Why Your Business Email Keeps Landing in Spam (SPF, DKIM, and DMARC in Plain English)

KJONGSysSupport

Have you ever sent an important email to a customer and later found out it went straight to their spam folder? You are not alone. Over the past year we have helped several businesses dig out of this exact hole, and in almost every case the root cause was the same: their domain was missing one or more of the three email authentication records that mailbox providers now expect.

The good news is that these records are free, they only need to be set up once, and you do not need to change how you send email at all. Here is what they are, in plain English.

SPF: The Approved Sender List

SPF (Sender Policy Framework) is a small entry in your domain’s DNS settings that lists which servers are allowed to send email on behalf of your domain. When your message arrives at Gmail or Outlook, the receiving server checks the list. If the message came from a server on the list, it passes. If not, it looks suspicious.

The most common problems we see are businesses that send mail from more than one place (their website, their email provider, a newsletter service like Mailchimp or Flodesk) but only list one of them, and businesses with two conflicting SPF records, which causes the whole check to fail. You are only allowed one SPF record per domain, and every service that sends mail for you needs to be included in it.

DKIM: The Tamper-Proof Seal

DKIM (DomainKeys Identified Mail) adds an invisible digital signature to every message you send. The receiving server uses a public key published in your DNS to verify that the message really came from your domain and was not altered along the way.

Most email providers can generate this for you with a couple of clicks, but it is not always turned on by default. One detail worth checking: older setups often use 1024-bit signing keys, and the current recommendation is 2048-bit. If your DKIM key was set up years ago, it is worth regenerating it.

DMARC: The Policy That Ties It Together

DMARC is the newest of the three, and since 2024 both Google and Yahoo require it for anyone sending meaningful volume. It does two things. First, it tells receiving servers what to do with messages that fail SPF and DKIM: deliver them anyway, quarantine them, or reject them. Second, it can send you reports showing who is sending email that claims to be from your domain.

Those reports are more useful than most people expect. When we set up DMARC reporting for our own clients, we have found forgotten newsletter services still trying to send mail, misconfigured website contact forms, and in one case a whole sending service that was silently failing authentication for months. Nobody had noticed because the mail simply disappeared into spam folders.

How To Check Your Own Domain

You do not need any special tools to get a quick read on your setup. Free checkers like MXToolbox will show you whether SPF, DKIM, and DMARC records exist for your domain and whether they have obvious errors. Send yourself a test message from your business address to a Gmail account, open it, and choose “Show original” from the message menu. Gmail will show you a plain PASS or FAIL for all three checks right at the top.

If any of them say FAIL (or are missing entirely), that is very likely why your messages are not reaching inboxes.

A Word of Caution

These records live in your domain’s DNS, and a typo can make your email situation worse instead of better. A broken SPF record can cause every message you send to fail authentication. If you are not comfortable editing DNS, have your IT provider or hosting company make the changes, and always test with a real message afterward.

If your business email keeps ending up in spam and you are not sure why, this is exactly the kind of thing we sort out for our clients. Feel free to reach out and we will take a look.