domains, dns, and email

your email is landing in spam. three DNS records decide it.

A customer writes in: the receipt never arrived. It did. It went to spam. The same records that decide where a store's order confirmation lands also decide where your invoices, password resets, and plain business email land. Three DNS records, and most businesses have never looked at them.

three records decide trust

SPF answers one question: which servers are allowed to send email for your domain. It is a DNS record listing your legitimate senders (your email provider, your store platform, your marketing tool). A message from a server on the list passes. A message from anywhere else fails.

DKIM puts a cryptographic signature on every message you send. The receiving inbox checks the signature against a public key in your DNS. A valid signature proves the message really comes from your domain and wasn't altered on the way. Each app that sends for you needs its own DKIM key turned on.

DMARC is the rule you publish for what inboxes should do when the other two fail: deliver anyway, quarantine, or reject. It also requires the passing checks to align with the address in the From line, and it sends you reports about who is sending as your domain. Without DMARC, the other two records carry no instructions.

check yours in five minutes

  • Send yourself a real message. If you run a store, place a test order and open the confirmation email. If you don't, send a normal email from your main system to a Gmail address you control.
  • Open the headers. In Gmail: the three-dot menu on the message, then "Show original". The summary at the top names all three checks.
  • Read three lines. You want spf=PASS, dkim=PASS, dmarc=PASS. Anything else, you found the leak.

what usually breaks

  • SPF still lists an email provider the business left years ago, and doesn't list the app that actually sends today.
  • DKIM was never switched on for the platform sending the real mail. Most tools ship with it off.
  • DMARC doesn't exist, so the inbox has no rule to apply and judges the message on reputation alone.
  • Nobody can say who has access to the DNS, so a five-minute record change takes three weeks and two support tickets.

The stakes went up in 2024 and stayed up. Google's published sender guidelines require SPF or DKIM from every sender, and all three records, aligned, plus one-click unsubscribe, from any domain sending 5,000 or more messages a day to Gmail. Yahoo enforces matching rules and Microsoft has followed for consumer Outlook. As of August 2026 this is the baseline for reaching the inbox, not an optimization.

what the fix involves

Alignment work, mostly. List every system that legitimately sends as your domain: email provider, store platform, invoicing tool, marketing app, helpdesk. Make SPF name exactly those senders. Turn on DKIM in each of them. Publish DMARC, start in monitor mode, read the reports, then tighten the policy once every legitimate sender passes.

And write down where the DNS lives and who can log into it, because the next email problem is usually an access problem. This whole area is one of the eight services: domains, DNS and email.

common questions

Why does my email go to spam when I'm not a spammer?

An inbox can only judge what it can verify. When SPF, DKIM, or DMARC fails or is missing, your message looks the same as one forged by a spammer using your domain, and it gets sorted the same way. Authentication is how honest senders prove the difference.

Do I need DMARC if SPF and DKIM already pass?

Yes. Without DMARC there is no published rule for failures and no requirement that the passing domain matches your From address, so a forger can pass both checks on their own domain while displaying yours. DMARC closes that gap, and Gmail and Yahoo require it outright for bulk senders.

Will this get my cold outreach delivered?

Authentication keeps legitimate mail out of spam. It does not make unwanted mail welcome, and we don't take on deliverability work whose goal is mass cold email. If your receipts, invoices, and replies are landing in spam, that we fix.

Can you just fix it for us?

Yes. It starts with a stack review: we check all three records, every app that sends as you, and who can log into the DNS, then hand you written findings and a prioritized list. Fixed fee, one week, from $1,500, yours either way.

the first step

three passes, or you found the leak.

A stack review checks your records, your senders, and your access in one week. Fixed fee, from $1,500. The findings document is yours whether or not we work together.

book a stack review