Guide

How to fix your email going to spam (SPF, DKIM and DMARC)

When legitimate email lands in recipients' spam folders, the cause is almost always sender authentication rather than content. SPF, DKIM and DMARC together prove a message really came from your domain. Get all three aligned and deliverability usually recovers within a day or two.

What you'll see

  • Customers say your replies arrive in junk, or never arrive at all
  • Mail sent from a newsletter tool or CRM is filtered while mail from Outlook is not
  • You recently changed email provider, domain or marketing platform

The procedure

Step by step

  1. Step 01

    Read the headers of a filtered message

    Ask the recipient to forward the message as an attachment, or view the original headers. Look for the SPF, DKIM and DMARC results near the top: any result of fail, softfail or none tells you which record to fix first.

  2. Step 02

    List every service that sends as your domain

    Write down each one: Microsoft 365 or Google Workspace, your CRM, your invoicing tool, your marketing platform, your website contact form. A record that omits one of them will cause intermittent failures that are hard to reproduce.

  3. Step 03

    Publish a single, correct SPF record

    Create one TXT record at the domain root containing every sending service, ending in -all once you are confident the list is complete. Never publish two SPF records — that is an automatic permanent failure — and keep total DNS lookups at ten or fewer.

  4. Step 04

    Enable DKIM signing at each sender

    In Microsoft 365, enable DKIM in the Defender portal and publish the two CNAME selector records it gives you. Repeat the equivalent step for every other sending platform. DKIM survives forwarding, which is why it matters more than SPF alone.

  5. Step 05

    Start DMARC in monitoring mode

    Publish a TXT record at _dmarc.yourdomain with p=none and an rua address so you receive aggregate reports. Read a fortnight of reports before tightening anything — this is where you discover the sender nobody remembered.

  6. Step 06

    Move DMARC to quarantine, then reject

    Once reports show all legitimate mail passing, raise the policy to p=quarantine, and after another clean fortnight to p=reject. This is the step that stops other people spoofing your domain, and it is the point at which mailbox providers start trusting you more.

When to stop and escalate

Escalate if your domain or sending IP appears on a public blocklist, or if DMARC reports show volumes of mail you did not send. That is spoofing or a compromised account, and it needs containment alongside the DNS work.

How AlwaysOnIT handles it

AlwaysOnIT diagnoses this in chat: the agent reads the failing headers, checks your live DNS, tells you exactly which record is wrong and what the corrected value should be, then re-checks once you publish it.

More walkthroughs in the guides index, terminology in the glossary.

Get started

Open a chat. The AI picks up before the second ring — every time.

No onboarding calls. No sales process. Connect your devices and start raising tickets in under ten minutes.