to spam: SPF, DKIM and DMARC explained

Emails land in spam when providers cannot prove they came from you. What SPF, DKIM and DMARC do, why website email fails so often, and how to check your own setup.

Why your emails go to spam: SPF, DKIM and DMARC explained: article by Sudeshna Thapa
In this article9
  1. Spam filters judge the sender before the message
  2. SPF: the list of servers allowed to send for your domain
  3. DKIM: a signature that proves the message is genuine
  4. DMARC: telling providers what to do when checks fail
  5. Gmail, Yahoo and Outlook now require it
  6. Website emails: the problem most people miss
  7. What is blamed, and is rarely the main cause
  8. How to check your own setup
  9. Get the exact values from each provider

Business emails usually land in spam because the receiving mail service cannot confirm they really came from you. Gmail, Outlook and the other large providers check three records in your domain’s DNS settings, called SPF, DKIM and DMARC, and treat mail that fails those checks with suspicion however polite and relevant it is. Most of the time the fix is a few lines of text added in the right place, plus making sure every system that sends as your domain is included. Below I explain what each record does, where small businesses tend to go wrong, and how to check your own setup in about ten minutes.

Spam filters judge the sender before the message

Anyone can type any address into the From line of an email, in the same way anyone can write any return address on an envelope. Mail providers know this, so before they look at your words they ask a simpler question: is this message provably from the domain it claims to be from? If the answer is no, or unclear, the message starts at a disadvantage, and a borderline one goes to junk.

That is why a perfectly ordinary quote or invoice can vanish while an obvious sales pitch from a well-configured sender arrives safely. Your email deliverability depends first on authentication, then on your reputation as a sender, and only after that on the content itself.

Authentication lives in your DNS, the public settings for your domain that also tell browsers where your website is and tell the world where your mail should be delivered. You do not need to understand DNS in depth. You need to know where yours is managed and what three records should say.

SPF: the list of servers allowed to send for your domain

SPF, short for Sender Policy Framework, is a single text record that lists the services permitted to send email using your domain. When a message arrives, the receiving server checks whether it came from somewhere on that list.

A typical small business sends from more places than it realises: the Microsoft 365 or Google Workspace mailboxes, a newsletter tool, the website’s contact form, accounting software that emails invoices, a booking system, perhaps a CRM. Each of them needs to be covered, normally by an include entry that the service gives you.

Three mistakes come up again and again:

  • Two SPF records. A domain may have only one. When a new tool tells you to “add an SPF record” and you add a second one instead of merging the entries, both stop working.
  • Too many lookups. SPF allows ten DNS lookups when it is checked. Every include can use several, so a record that has grown over years of adding tools can quietly break the limit and fail.
  • Forgotten senders. The invoicing system someone set up three years ago is not in the record, so every invoice fails the check.

SPF has one weakness worth knowing: it checks the technical return address hidden in the message headers, not the From address your recipient sees. That gap is what DMARC closes.

DKIM: a signature that proves the message is genuine

DKIM, DomainKeys Identified Mail, adds a digital signature to every message you send. Your mail service signs each email with a private key it keeps secret, and you publish the matching public key in your DNS. The receiving server uses that public key to confirm two things: the message was signed by someone authorised to sign for your domain, and nobody changed it on the way.

The common failure here is simple: DKIM was never switched on. Microsoft 365 and Google Workspace both support it, but on a custom domain it usually needs to be enabled in the admin centre and the records added to DNS before it does anything. Newsletter tools work the same way; most ask you to “authenticate your domain”, and until you do, they sign mail with their own domain rather than yours.

DKIM also copes better than SPF when an email is forwarded, because the signature travels with the message. That makes it the more dependable of the two checks.

DMARC: telling providers what to do when checks fail

DMARC ties the other two together. It is a text record published at _dmarc.yourdomain.co.uk that does three jobs:

  1. It requires that SPF or DKIM not only pass but pass for the same domain your recipient sees in the From line. This matching is called alignment, and it stops someone passing SPF with their own domain while pretending to be you.
  2. It states a policy for mail that fails: p=none (deliver it as normal, just report it), p=quarantine (treat it as suspicious, usually meaning junk) or p=reject (refuse it).
  3. It asks providers to send you reports showing every source that sent mail using your domain, and whether it passed.

I would start any domain on p=none with reporting switched on. The reports are not easy reading in their raw form, but a free or low-cost DMARC reporting service will turn them into a list of senders. After a few weeks you can see which legitimate systems are still failing, fix them, and then move to quarantine and eventually reject. Jumping straight to reject without that step is how businesses block their own invoices.

The UK’s National Cyber Security Centre recommends DMARC for every organisation, mainly because a reject policy makes it much harder for criminals to send convincing fake invoices in your name. For your own mail, better delivery is a useful side effect.

Gmail, Yahoo and Outlook now require it

For a long time these records were good practice. They are now a condition of entry. Under Google’s email sender guidelines, in force since February 2024, anyone sending to personal Gmail accounts must have SPF or DKIM set up, and anyone sending around 5,000 or more messages a day to Gmail must have all three, offer one-click unsubscribe on marketing mail and keep their spam complaint rate below 0.3%. Yahoo introduced matching rules at the same time, and Microsoft followed for Outlook.com in 2025.

Most UK small businesses send nowhere near 5,000 a day, but the direction is clear: unauthenticated mail is increasingly treated as suspect by default, whatever the volume.

Website emails: the problem most people miss

If the emails going missing are contact form notifications, order confirmations or password resets from your website, the cause is very often the website itself.

By default, WordPress and many other systems send mail straight from the web hosting server. That server is not in your SPF record and does not sign mail with your DKIM key, so the messages fail DMARC. Some arrive, some go to junk, and some disappear without any bounce.

The fix is to route website mail through a proper sending service. On WordPress that usually means an SMTP plugin connected either to your Microsoft 365 or Google Workspace account or to a transactional email service, with that service’s SPF and DKIM records added to your DNS. Then send a test from every form on the site.

Contact forms have a second trap. Many are set up to send the notification “from” the visitor’s own address, so replying is easier. That means your website claims to be sending as gmail.com or someone’s company domain, which fails their DMARC every time. Send from an address on your own domain and put the visitor’s address in the Reply-To field instead.

What is blamed, and is rarely the main cause

When emails go to junk, people tend to rewrite the subject line first. Words like “free” or a row of exclamation marks can nudge a borderline message the wrong way, but modern filters weigh them far less than authentication and reputation. If your records fail, no amount of rewording will reliably fix it.

Images, attachments and the length of the email matter in a similar, secondary way. A .co.uk domain makes no difference. Paying for a dedicated sending IP address rarely helps a small sender; it can make things worse, because a new IP has no history.

What does matter, once authentication is right, is how people respond to your mail. Your sender reputation builds from whether recipients open, reply, delete unread or mark you as spam. A high spam complaint rate will undo good DNS records. Sending marketing email to people who never asked for it, including bought lists, is the quickest way to get there, and under PECR it is generally unlawful to send marketing email to individuals without their consent.

How to check your own setup

This takes about ten minutes and needs no special software.

  1. List every sender. Write down every system that emails customers using your domain: mailboxes, newsletter platform, website, accounting and invoicing, bookings, CRM, ecommerce.
  2. Send yourself a test from each one to a personal Gmail address.
  3. Read the result. In Gmail, open the message, choose the three-dot menu and select “Show original”. The summary at the top shows SPF, DKIM and DMARC as PASS, FAIL or missing. You want all three to pass, with your domain named.
  4. Look at the records. Any free DNS lookup tool will show the TXT records on your domain and on _dmarc. Check there is exactly one SPF record and that a DMARC record exists.
  5. Find out who controls your DNS. It is wherever your domain’s nameservers point, which may be your domain registrar, your web host or a service such as Cloudflare. Changes made anywhere else have no effect.

If every sender passes all three checks and mail still lands in junk, the problem is reputation or list quality rather than setup, and that needs a different conversation.

Get the exact values from each provider

I have deliberately not printed record values to copy. The correct include for your SPF record, the DKIM selector names and the format all depend on which services you use, and each provider publishes its own up-to-date instructions. Copying a record from a blog post, or from another business’s settings, is a common way to break mail that was working.

Before you change anything, save a copy of your current DNS records so you can put them back. Most changes take effect within an hour, though some can take longer depending on the record’s settings, so test again the next day.

Authentication is also the first thing I check when I take on email marketing for a business, and contact form delivery is part of the routine checks in my WordPress maintenance and care plans. If you would rather have someone check it for you, send me a message through the contact page and list the tools that send email for your business.

Frequently asked questions

Will adding a DMARC record stop my emails being delivered?

Not if you start with p=none. That setting only asks providers to report on your mail; it does not change how they treat it. The risk comes when you move to quarantine or reject before every legitimate sender passes, so read the reports for a few weeks first and fix anything that fails.

Why do my emails reach Gmail but go to junk in Outlook, or the other way round?

Each provider runs its own filters and keeps its own view of your reputation, so the same message can be treated differently. A partial setup, such as SPF in place but DKIM never switched on, often passes one provider's checks and not another's. Run the Show original test in Gmail and look at the message headers in Outlook to compare.

How long do DNS changes take to work?

Usually minutes to an hour, occasionally up to a day or two. Each record carries a time-to-live setting that tells other servers how long to keep the old version, and some providers check new DKIM records on their own schedule. Wait, then send a fresh test rather than re-checking an old message.

Do I need all this if I only send a handful of emails a day?

Yes. The 5,000-a-day threshold only decides which of Google's stricter rules apply. Even a sole trader's quotes and invoices are judged on authentication, and a domain with no DMARC record is also easier for fraudsters to impersonate, which puts your customers at risk.

Found this useful?

Share it, or ask an AI to summarise it

Written by

Sudeshna Thapa

SEO and Digital Marketing Consultant.

Need help with this?

Book a call and I will tell you what applies to your site, and what can safely wait.