Why Your Business Emails Go to Spam — SPF, DKIM and DMARC Explained

If customers say your emails land in their spam folder, the cause is usually three missing or broken DNS records.

In short: SPF lists who may send email for your domain, DKIM digitally signs each message, and DMARC tells receiving servers what to do when a message fails those checks. Gmail, Outlook and other providers increasingly expect all three — without them, legitimate business email gets filtered as spam.

Why do business emails end up in spam?

Receiving mail servers have to decide whether a message claiming to come from yourcompany.com really does. Anyone can type any "From" address, so servers look for proof in your domain's DNS. If they can't find it, your message looks exactly like a spoofed or phishing email.

The usual culprits we find when businesses ask us why their emails go to spam:

  • No SPF record, or an SPF record that doesn't include every service that sends your mail
  • DKIM never switched on after moving to Microsoft 365 or Google Workspace
  • No DMARC record at all
  • Old hosting provider records left behind after an email migration

SPF — Sender Policy Framework

SPF is a single TXT record in your DNS that lists the servers allowed to send email for your domain — for example Microsoft 365, your website's contact form server, or a billing system.

When a message arrives, the receiving server checks whether it came from one of those listed sources. If it didn't, the SPF check fails.

Tip: a domain must have only one SPF record. Two separate SPF records is a common mistake that makes both invalid.

DKIM — DomainKeys Identified Mail

DKIM adds a digital signature to every email you send. The matching public key is published in your DNS, so receiving servers can confirm the message really came from your domain and wasn't altered on the way.

In Microsoft 365 and Google Workspace, DKIM usually has to be enabled manually and the DNS records added — many businesses never complete this step after setting up their email.

DMARC — the policy that ties it together

DMARC tells receiving servers what to do with messages that fail SPF and DKIM checks: do nothing and report (p=none), send to spam (p=quarantine), or reject (p=reject). It also sends you reports showing who is sending email using your domain.

Start with monitoring, confirm all your legitimate senders pass, then tighten the policy step by step. Jumping straight to reject can block your own invoices or website enquiries.

How to check your domain

  • Send an email to a Gmail account, open it, choose Show original and check that SPF, DKIM and DMARC all show PASS.
  • Look up your domain's TXT records with a free DNS lookup tool and confirm there is exactly one SPF record and a DMARC record at _dmarc.yourdomain.
  • In Microsoft 365, check the DKIM status in the Defender / email authentication settings.

Common mistakes to avoid

  • Forgetting to add your website form or accounting software to SPF
  • Leaving old hosting records in place after migrating email
  • Setting DMARC to reject before checking reports
  • Editing DNS at the wrong provider — your domain registrar and DNS host may differ

Getting this right is part of every email setup and Microsoft 365 migration we do, and it also reduces the risk of criminals spoofing your domain — see our cybersecurity services.

Emails still landing in spam?

We'll check your domain's records and fix the cause.