Why Are My Business Emails Going to Spam? SPF, DKIM & DMARC Explained

Business emails landing in spam? Learn how SPF, DKIM and DMARC work, the Gmail and Yahoo sender rules, and a step-by-step fix to reach the inbox again.

Why Are My Business Emails Going to Spam? SPF, DKIM & DMARC Explained

Few things are as frustrating as sending a proposal or invoice and hearing “sorry, it was in my spam folder” a week later. In most cases the problem isn’t what you wrote — it’s that receiving mail servers can’t verify that your email really comes from your domain.

This guide explains the three DNS records that fix that — SPF, DKIM and DMARC — in plain English, plus the other common causes I see when helping businesses with email deliverability.

Why legitimate emails end up in spam

Gmail, Outlook and other providers ask three questions about every message: is the sender authenticated, does the sending domain and server have a good reputation, and does the content look like spam? If authentication fails, even a perfectly normal email can be filtered.

Since February 2024, Gmail and Yahoo require authentication from senders. Everyone sending to Gmail needs SPF or DKIM, and bulk senders (around 5,000 messages a day to Gmail addresses) must have SPF, DKIM and DMARC, offer one-click unsubscribe and keep spam complaints low.

SPF: who is allowed to send for your domain

SPF (Sender Policy Framework) is a TXT record in your DNS that lists the servers allowed to send email for your domain. For a domain that uses Google Workspace, it might look like this:

v=spf1 include:_spf.google.com ~all

Important rules:

  • A domain should have only one SPF record. Two separate SPF records cause both to fail — merge them into one.
  • Include every service that sends on your behalf: your email provider, newsletter tool, CRM and website.
  • SPF allows a maximum of 10 DNS lookups. Too many include: entries will break it.

DKIM: a digital signature on every email

DKIM (DomainKeys Identified Mail) adds a cryptographic signature to each message. Your email provider generates a key pair; you publish the public key as a DNS record (for example google._domainkey.yourdomain.com), and receiving servers use it to confirm the message wasn’t forged or altered.

Turning DKIM on is usually a few clicks in Google Workspace or Microsoft 365, plus one DNS record.

DMARC: the policy that ties it together

DMARC tells receiving servers what to do when a message fails SPF and DKIM alignment, and sends you reports about who is sending email using your domain. A safe starting record looks like this:

v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com

Start with p=none to monitor without affecting delivery. Once the reports show that all your legitimate sending sources pass, move to p=quarantine and eventually p=reject, which also protects your brand from email spoofing.

Other common causes

  • Website contact forms sending through the web server. Many WordPress sites send form emails with the server’s default PHP mail, which isn’t authenticated for your domain. Sending through a proper SMTP service fixes this.
  • A new or “cold” domain. Domains with no sending history have no reputation yet. Increase volume gradually.
  • Blacklisted sending IP. Shared hosting servers sometimes end up on blocklists because of other customers.
  • Spammy content and formatting. All-caps subject lines, only images, link shorteners and attachments from unknown senders all raise flags.
  • Poor list hygiene. Sending newsletters to old or purchased lists produces bounces and complaints that hurt your reputation.

Step-by-step fix

  1. List every service that sends email using your domain.
  2. Create or correct a single SPF record that includes all of them.
  3. Enable DKIM for your email provider and every marketing tool.
  4. Add a DMARC record with p=none and a reporting address.
  5. Make your website send through authenticated SMTP instead of the server’s default mail.
  6. Test with a tool such as mail-tester.com, and check your domain in MXToolbox.
  7. After a few weeks of clean reports, tighten DMARC to quarantine or reject.

How to check your current setup

Send a test email to a Gmail address, open it, choose “Show original” and look for SPF: PASS, DKIM: PASS and DMARC: PASS. If any of them fail, that is where to start. For regular sending, Google Postmaster Tools shows your domain reputation and spam rate.

Frequently asked questions

How long do DNS changes take to work?

Often minutes, sometimes up to 24–48 hours depending on DNS caching.

Will DMARC stop my emails from being delivered?

Not with p=none, which only monitors. Problems only appear if you jump straight to a strict policy before every legitimate sender passes.

Do I need all three records?

Yes. SPF and DKIM authenticate your email; DMARC connects them to your visible “From” address and tells providers how to treat failures. Together they give you the best chance of reaching the inbox.

Want this fixed for you?

Email authentication is one of the most common jobs in my IT support service — from SPF, DKIM and DMARC to Google Workspace setup and website SMTP. Tell me what’s happening and I’ll get your emails back in the inbox.

Next step

Want results like these
for your business?

Book a free, no-obligation call and get a clear plan for SEO, ads and your website.