Squish/attentionSquish →

Why Do My Emails Go to Spam? A Plain-English Checklist

Your email keeps landing in spam and nobody can tell you why. Here is what inbox providers are actually checking, in plain English, and how to see your own score free.

By Squish··6 min read

You send a quote on Tuesday. On Friday you ring to follow up and hear the sentence every small business dreads: "Sorry — I never got that."

It was not lost. It was filed. Somewhere in their spam folder, underneath the offers and the newsletters, sits the most important email you sent that week. And the frustrating part is that nothing on your end looked wrong. It sent. It said delivered. It simply never arrived anywhere a human would look.

Here is what is actually going on, and how to see where you stand in about a minute.

The short version: they cannot verify it is you

Inbox providers — the big mail systems your customers use — are not judging your writing. They are asking a much colder question: can we prove this message really came from the domain it claims to come from?

Anyone can put your business name in the "from" line of an email. That is not a flaw somebody forgot to fix; it is how mail has worked since the beginning. So the defence was bolted on afterwards, in the form of three records that live with your domain and vouch for your mail.

If those records are missing, incomplete, or contradict each other, you are an unverified sender. Unverified mail does not get rejected outright — that would be too obvious. It gets quietly deprioritised. Into the spam folder, into the promotions tab, into the void.

The three records, without the acronym soup

SPF is a list of who is allowed to send email using your domain. Your mail provider is on it. Your invoicing software should be on it. Your booking system, your newsletter tool, your accountant's portal that emails receipts on your behalf — all of them need to be on it. If something sends as you and is not on the list, that mail looks forged.

The most common problem we see here is not a missing list. It is a list that was correct two years ago and has not kept up with the software the business added since.

DKIM is a signature. Your mail server stamps each message with a cryptographic mark that the receiving server checks against a key published on your domain. If the stamp matches, the message genuinely came from you and nobody altered it on the way. If there is no stamp at all, there is nothing to check.

DMARC is the instruction that ties the other two together. It tells receiving servers what to do when a message fails those checks — ignore it, quarantine it, reject it — and it can send you reports about who is sending mail in your name. Without DMARC, the other two records are advice. With it, they are a policy.

You do not need to understand the cryptography. You need all three to exist, agree with each other, and know about every system that sends on your behalf.

The reasons that have nothing to do with records

Records are the biggest cause, and they are not the only one. Before you go rebuilding anything, rule these out too.

  • Your domain is very new. A domain nobody has ever received mail from is treated cautiously for a few weeks. This one solves itself, as long as everything else is in order.
  • You are on a blocklist. These are shared lists of domains and addresses associated with spam. You can land on one through no fault of your own — an old shared server, a compromised mailbox, an address someone else used badly before you. It is fixable, but only once you know.
  • You sent something that reads like bulk mail. One message to two hundred recipients from a normal mailbox looks like exactly what filters are built to catch. Newsletters belong in a tool built for newsletters.
  • Your reply-to points somewhere else. Mail that claims to be from one domain and asks for replies at another is a classic scam pattern, and filters know it.
  • Someone marked you as spam. Once, a while ago, possibly by accident. It carries weight.

How to see where you actually stand

None of this is guesswork. It is all published, publicly, on your own domain — which means you can check it yourself right now.

Run the Email Deliverability Test on your domain. It reads your SPF, DKIM and DMARC setup the way a receiving mail server would, and hands back a graded result with plain-English findings. It is complimentary, it takes about a minute, and it does not ask you to sign up for anything.

If the trouble looks like it is specifically DMARC — you were told to have one, or you have one and are not sure it is doing anything — the DMARC Checker goes deeper on just that record. And if you suspect the blocklist problem, the Blacklist Checker will tell you in seconds whether your domain or its address is sitting on one of the major lists.

What to fix first

If the check comes back with gaps, the order matters more than people expect.

  1. Get SPF listing every system that sends as you. Walk through your software and write the list down first. Half of all deliverability problems are one forgotten tool.
  2. Turn DKIM on. Most mail providers support it; on plenty of accounts it is simply switched off.
  3. Add DMARC last, gently. Start it in monitoring mode so it reports without blocking anything, read what comes back for a few weeks, then tighten it. A DMARC policy set to reject before the other two records are right will stop your own legitimate mail. This is the step where enthusiasm does real damage.

None of that is glamorous. All of it is the difference between your quote being read and your quote being filed.

And if you would rather not

It is genuinely fine to not want to own this. Most business owners have no reason to know what a DKIM key is, and the honest reading of the checklist above is that it is somebody's job, not everybody's.

That is the version we run. On managed Microsoft 365, the records are configured when your mail is set up — the sending list, the signature, the policy — and they are kept current as you add software, because we are the ones adding it. Migrations come with the setup done rather than left as homework. If something starts landing in spam later, it becomes a case with a person on it, not an afternoon of your life spent reading about DNS.

Start with the check. Run the Email Deliverability Test on your own domain and see the grade. Plenty of businesses find they are already fine — and the ones that are not usually find it is one missing record, put there in ten minutes, quietly costing them customers for years.