why do my business emails go to spam? the three records that decide

web · Oct 7, 2026 · 5 min read

the email arrived, and nothing happened. you follow up a week later and the client says "i never got it". your mail is sitting in their spam folder, and you were never told. for a small business this is quietly one of the most expensive technical failures there is, because it looks like silence from customers, not like a settings problem.

what the receiving server is actually doing

understand the paranoia and the fix makes sense. a receiving mail server gets billions of messages a day claiming to be from anyone — the "from" field is a suggestion, not proof, the same way the return address on an envelope is a suggestion. so before delivering, it asks: does this server have permission to send mail for this name? is there cryptographic proof the message really came from where it claims? and if it fails, what should i do?

those three questions are answered by three dns records. not by the mail client, not by how well the email is written — by three lines in the same phone book described in what is dns in simple words.

record the question it answers in practice
spf "which servers may send mail for this domain?" a list of your provider's sending servers
dkim "can you prove the message was not altered?" a cryptographic signature on every email
dmarc "and what do i do when the check fails?" tells the receiver to deliver, quarantine or reject

missing spf is walking around without id. missing dkim is a signature anyone could forge. no dmarc and the receiver decides your fate alone. your provider gives you all three values as copy-paste lines when you set up professional email — the failure mode is simply that nobody pasted them.

the other things that land you in spam

the records are the foundation; on top of them sit habits that receivers score:

  • you bought a list. sending to people who never asked is the definition of spam, no matter how good the records are. there is no technical fix for an unsolicited list.

  • the brand new domain that sends immediately. a domain registered last week that blasts fifty emails looks exactly like the spam pattern it copies. warm up: real conversations first, bulk later.

  • everyone BCC'd on one send. it hides the recipient list, and receivers notice. use proper groups or a newsletter tool for anything beyond a handful.

  • links and attachments that look like the phishing everyone gets. a first contact carrying a zip file reads as a threat, not as your portfolio.

    how to check yours in five minutes

send a message from your business address to one of the free "mail tester" services; it answers with a score and names the missing records by name. run it once after setup, run it again whenever you change provider. it is the closest thing email has to a smoke test.

and a habit that saves more mail than any setting: ask new clients to add you to contacts, and when a client says "i never got it", have them check spam and press "not spam" — the receiver learns from that one correction.

FAQ: the questions i actually get

i have the records. why is it still hit and miss?

records make you legitimate; reputation is still earned per sender. volume spikes, complaints and cold templates all drag the score. keep the sending pattern human and it stabilizes.

does switching providers fix deliverability?

only if the problem is the provider's sending infrastructure. if the records were missing, the new provider inherits the same hole. fix the records first, then judge the provider.

is a gmail.com sender address the problem?

for deliverability, no — google's servers authenticate fine. the cost of a free-mail sender is trust, not spam folders. that case is made in how do i set up professional email.