The bouncers got stricter
Think of every inbox as an exclusive club. Your email turns up at the door, and a bouncer decides whether it gets in, gets sent to the back room (the spam folder), or gets turned away. For years, those bouncers were fairly relaxed. A reasonable-looking message from a reasonable-looking server usually got in. Not any more.- February 2024: Google and Yahoo announced new rules for anyone sending to their users. Everyone needs basic authentication. Bigger senders (more than 5,000 messages a day to Gmail) need the full set: SPF, DKIM and DMARC, plus one-click unsubscribe and low complaint rates.
- May 2025: Microsoft followed for Outlook.com, Hotmail and Live addresses.
- November 2025: Gmail stopped giving second chances. Mail that fails the checks is now rejected outright, rather than delayed and retried.
Meet the three checks
SPF, DKIM and DMARC sound like a firm of solicitors. They're actually three simple records that together answer one question: is this email really from who it says it's from?SPF: the guest list
SPF (Sender Policy Framework) is a list of the servers allowed to send email for your domain. When your message arrives, the receiving server checks whether it came from somewhere on the list. If you send from your hosting mailbox, a newsletter tool and your website's contact form, all three need to be on that list. The most common mistake we see? Two guest lists. You sign up for a new newsletter service, it tells you to add an SPF record, and you add a second one instead of adding the service to the first. A domain can only have one SPF record. Two of them is an error, and it can cause all of your mail to fail the check, not just the new service's.DKIM: the wax seal
DKIM (DomainKeys Identified Mail) adds a digital signature to every message you send. It's the modern version of a wax seal on a letter: proof that it came from you and hasn't been opened and tampered with on the way. Your mail server signs each message with a private key. The matching public key sits in your DNS so anyone can check the seal. If the two don't match, perhaps because the DNS record was never published or went missing during a move, the seal looks forged. Here's the catch many people miss. Google expects your mail to be signed, and SPF on its own isn't enough. Plenty of businesses set up SPF years ago, added DMARC when they read about the new rules, and never published a DKIM record at all.DMARC: the instructions for the bouncer
DMARC ties the other two together. It tells receiving servers what to do when a message fails SPF and DKIM: let it in anyway, put it in spam, or turn it away. It also lets you ask for reports, so you can see who is sending email in your name. That last part matters more than you might think. If a scammer is sending invoices that look like they're from your domain, DMARC is how you find out, and eventually how you stop them. The sensible starting point is a policy ofp=none. That means "don't change anything yet, just send me reports". Once you're confident all your genuine email passes, you can tighten it.The other usual suspects
Authentication is the big one, but it's not the only reason good email goes astray. These are the other patterns we see again and again.Your website is sending the "wrong" way
WordPress, WooCommerce and Magento all send email: order confirmations, password resets, contact form notifications. Out of the box, many of them use PHP's built-in mail function. It's easy, needs no setup, and is the method most likely to end up in spam, because those messages often aren't signed properly. Switching your site to send through a real mailbox using SMTP is often the single most effective fix. It sends your website's email down the same authenticated route as the email you write yourself.You're sending newsletters from your everyday mailbox
Sending a newsletter to 800 people from the same mailbox you use for customer emails is a bit like using your front door as a loading bay. You'll hit sending limits, and if a few people mark it as spam, your day-to-day email suffers too. A dedicated email marketing tool keeps bulk mail separate, handles unsubscribes properly, and protects the reputation of the address your customers actually reply to.Your DNS lives somewhere else
If your domain's DNS is managed at Cloudflare, your registrar or another provider, that's where your SPF, DKIM and DMARC records need to live. We often see perfectly correct records added in cPanel that have no effect, because the domain's nameservers point somewhere else entirely.Someone else is using your account
If an email account or website has been compromised, spam can go out in your name without you knowing. Your own messages might look perfectly clean, but your domain's reputation is being dragged down behind the scenes. If delivery suddenly gets worse for no obvious reason, check your sent folder for messages you didn't write.Your 10-minute email health check
Grab a cup of tea. Here's how to check where you stand.- Open Email Deliverability in cPanel. You'll find it under Email. It checks your SPF and DKIM records for every domain on your account and flags anything missing or mismatched. If you see a problem, the Repair button will usually fix it.
- Count your SPF records. Look in your DNS for records starting
v=spf1. There should be exactly one. - List everything that sends email as you. Your mailboxes, your website, your newsletter tool, your CRM, your accounting software. Each one needs to be covered by your SPF record and set up with its own DKIM record.
- Check you have a DMARC record. If not, start with a simple
p=nonepolicy. Our guide below shows exactly what to add. - Check where your DNS lives. If your nameservers don't point to us, make your changes at your DNS provider instead.
- Switch your website to SMTP. Especially if it's a shop sending order confirmations.
- Send yourself a test. Send a message to a personal Gmail or Outlook address and look at the message headers. You want to see a pass for SPF, DKIM and DMARC.
DNS changes can take a few hours to reach everywhere, so give it up to a day before you test again.
Want to go deeper?
Our knowledge base has step-by-step guides for every part of this:- Why are my sent emails going to spam or being rejected?
- Understanding SPF records
- How to read an email bounce message
- How to set up SMTP authentication in WordPress
- What to do if your domain is blacklisted
Email that gets through, with people who can help
Every account with us comes with the basics done for you: DKIM keys set up on the server, a sensible SPF record from day one, and every outgoing message passing through our filtering gateway to keep our sending reputation clean. Incoming mail is filtered for spam before it reaches you. And for newsletters and campaigns, MailMachine keeps your bulk sending well away from your everyday inbox. But the setups that cause the most trouble are the ones that have grown over time: a newsletter tool here, a CRM there, DNS at one company and email at another.That's where it helps to have people who'll actually look. If your emails are going missing and you can't work out why, get in touch with our support team. Send us a bounce message or a copy of a message that landed in spam, and we'll check your records, your mail logs and the reputation of the server you send from, and tell you exactly what to fix.
Because your email shouldn't be lost in the post.


