Blog · Email
Your business email keeps landing in spam, and here are the DNS records that fix it
By the HostingAlly team Published 27 July 2026 7 min read

A customer says "found it in spam" and something in your stomach drops. Your invoice, your quote, that proposal you spent an afternoon writing, all filed alongside the pills and the princes. Where a small business sends from its own domain, the content of the message is rarely to blame. Authentication is. Your domain has not proved, cryptographically, that the mail genuinely came from you.
Google and Yahoo tightened their bulk-sender rules back in 2024, and those requirements have only ratcheted upward since. Unauthenticated mail gets no benefit of the doubt now. Better news follows: authentication amounts to three DNS records, they cost nothing, and the entire job fits inside twenty minutes.
The three records, in plain English
SPF is the guest list. It's a DNS record naming the servers permitted to send mail on behalf of your domain. When mail arrives, the receiving server compares the sender's IP against that list, and anything sent from elsewhere fails. One record, one line. Our SPF walkthrough writes it alongside you.
DKIM is the wax seal. Every outgoing message gets signed by your mail server with a private key, while the public half sits in your DNS where receivers can check it. If the signature validates, nobody forged the message and nobody altered it on the way. Turning it on comes down to a panel toggle plus one record.
DMARC is the instruction card. It tells receivers how to handle a message when SPF and DKIM fail: deliver it anyway, quarantine it, or reject it outright. It also says where reports should go. Gmail now expects one from any domain hoping for inbox placement. Begin at p=none and watch, then tighten the policy once the reports come back clean.
Mistakes that keep authenticated mail stuck in spam
Application mail travelling the wrong path. Your WordPress contact form, or the invoicing app, sends 'from' your domain through a server that never appears in your SPF record, and every single message fails authentication. Route that application mail through authenticated SMTP instead. The WordPress version takes ten minutes.
More than one SPF record. A domain is allowed exactly one. Leave a second lying around, usually a relic from a previous provider, and SPF fails permanently. Merge the pair into a single record.
Spoofing the 'from' line out of free webmail. Sending as you@yourdomain through a personal Gmail's 'send as' feature, with no SMTP authentication behind it, fails DMARC at every strict receiver. Push domain mail through the domain's own mail service.
Then there's the factor that has nothing to do with DNS: engagement history. A domain that jumps from nothing to hundreds of identical messages overnight reads like a compromised mailbox. Warm new domains up slowly, and keep transactional sending (invoices, receipts) separate, in volume terms, from any marketing blast.
The 20-minute checklist
One: write down everything that legitimately sends as your domain, meaning the mailbox itself, the forms on your website, and your invoicing tool. Two: publish a single SPF record that covers precisely that list, nothing more. Three: turn DKIM signing on at your mail host and publish the key. Four: publish DMARC at p=none with a reporting address attached, wait a week, read what comes back, then move to quarantine. Five: fire a test at a Gmail address and open 'Show original'. Three green PASS lines is what you want to see.
With our email hosting, SPF and DKIM records come pre-generated for every mailbox domain, and the panel spells out exactly what to publish. Most of those twenty minutes you spend reading. Inbound spam filtering ships on every plan. For domains with heavier filtering demands, dedicated mail filtering can sit in front of any mailbox, hosted wherever it happens to live.
Quick answers
My business emails aren't spam, so why do they keep going to spam?
Nearly always missing authentication. With no SPF, DKIM or DMARC records in place, a receiving server has no way to confirm the mail truly came from your domain, and ever since the 2024 Gmail/Yahoo rules, unauthenticated mail gets demoted by default. Content counts for far less than owners imagine.
In plain terms, what are SPF, DKIM and DMARC?
SPF publishes a list of the servers permitted to send mail for your domain. DKIM adds a cryptographic signature showing each message is genuine and untouched. DMARC instructs receivers on what to do when either check fails, and mails you reports afterwards. Between them, they decide whether you land in the inbox or the spam folder.
Once the records are added, how long until deliverability improves?
Authentication bites the moment DNS propagates, so hours rather than days. Reputation is slower to mend. Expect steady improvement across two to four weeks of consistent, authenticated sending.
More from the blog
So what does web hosting actually cost in 2026?
Treat the signup price as an advert; the renewal is the actual product. Three-year arithmetic on 'cheap' hosting, done properly.
The truth about “unlimited” web hosting
Infinite disk does not exist on any server. Read 'unlimited' as marketing shorthand for 'capped by things nobody told you about': inodes, CPU seconds, fair-use clauses buried in the terms.
Before you claim that free domain with hosting, read this
Year one really is free. Everything worth asking concerns year two: the renewal figure, whose name sits on the registration, and how much effort walking away costs you.
Hosting that matches what this blog says
Flat renewals, printed limits, free migration and support that answers — the product version of everything above.
See Hosting Plans