Blog · Email
Business mail in the spam folder, and the DNS records that cure it
By the Hosting Seller team Published 27 July 2026 7 min read

A particular sinking feeling arrives when a customer mentions they found it in spam. Your invoice. Your quote. The proposal you gave up an evening to write, filed away between the pills and the princes. For a small business sending from its own domain, how the message was worded is hardly ever the culprit. Authentication is: your domain has not proved, cryptographically, that this mail actually came from you.
Google and Yahoo tightened their bulk-sender rules in 2024, and nobody has loosened anything since, so unauthenticated mail no longer gets the benefit of any doubt. Here is the cheerful part. Authentication reduces to three DNS records, none of them costs a penny, and the whole job fits inside twenty minutes.
The three records in plain English
SPF is the guest list. A DNS record naming which servers may send mail on behalf of your domain, nothing more. On arrival, the receiving server matches the sender's IP against that list, and anything posted from elsewhere fails. One record, one line. Our SPF walkthrough writes it alongside you.
DKIM is the wax seal. Every outgoing message gets signed by your mail server with a private key, while the matching public key sits in DNS where receivers can check it. A valid signature shows the message was neither forged nor tampered with in transit. Switching it on comes down to a toggle in the panel plus one record.
DMARC is the instruction card. It tells a receiver what to do when SPF and DKIM both fail: deliver anyway, quarantine, or refuse outright. It also says where the reports should be sent. Gmail now expects one from any domain hoping for the inbox. Start at p=none, watch for a while, then tighten the policy once those reports come back clean.
Why authenticated mail still lands in spam
Application mail taking the wrong road. Your WordPress contact form, or the invoicing app, sends "from" your domain by way of a server that never made it onto your SPF list, so every one of those messages fails. Push application mail through authenticated SMTP instead, which for WordPress takes ten minutes.
Two SPF records. Exactly one is permitted per domain. A second, normally left behind by whoever hosted you before, breaks SPF for good. Fold the pair into one line.
Sending as your domain out of personal webmail. Borrowing a personal Gmail's "send as" for you@yourdomain, with no proper SMTP authentication behind it, fails DMARC at every strict receiver. Put your domain's mail through your domain's own service.
One further factor has nothing whatever to do with DNS: history. A domain that leaps from silence to hundreds of identical messages reads like a hijacked mailbox. Warm a new domain up slowly, and keep invoices and receipts apart, by volume, from anything you send as marketing.
The 20-minute checklist
One, write down everything that legitimately sends as your domain: the mailbox itself, the forms on your website, your invoicing tool. Two, publish one SPF record covering that list and nothing beyond it. Three, turn DKIM signing on at your mail host and publish the key. Four, publish DMARC at p=none with a reporting address, wait a week, read whatever arrives, then shift to quarantine. Five, send a test message to a Gmail address and open Show original. Three green PASS lines and you are finished.
On our email hosting we generate the SPF and DKIM records for every mailbox domain, and the panel prints exactly what needs publishing, so most of those twenty minutes goes on reading. Inbound spam filtering comes with every plan. Where a domain needs heavier work than that, dedicated mail filtering sits in front of any mailbox, no matter who hosts it.
Short answers
My business emails are not spam, so why do they keep landing there?
Nearly always because authentication is absent. With no SPF, DKIM or DMARC in place, a receiving server has no way to confirm the mail truly came from your domain, and under the 2024 Gmail and Yahoo rules unauthenticated post gets demoted by default. Wording counts for far less than owners imagine.
SPF, DKIM and DMARC: what are they, in plain terms?
SPF publishes a list of the servers permitted to send your domain's mail. DKIM adds a signature proving each message is genuine and has not been altered. DMARC instructs receivers on what to do when either check fails, and sends reports back to you. Between them, they decide inbox or junk.
Once the records are in, how long before deliverability improves?
Authentication kicks in the moment DNS propagates, so hours rather than days. Reputation is slower to rebuild. Expect steady gains over two to four weeks of consistent, authenticated sending.
Read next
Email Hosting
Mailboxes on your own domain, with SPF and DKIM pre-generated and spam filtering included.
Stop Email Going to Spam (Tutorial)
A hands-on version, every single record spelled out.
Mail Filtering
Filtering both ways, inbound and outbound, ahead of any mailbox.
Also on the blog
Web hosting costs in 2026: the whole bill
That number on the shelf edge is marketing. What you pay from year two onward is the actual deal. Here is the three-year sum, done in public.
“Unlimited” web hosting, and where the ceilings actually sit
A disk has a size. Read 'unlimited' as 'limited by units you have not bumped into yet': inodes, CPU seconds, one fair-use paragraph.
A free domain with your hosting: four things to check before claiming it
That free year is real enough. Year two carries the questions worth asking: what the renewal rate is, whose name sits on the record, what walking away costs you.
The product behind the posts
Flat renewals, limits printed on the tin, free migration and a help desk that replies — everything above, in plan form.
Browse Hosting Plans