Guide · Trust and delivery

Why business email goes to spam: a checklist

A message that lands in spam was judged by the receiving server, usually on a few checkable facts. This guide lists them in the order that fixes most problems first.

What the receiver checks

A receiving server decides from evidence. Does the domain publish records saying who may send for it? Is the message signed, and does the signature verify? Does the sending host match? Does the message look like the mail the domain normally sends? Most of this can be checked from the sender’s side before a message is sent.

The checklist, in order

  1. The four records are published. The MX, the SPF record, the DKIM key and the DMARC policy. The DNS records a mail domain needs explains them, and the client area shows whether DNS carries each one.
  2. There is one SPF record, and it lists every sender. RFC 7208 describes SPF as the way a domain explicitly authorises the hosts allowed to use its name. A second provider is added with an include in the same record.
  3. Outgoing mail is signed. RFC 6376 describes DKIM as a cryptographic signature through which the owner of a domain takes responsibility for a message. The key is created with the domain, and the record to publish is in the client area.
  4. A DMARC policy exists. RFC 7489 lets a domain say how receivers should treat a message that fails; p=none to begin, tightened as the reports show that real mail passes.
  5. The address is a real one. Replies go to an address someone reads, and the role addresses postmaster and abuse answer.
  6. The content looks like business mail. No all-capital subjects, no attachments from nowhere, no links that hide their destination, and an unsubscribe path for anything sent to a list.

Habits that build a reputation

  • Send from the domain’s own addresses, not from a personal mailbox elsewhere that merely quotes it.
  • Add a new domain’s volume gradually rather than sending thousands of messages on the first day.
  • Remove addresses that bounce, and do not write again to people who never answer or who report the mail.

When it still lands in spam

Read the message headers at the receiving end: they say whether SPF, DKIM and DMARC passed. A failure points to the record to fix. A pass on all three with spam still, points to content or reputation, and the remedy is time and consistency.

Questions

Which record matters most for delivery?

None alone. Receivers weigh SPF, DKIM and DMARC together, so a domain should publish all of them.

Is a signed message always delivered to the inbox?

No. A signature shows who takes responsibility for a message; the receiver still weighs content and the sender’s reputation.

How can the result be read?

In the headers of the received message, which record whether SPF, DKIM and DMARC passed.

Sources

The documents this guide’s statements rest on. Each link opens in a new page.

  1. RFC 7208: Sender Policy Framework (SPF)
  2. RFC 6376: DomainKeys Identified Mail (DKIM) Signatures
  3. RFC 7489: Domain-based Message Authentication, Reporting, and Conformance (DMARC)