Lost in the post: why your emails land in spam (and how to fix it)

Written by Jo Stonehouse 0 Comments
You send the quote. You wait. A day passes. Then two. You chase, a little awkwardly, and get the reply every small business dreads: "Sorry, it went to my junk folder." Or worse, you never find out at all. The order confirmation, the password reset, the invoice reminder. Each one quietly filed away where nobody looks, while your customer wonders why you went silent. If this sounds familiar, you're not alone. Email delivery is one of the things our support team is asked about most. And over the past 18 months, the rules have changed in a way that has caught a lot of good businesses out. The good news? Most of it comes down to three short lines of text in your DNS. Let's walk through what changed, what those lines do, and how to check yours in about 10 minutes.

The bouncers got stricter

Think of every inbox as an exclusive club. Your email turns up at the door, and a bouncer decides whether it gets in, gets sent to the back room (the spam folder), or gets turned away. For years, those bouncers were fairly relaxed. A reasonable-looking message from a reasonable-looking server usually got in. Not any more.
  • February 2024: Google and Yahoo announced new rules for anyone sending to their users. Everyone needs basic authentication. Bigger senders (more than 5,000 messages a day to Gmail) need the full set: SPF, DKIM and DMARC, plus one-click unsubscribe and low complaint rates.
  • May 2025: Microsoft followed for Outlook.com, Hotmail and Live addresses.
  • November 2025: Gmail stopped giving second chances. Mail that fails the checks is now rejected outright, rather than delayed and retried.
"But I'm not sending 5,000 emails a day," you might be thinking. Fair enough. The strictest rules are aimed at bulk senders. But the bouncers now look at everyone's ID, and messages that can't prove who they're from are the first to be treated with suspicion. The businesses we see with delivery problems are rarely big senders. They're usually small ones whose records were set up years ago and never looked at again.

Meet the three checks

SPF, DKIM and DMARC sound like a firm of solicitors. They're actually three simple records that together answer one question: is this email really from who it says it's from?

SPF: the guest list

SPF (Sender Policy Framework) is a list of the servers allowed to send email for your domain. When your message arrives, the receiving server checks whether it came from somewhere on the list. If you send from your hosting mailbox, a newsletter tool and your website's contact form, all three need to be on that list. The most common mistake we see? Two guest lists. You sign up for a new newsletter service, it tells you to add an SPF record, and you add a second one instead of adding the service to the first. A domain can only have one SPF record. Two of them is an error, and it can cause all of your mail to fail the check, not just the new service's.

DKIM: the wax seal

DKIM (DomainKeys Identified Mail) adds a digital signature to every message you send. It's the modern version of a wax seal on a letter: proof that it came from you and hasn't been opened and tampered with on the way. Your mail server signs each message with a private key. The matching public key sits in your DNS so anyone can check the seal. If the two don't match, perhaps because the DNS record was never published or went missing during a move, the seal looks forged. Here's the catch many people miss. Google expects your mail to be signed, and SPF on its own isn't enough. Plenty of businesses set up SPF years ago, added DMARC when they read about the new rules, and never published a DKIM record at all.

DMARC: the instructions for the bouncer

DMARC ties the other two together. It tells receiving servers what to do when a message fails SPF and DKIM: let it in anyway, put it in spam, or turn it away. It also lets you ask for reports, so you can see who is sending email in your name. That last part matters more than you might think. If a scammer is sending invoices that look like they're from your domain, DMARC is how you find out, and eventually how you stop them. The sensible starting point is a policy of p=none. That means "don't change anything yet, just send me reports". Once you're confident all your genuine email passes, you can tighten it.

The other usual suspects

Authentication is the big one, but it's not the only reason good email goes astray. These are the other patterns we see again and again.

Your website is sending the "wrong" way

WordPress, WooCommerce and Magento all send email: order confirmations, password resets, contact form notifications. Out of the box, many of them use PHP's built-in mail function. It's easy, needs no setup, and is the method most likely to end up in spam, because those messages often aren't signed properly. Switching your site to send through a real mailbox using SMTP is often the single most effective fix. It sends your website's email down the same authenticated route as the email you write yourself.

You're sending newsletters from your everyday mailbox

Sending a newsletter to 800 people from the same mailbox you use for customer emails is a bit like using your front door as a loading bay. You'll hit sending limits, and if a few people mark it as spam, your day-to-day email suffers too. A dedicated email marketing tool keeps bulk mail separate, handles unsubscribes properly, and protects the reputation of the address your customers actually reply to.

Your DNS lives somewhere else

If your domain's DNS is managed at Cloudflare, your registrar or another provider, that's where your SPF, DKIM and DMARC records need to live. We often see perfectly correct records added in cPanel that have no effect, because the domain's nameservers point somewhere else entirely.

Someone else is using your account

If an email account or website has been compromised, spam can go out in your name without you knowing. Your own messages might look perfectly clean, but your domain's reputation is being dragged down behind the scenes. If delivery suddenly gets worse for no obvious reason, check your sent folder for messages you didn't write.

Your 10-minute email health check

Grab a cup of tea. Here's how to check where you stand.

  1. Open Email Deliverability in cPanel. You'll find it under Email. It checks your SPF and DKIM records for every domain on your account and flags anything missing or mismatched. If you see a problem, the Repair button will usually fix it.
  2. Count your SPF records. Look in your DNS for records starting v=spf1. There should be exactly one.
  3. List everything that sends email as you. Your mailboxes, your website, your newsletter tool, your CRM, your accounting software. Each one needs to be covered by your SPF record and set up with its own DKIM record.
  4. Check you have a DMARC record. If not, start with a simple p=none policy. Our guide below shows exactly what to add.
  5. Check where your DNS lives. If your nameservers don't point to us, make your changes at your DNS provider instead.
  6. Switch your website to SMTP. Especially if it's a shop sending order confirmations.
  7. Send yourself a test. Send a message to a personal Gmail or Outlook address and look at the message headers. You want to see a pass for SPF, DKIM and DMARC.

DNS changes can take a few hours to reach everywhere, so give it up to a day before you test again.

Want to go deeper?

Our knowledge base has step-by-step guides for every part of this:

Email that gets through, with people who can help

Every account with us comes with the basics done for you: DKIM keys set up on the server, a sensible SPF record from day one, and every outgoing message passing through our filtering gateway to keep our sending reputation clean. Incoming mail is filtered for spam before it reaches you. And for newsletters and campaigns, MailMachine keeps your bulk sending well away from your everyday inbox. But the setups that cause the most trouble are the ones that have grown over time: a newsletter tool here, a CRM there, DNS at one company and email at another.

That's where it helps to have people who'll actually look. If your emails are going missing and you can't work out why, get in touch with our support team. Send us a bounce message or a copy of a message that landed in spam, and we'll check your records, your mail logs and the reputation of the server you send from, and tell you exactly what to fix.

Because your email shouldn't be lost in the post.

You might also like...

About the Author

Jo Stonehouse is the Founder and Managing Director at Kualo. He loves helping businesses succeed online, and is based in London were he lives with his wife, Sali, daughter Seren, son Griff and dog, Milo.