A customer swears they never got your invoice. A lead fills out your contact form and the notification lands in your own spam folder. A vendor forwards you an odd email "from you" that you never sent. These look like three separate problems. Very often they trace back to the same three settings on your domain.
SPF, DKIM and DMARC are short records on your domain that prove your emails really come from you. SPF lists who's allowed to send for you, DKIM puts a tamper proof seal on each message and DMARC tells inboxes what to do when a message fails. When they're missing or out of date, your legitimate email looks suspicious and lands in spam.
Why real business email ends up in spam
Email was built decades ago with no way to prove who sent a message. Anyone can type any "From" address, a bit like writing any return address on an envelope. Spammers and scammers took full advantage.
So inbox providers like Gmail and Outlook got suspicious. When a message arrives claiming to be from yourbusiness.com, they look for proof. If the proof is missing, or doesn't match, the message gets treated like a stranger at the door. Sometimes it's let in, sometimes it's sent to spam and sometimes it's turned away.
Google's own email sender guidelines say it directly: "Messages that aren't authenticated with these methods might be marked as spam or rejected." The methods it means are SPF, DKIM and DMARC.
SPF, DKIM and DMARC, with one analogy
Think of your business as an office building, and every email as a package leaving it. These records live in your domain's DNS, the public settings that tell the internet where your website and email are.
SPF: the list at the front desk
SPF (Sender Policy Framework) is a guest list posted at the front desk. It names every service allowed to send mail for your domain: your email provider, your invoicing tool, your website's form. Google describes it this way: "SPF prevents spammers from sending unauthorized messages that appear to be from your domain." If a sender isn't on the list, that's a red flag.
DKIM: the wax seal
DKIM (DomainKeys Identified Mail) is a seal stamped on each package. The receiving side checks the seal against a key you publish. If it matches, the message really came from your domain and wasn't changed on the way. In Google's words, "Receiving servers use DKIM to verify that the domain owner actually sent the message."
DMARC: the instructions to security
DMARC is the note you leave with building security: here's what to do with a package that fails the checks. You can ask them to just watch and report, move it to spam or turn it away. Google puts it simply: "DMARC tells receiving servers what to do with your messages that don't pass SPF or DKIM." DMARC can also send you reports, which is how you find out someone is sending mail pretending to be you.
Where it breaks for small businesses
I see the same few patterns again and again:
- The website form. Your site sends a notification "from" your domain, but the web server isn't on your SPF list and doesn't sign with DKIM. Inboxes treat it as a fake. That's how leads die in spam. More on that in Is your contact form actually sending?
- The new tool. You started sending invoices, newsletters or appointment reminders through a new service, and nobody added it to your records.
- Two SPF records. Someone added a second one instead of editing the first, and now neither works as intended.
- No DMARC at all. Nothing tells inboxes how to treat fakes, and nobody gets the reports.
- Spoofing. Scammers send fake invoices or payment requests using your domain name. Without these records, it's easier for those fakes to reach your customers looking like you.
What Gmail now requires
Google tightened the rules for anyone sending to Gmail addresses. Its guidelines say: "Starting February 1, 2024, all email senders who send email to Gmail accounts must meet the requirements in this section." For every sender, the first item is to "Set up SPF or DKIM email authentication for your sending domains."
Senders who send more than 5,000 messages a day to Gmail accounts have a longer list. That includes SPF and DKIM together, a DMARC record and one click unsubscribe on marketing messages. Most small businesses aren't near that volume. I still set up all three, and Google recommends the same: "To improve email delivery, we recommend that you always set up SPF, DKIM, and DMARC for your domains."
And if you skip it, Google spells out the cost: "If you don't meet the requirements described in this article, your email might not be delivered as expected, or might be marked as spam."
How to check your own domain in ten minutes
- Send a test. Email a personal Gmail address from your business account. Then submit your own website form. See where each lands.
- Look at the header. In Gmail, open the message, click More next to Reply, then Show original. The header is the hidden routing information attached to every email. Look for the lines that mention spf, dkim and dmarc and whether each says pass.
- Get a second opinion. Copy that header into Google's free Admin Toolbox Messageheader tool, which lays it out in plain view.
- List your senders. Write down every service that sends email as your domain: email provider, website, invoicing, newsletters, scheduling. Each one needs to be covered.
- Check with whoever manages your DNS. Ask them to show you your SPF, DKIM and DMARC records and confirm there's only one SPF record.
Fixing it yourself: what it takes
These are a few lines of text in your DNS settings. You can do it. Here's what it really involves.
Time. An hour or two if you have one email provider and a simple site. Longer if several tools send as you, since each has its own setup steps.
Skills. You need to be comfortable editing DNS, where one typo can stop email or even take your website offline. You'll also need to read DMARC reports, which arrive as files that aren't friendly to read.
Tools. Login access to your domain registrar or DNS host, your email provider's admin panel and each sending service's setup guide.
The risk. Setting DMARC to reject too early can block your own legitimate mail, like the invoices from that tool you forgot about. The safe path is to start by only watching reports and tighten step by step.
If you're comfortable in DNS settings, go for it. If the words "TXT record" make you tired, that's useful to know too.
Get your email set up once, and kept right
Our email setup covers SPF, DKIM and DMARC for your domain, and your domain and DNS are documented in your name. When a site is on our care plan, we monitor for broken forms and run a monthly check that everything still works, which includes making sure form notifications still reach you. None of this makes every message land in the inbox. Spam filters weigh a lot of things. It removes the most common reason good email gets flagged.
For the other quiet problems that cost leads, see six silent website failures. And if you'd rather have someone keep your email records and forms in shape, ask us about a care plan.



