Guide
How to fix your email going to spam (SPF, DKIM and DMARC)
When legitimate email lands in recipients' spam folders, the cause is almost always sender authentication rather than content. SPF, DKIM and DMARC together prove a message really came from your domain. Get all three aligned and deliverability usually recovers within a day or two.
What you'll see
- Customers say your replies arrive in junk, or never arrive at all
- Mail sent from a newsletter tool or CRM is filtered while mail from Outlook is not
- You recently changed email provider, domain or marketing platform
The procedure
Step by step
Step 01
Read the headers of a filtered message
Ask the recipient to forward the message as an attachment, or view the original headers. Look for the SPF, DKIM and DMARC results near the top: any result of fail, softfail or none tells you which record to fix first.
Step 02
List every service that sends as your domain
Write down each one: Microsoft 365 or Google Workspace, your CRM, your invoicing tool, your marketing platform, your website contact form. A record that omits one of them will cause intermittent failures that are hard to reproduce.
Step 03
Publish a single, correct SPF record
Create one TXT record at the domain root containing every sending service, ending in -all once you are confident the list is complete. Never publish two SPF records — that is an automatic permanent failure — and keep total DNS lookups at ten or fewer.
Step 04
Enable DKIM signing at each sender
In Microsoft 365, enable DKIM in the Defender portal and publish the two CNAME selector records it gives you. Repeat the equivalent step for every other sending platform. DKIM survives forwarding, which is why it matters more than SPF alone.
Step 05
Start DMARC in monitoring mode
Publish a TXT record at _dmarc.yourdomain with p=none and an rua address so you receive aggregate reports. Read a fortnight of reports before tightening anything — this is where you discover the sender nobody remembered.
Step 06
Move DMARC to quarantine, then reject
Once reports show all legitimate mail passing, raise the policy to p=quarantine, and after another clean fortnight to p=reject. This is the step that stops other people spoofing your domain, and it is the point at which mailbox providers start trusting you more.
When to stop and escalate
Escalate if your domain or sending IP appears on a public blocklist, or if DMARC reports show volumes of mail you did not send. That is spoofing or a compromised account, and it needs containment alongside the DNS work.
How AlwaysOnIT handles it
AlwaysOnIT diagnoses this in chat: the agent reads the failing headers, checks your live DNS, tells you exactly which record is wrong and what the corrected value should be, then re-checks once you publish it.
Get started
Open a chat. The AI picks up before the second ring — every time.
No onboarding calls. No sales process. Connect your devices and start raising tickets in under ten minutes.