Web development · 4 min read
Email that lands in the inbox: SPF, DKIM and why yours goes to spam
If your invoices, quotes and contact form replies keep landing in spam, the fix usually has nothing to do with your words and everything to do with three DNS records most site owners never touch.

A customer fills in your contact form, you reply with a quote, and it lands in their spam folder or never arrives at all. This happens more than most business owners realise, and it rarely has anything to do with what you wrote. It comes down to whether your domain is set up to prove the email actually came from you.
What SPF and DKIM actually do
SPF (Sender Policy Framework) is a DNS record that lists which mail servers are allowed to send email on behalf of your domain. When a receiving server gets a message claiming to be from you, it checks that record. If the sending server isn't on the list, the message looks forged, even if it isn't.
DKIM (DomainKeys Identified Mail) works differently. It attaches a digital signature to outgoing mail, generated with a private key your mail provider holds, and publishes the matching public key in your DNS. The receiving server checks the signature against that key. If it matches, the message wasn't altered in transit and genuinely came from a server holding your key.
Why this ends up in spam
- Your invoicing tool, CRM or contact form sends email from your domain through a different server than the one SPF allows
- You switched email or hosting providers and never updated the SPF record for the new sender
- DKIM was never configured because it requires a DNS change most site builders don't prompt for
- No DMARC record exists to tell receiving servers what to do when SPF or DKIM fails, so they default to their own judgment, and that judgment increasingly means spam or rejection
DMARC ties the other two together
DMARC (Domain-based Message Authentication, Reporting and Conformance) is the policy layer. It tells receiving servers what to do when a message fails SPF or DKIM: let it through, send it to spam, or reject it outright. Without a DMARC record, servers guess, and Gmail, Outlook and Yahoo have all become stricter guessers over the past two years.
5,000
emails/day above which Google requires SPF, DKIM and DMARC or rejects the message outright
Source: Google Workspace bulk sender guidelines, effective February 2024
That threshold is for bulk senders, but the filtering logic behind it applies to everyone. A domain without these records reads as suspicious to Gmail and Yahoo regardless of how many emails it sends, it's just that bulk senders get rejected outright while smaller senders get quietly filtered.
How to check your own setup
You don't need special software for this. MXToolbox and Google's own Admin Toolbox both offer free SPF, DKIM and DMARC lookups. Enter your domain and you get a pass or fail in seconds. If any of the three come back missing or failing, that's usually the actual reason your emails aren't landing, not your subject line or your sending frequency.
| Record | Proves | Lives in |
|---|---|---|
| SPF | Which servers may send mail as you | A TXT record on your domain |
| DKIM | Mail wasn't altered and came from a server holding your key | A TXT record with a public key |
| DMARC | What to do when SPF or DKIM fails | A TXT record with a policy (none, quarantine, reject) |
Fixing it
- 1Log in to wherever your domain's DNS is managed, usually your registrar or hosting provider, not your email provider
- 2Add or correct the SPF record so it includes every service that sends mail on your behalf: your email provider, invoicing tool, CRM and website contact form
- 3Enable DKIM in your email provider's settings and publish the key it gives you as a DNS record
- 4Add a DMARC record starting with a p=none policy so you can monitor without risking legitimate mail, then tighten it once you confirm everything passes
- 5Re-run the lookup after DNS propagates, usually under an hour, occasionally up to 24
None of this touches your website's code or design. It's DNS plumbing, and it's exactly the kind of thing that quietly breaks when you switch providers or add a new tool, then sits broken for months because nobody notices until a client says they never got your quote. If keeping track of this isn't something you want to own yourself, it's one of the things covered under our ongoing maintenance and support, alongside uptime, backups and the other unglamorous parts of keeping a site, and its email, working.
Check your domain today if you haven't in the last year. Providers have tightened their requirements twice in the past two years, and a setup that passed in 2023 isn't guaranteed to still pass now.
Questions people also ask
Do I need SPF, DKIM and DMARC if I only send a handful of emails a week?
Yes. Google and Yahoo's bulk sender rules technically kick in at volume, but their spam filtering treats unauthenticated domains with suspicion regardless of volume. Low-volume senders without these records still see deliverability problems, just less predictably.
Will adding these records break my existing email?
Not if you do it correctly. SPF and DKIM only fail mail that shouldn't have been sending as you in the first place. Start DMARC in monitoring mode with a p=none policy so you can see what would happen before you enforce anything.
How long does it take to fix?
The DNS changes themselves take about 15 minutes. DNS propagation adds up to 24 hours before every mail server worldwide sees the update, though most see it within the hour.



