Skip to main content

Blog · Email

Business mail in the spam folder: the DNS records that put it right

By the Hosting & Domains team Published 27 July 2026 7 min read

Nothing stings quite like a customer telling you it turned up in their spam folder. Your invoice. The quote. The proposal you gave up an evening to write, sorted in among the pills and the princes. Where a small business sends under its own name, what the message says is almost never the fault. The fault lies in authentication: nothing on your domain offers cryptographic proof that the mail came from you.

Google and Yahoo tightened their bulk-sender rules in 2024, and the screws have gone on further since, so unauthenticated mail no longer receives the benefit of the doubt. Here is the consolation: the repair comes down to three DNS records, none of which costs anything, and the whole job fits inside twenty minutes.

The three records, translated

SPF is the approved-sender list. A single DNS record names every server permitted to send mail for your domain. The receiving server compares the sending IP against that list and fails whatever is not on it. One record, one line, and our SPF walkthrough writes it alongside you.

DKIM is the tamper-proof signature. Your mail server signs every outgoing message with a private key, and the matching public key sits in DNS where any receiver can check it. If the signature holds, the message is genuine and arrived exactly as you sent it. Switching it on takes one panel toggle plus one record.

DMARC is the standing instruction. It tells a receiver how to treat mail that fails SPF and DKIM: deliver it regardless, quarantine it, or refuse it outright, and where to send the reports afterwards. Gmail now expects one from any domain that hopes to reach the inbox. Begin at p=none, read what the reports say, and tighten the policy once they come back clean.

Why mail still fails once the records are in

Application mail leaving by the wrong door. A WordPress contact form, or an invoicing app, puts your domain in the "from" line but pushes the message through a server your SPF record has never met, so every one of those fails. Route application mail over authenticated SMTP instead. In WordPress that is a ten-minute job.

Two SPF records on one domain. The standard permits exactly one. A second, generally abandoned there by a previous provider, breaks SPF outright. Merge them into a single record and delete the spare.

Sending as your own domain from personal webmail. Set "send as" for you@yourdomain inside a personal Gmail account, skip real SMTP authentication, and DMARC fails at every strict receiver. Mail carrying your domain belongs on the mail service that domain runs.

One cause sits outside DNS altogether: history. Go from complete silence to hundreds of identical messages and the domain looks precisely like a hijacked mailbox. Warm new domains up slowly. Keep invoices and receipts well separated, by volume, from anything you send as marketing.

Twenty minutes, five steps

One, write down everything that legitimately sends as your domain: the mailbox, the forms on the website, the invoicing tool. Two, publish a single SPF record covering exactly those senders and nothing else. Three, switch DKIM signing on at your mail host and put the key it gives you into DNS. Four, publish DMARC at p=none with a reporting address, leave it alone for a week, read what arrives, then step up to quarantine. Five, send a message to a Gmail address and open Show original. You are done when three PASS lines come back green.

Take our email hosting and the SPF and DKIM records come generated for every mailbox domain, with the panel spelling out precisely what to publish, so most of those twenty minutes turn into reading. Inbound spam filtering sits in every plan. A domain that needs more than that can place dedicated mail filtering in front of any mailbox, wherever the mailbox is hosted.

Quick answers

My business mail is not spam, so why does it keep landing there?

Nearly always because the authentication is absent. With no SPF, no DKIM and no DMARC, a receiver has no way to confirm the mail actually left your domain, and the 2024 Gmail and Yahoo rules downgrade unverified mail as a matter of course. Content counts for far less than senders assume.

SPF, DKIM and DMARC — what is each one for?

SPF publishes the servers cleared to send on behalf of your domain. DKIM puts a signature on every message showing it is genuine and unaltered along the way. DMARC gives receivers an instruction for failures, then reports what happened back to you. Between them they decide inbox or junk.

Once the records are live, how fast does deliverability recover?

Authentication starts working the moment DNS propagates, and that is a matter of hours. Reputation is slower to rebuild: expect gains to accumulate across two to four weeks of steady, authenticated sending.

Up next

More from the blog

The hosting these notes are written on

Renewals that stay flat, limits printed before you buy, migration at no charge and a support desk that writes back, all wrapped into one plan.

Browse Hosting Plans