Why Your Emails Are Going to Spam (and the Half You Can't Fix)
I found it while looking at something else entirely, which is how these things generally turn up.
The instruction is a DMARC record, and on its own it is a good thing to publish. It tells Gmail, Outlook and the rest what to do with any message claiming to come from your domain that can’t prove it. His said p=quarantine — put it in spam. That is the correct, responsible setting, and it is what stops somebody forging your address to invoice your customers.
It only works if the proving half works. His didn’t. Eight of his messages, sampled across two months, came back the same way every time: spf=none, dkim=permerror. No sender list published, and a signature pointing at a key that had never existed. So every message he sent arrived with nothing to identify it, met a policy he had published himself, and did what the policy said.
Two of his emails to me were sitting in my spam folder while we were talking about why his emails went to spam.
What an SPF record, a DKIM record and a DMARC record actually do
Three short lines of text live in your domain’s DNS settings. Between them they answer one question a receiving mail server asks about every message: is this really from who it says it’s from?
SPF is a list of the servers allowed to send email as you. The receiver looks up the list and checks whether this message came from one of them.
DKIM is a signature. Your mail provider signs each message on the way out, and publishes the matching key in your DNS so the receiver can check the signature is genuine.
DMARC is the instruction. It tells the receiver what to do when the first two don’t check out — nothing, quarantine, or reject — and it’s the one that gives the other two teeth.
None of this is new and none of it is optional any more. Gmail and Microsoft both tightened their requirements for anyone sending in volume in 2024, and they have kept tightening since. A setup that was fine three years ago can start failing without anybody touching it.
How to check SPF, DKIM and DMARC in two minutes
Send an email from your business address to a Gmail account you own. Open it in Gmail on a computer — not the phone app — click the three dots at the top right of the message, and choose Show original.
The first few lines give you SPF, DKIM and DMARC with a verdict beside each. You want three PASSes. Anything reading fail, none, softfail or permerror means your mail is going out without identification, and some proportion of it is landing somewhere you’d rather it didn’t.
That check is free, it takes two minutes, and it’s the one I’d run before rewriting a single subject line.
The repair is usually one DNS record. Working out which servers legitimately send as you is the fiddly part — you’d be surprised how many businesses route their mail through a relay they’ve never heard of, sitting between their hosting and the world — and you cannot guess it from the mail server’s name. It’s readable from the message headers you just opened, which is a happier way to spend twenty minutes than most.
The half of email deliverability that isn’t yours to fix
Your DNS records govern the mail you type and send. They have far less to say about the automatic mail — the booking confirmations, the enquiry replies, the receipts and the password resets. That mail almost always leaves through a third-party sending service, and that service has its own machinery, its own reputation and its own faults.
On the same client, in the same week: four of seven people with a Hotmail, Live or Outlook address never received their enquiry reply. Everyone else got theirs — one failure in twenty-four across every other provider, and that one was a dead address. Every single Microsoft failure carried the same message in the sending service’s own log, an internal error on their side, thrown before the message ever left for the customer.
Nothing at his end caused it and no DNS record would have prevented it. It had been running since May. The only reason anybody knows is that somebody opened the log and read it.
The records are yours: free, twenty minutes, entirely in your control. The sending service is not yours: you can read its log and raise a ticket, and that is the whole of your power. Fix the first and stop, and you have fixed the half you could see.
Why email authentication fails silently
A bounce is a gift. Something comes back, you know a message didn’t land, you pick up the phone.
Neither of these gives you that. A message that fails authentication is delivered — into spam. A message that dies inside a sending platform is recorded as accepted and simply never arrives. In both cases your screen says sent, no red light appears anywhere, and the customer at the other end reaches the only conclusion available to her: you didn’t reply.
You will never hear about it. What reaches you is a quiet week, and quiet weeks have a hundred explanations, all of them more comfortable than this one.
That’s the same shape as why a website gets visitors but not enquiries — the traffic is real, the failure is downstream of anything you’re looking at, and the number on the dashboard is fine right up until you check the layer underneath it. It’s the whole argument in the dashboard is a decoy, and it’s why half of service-business enquiries arrive by phone and most tracking records none of them. Every layer reports on itself, honestly, and the gaps between them belong to nobody.
What I’d do this week
Run the two-minute check. If any of the three fails, the repair is twenty minutes of DNS and there is no good reason to leave it sitting.
Then find where your automatic mail goes out — the booking confirmations, the form replies — log into that service and open its delivery log. Filter for anything that doesn’t say delivered. If there’s nothing there, you’ve bought a clean answer for twenty minutes. If there is something there, it has been there a while.
None of this needs a specialist if your setup is simple, and I’d rather tell you that than sell you the morning. What the job actually takes is somebody willing to go and look on a day when nothing appears to be wrong — which is the difficulty with anything that fails silently. It never asks to be looked at.
If you’ve run the check and the answer worries you, tell me what you’re seeing and I’ll tell you which half it is.
Related: Why Your Website Gets Visitors But Not Enquiries · The Dashboard Is a Decoy · Call Tracking for UK Service Businesses
Tony Cooper
Founder
Put My Crackerjack Digital Marketing Skills To Work On Your Next Website Design Project!
Get Started