Why your emails land in spam
Email providers (Gmail, Outlook, Yahoo) check whether a message is really allowed to be sent in the name of your domain. Without a clear answer, the message is treated as suspicious. Three DNS records provide that answer: SPF, DKIM, and DMARC.
The three protections, one sentence each
- SPF lists the servers allowed to send email for your domain.
- DKIM adds a digital signature to every message; the recipient checks it against a key published in your DNS.
- DMARC says what to do when SPF and DKIM fail (nothing, quarantine, or reject) and where to send the reports.
For DMARC to pass, the domain visible in the “From” address must match the domain validated by SPF or DKIM. This is called alignment.
What the records look like
Examples for Microsoft 365 and Google Workspace. Your services may differ: always check your provider’s documentation.
SPF, Microsoft 365 (TXT on your domain)
v=spf1 include:spf.protection.outlook.com -all
SPF, Google Workspace (TXT on your domain)
v=spf1 include:_spf.google.com ~all
DMARC (TXT on _dmarc.yourdomain.com)
v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.comFor DKIM, Microsoft 365 publishes two CNAME records (selector1._domainkey and selector2._domainkey) and Google Workspace publishes one TXT record (google._domainkey). Your provider gives you the exact values.
How to check your domain
- Send a message from your business address to a personal Gmail address, open it, then choose “Show original”: Gmail shows PASS or FAIL for SPF, DKIM, and DMARC.
- Look up your records with a DNS lookup tool, or with the command
nslookup -type=txt yourdomain.com(SPF). For DMARC, query_dmarc.yourdomain.com; for DKIM, query your provider’s selector (selector1._domainkey.yourdomain.comorgoogle._domainkey.yourdomain.com). - Check that there is only one SPF record. Two SPF records make the check fail.
The most common mistakes
- A second SPF record added by another provider, instead of one combined record.
- Too many services in the SPF record: the standard limits it to 10 DNS lookups.
- A service that sends in your name (newsletter, invoicing, CRM) but is neither in the SPF record nor signed with DKIM.
- DMARC left at
p=noneforever: it monitors, but does not protect. - Jumping straight to
p=rejectwithout reading the reports: legitimate email can get blocked.
A safe order for setting up DMARC
- List every service that sends email with your domain (Microsoft 365 or Google, newsletter, invoicing, website forms).
- Publish a single SPF record that covers them, and turn on DKIM for each.
- Publish DMARC with
p=noneand an address for reports (rua), then read the reports for a few weeks. - Fix what fails, move to
p=quarantine, then top=rejectonce everything is in order.
What changes with Gmail, Yahoo, and Microsoft
Since February 2024, Gmail and Yahoo require SPF, DKIM, and DMARC from senders of large volumes (Google sets the threshold at more than 5,000 messages a day to Gmail; Yahoo does not publish one). Microsoft has applied similar requirements to Outlook.com, Hotmail.com, and Live.com since May 5, 2025 (5,000 messages a day or more); non-compliant messages can be rejected. Even at small volumes, these records help your email arrive.