← All guides ← Back to Home
Email • Deliverability Guide

Why your business emails go to spam (SPF, DKIM and DMARC explained)

By Jeffry, CF IT Solutions · Published 2 October 2026

If your business emails keep landing in customers' junk folders, the most common cause is missing or broken email authentication. Three DNS records, called SPF, DKIM and DMARC, prove to Gmail, Outlook and everyone else that your emails really come from you. Without them, your mail looks the same as a scammer pretending to be your business.

This guide explains what each record does, how to check yours, and how to set them up for Microsoft 365 or Google Workspace.


Why this matters more than it used to

Since February 2024, Gmail requires every sender to have SPF or DKIM in place, and anyone sending large volumes (5,000 or more emails a day to Gmail addresses) must have SPF, DKIM and DMARC. Yahoo brought in matching rules, and Microsoft followed with similar requirements for high volume senders to Outlook.com in 2025. Even if you send far less than that, mail providers now treat unauthenticated email with much more suspicion. See Google's email sender guidelines.

SPF, DKIM and DMARC in plain English

RecordWhat it doesWhat goes wrong without it
SPFA list of the services allowed to send email for your domain, such as Microsoft 365, your website or your invoicing software.Mail from a service that isn't on the list looks forged.
DKIMA digital signature added to every email, which receiving servers check against a key in your DNS.Receivers can't confirm the email wasn't altered or faked.
DMARCTells receivers what to do when an email fails SPF and DKIM, and sends you reports on who is sending as your domain.Scammers can send as your domain and nobody is told to stop them.

Step 1: Check what you have now

Free tools like Google Admin Toolbox Check MX or MXToolbox will look up your domain and show whether SPF, DKIM and DMARC exist and whether they're valid. A quicker real world test: send an email to a Gmail address, open it, choose Show original, and look for SPF, DKIM and DMARC each showing PASS.

Step 2: Fix SPF

Your SPF record is a TXT record on your domain that starts with v=spf1. A few rules catch most businesses out:

  • Only one SPF record per domain. Two separate SPF records break both. Combine them into one.
  • Include every service that sends as you. Microsoft 365 uses include:spf.protection.outlook.com and Google Workspace uses include:_spf.google.com. Add any others you use, like your website's mail service, CRM or invoicing tool.
  • Stay under 10 lookups. Each include can trigger more DNS lookups behind the scenes, and going over 10 makes the whole record fail.
  • End it properly. Most businesses finish with ~all while testing and move to -all once everything is confirmed.

A simple Microsoft 365 only example: v=spf1 include:spf.protection.outlook.com -all

Step 3: Turn on DKIM

DKIM is switched on inside your email platform, then you add the records it gives you to your DNS.

  • Microsoft 365: in the Microsoft Defender portal, go to the DKIM settings for your domain, publish the two CNAME records Microsoft shows you, then enable signing. Microsoft's steps are in Set up DKIM for your domain.
  • Google Workspace: in the Admin console, generate a DKIM key, add it as a TXT record, then start authentication. See Set up DKIM in Google Workspace.

If another service sends email as your domain, such as a newsletter platform, set up DKIM for that service too.

Step 4: Add DMARC, then tighten it

DMARC is a TXT record at _dmarc.yourdomain.com.au. Start in monitoring mode so nothing gets blocked while you check the reports:

v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com.au

Once the reports show your real email is passing, step the policy up to p=quarantine (failing mail goes to junk), and later p=reject (failing mail is refused). Moving straight to reject without checking first is a quick way to block your own invoices or website enquiries. More detail in Google's DMARC overview.

Common mistakes

  • Two SPF records after moving email providers
  • Forgetting the website contact form, which often sends as your domain through a different service
  • DKIM records added to DNS but signing never switched on
  • Jumping to a DMARC reject policy on day one
  • Old records left pointing at a provider you stopped using years ago

Still landing in spam after all three pass?

Authentication gets you through the door, but content and sending habits still count. Watch for a domain or IP on a blocklist, emails that are mostly one image, link shorteners, sudden large sends from a new domain, and lists of people who never asked to hear from you.

Rather have it fixed for you? I set up SPF, DKIM and DMARC properly, check every service that sends as your domain, and confirm your emails pass, from $350 per domain. Done remotely, anywhere in Australia. See the email deliverability fix or call Jeffry on 0406 160 140.