✉️

Why Your Business Emails Go to Spam (and the 30-Minute Fix)

October 2026•6 min read
EmailDeliverabilityHow-to
Why Your Business Emails Go to Spam (and the 30-Minute Fix)

Your emails are landing in spam and your host says everything looks fine. Here is the fine-print version: in February 2024, Gmail and Yahoo turned email authentication from a best practice into an entry ticket for anyone sending 5,000 or more emails a day to their users, and in November 2025 Gmail started rejecting non-compliant mail outright, per PowerDMARC's tracking of the enforcement rollout. You do not have to be a bulk sender for this to matter. The same three records decide whether your quote reaches the customer's inbox or the void.

The fix takes about thirty minutes, most of it waiting for DNS to propagate. Here is what to do.

The three records that decide your fate

When Gmail gets your email, it checks three things in your domain's DNS before it trusts you:

  • SPF is the list of servers allowed to send mail as you. No SPF, or a stale one from a service you stopped using in 2021, means receivers cannot tell your real email from a forgery.
  • DKIM is a cryptographic signature your sending service attaches to every message. It proves the email was not altered in transit. Your email host or Google Workspace generates it; you publish the public key.
  • DMARC is the policy that tells receivers what to do when SPF and DKIM fail: nothing, quarantine, or reject. Gmail now requires at least a published DMARC record, even at the do-nothing level, per Google's sender guidelines.

If any of the three is missing, you are asking every inbox on earth to take your word for it. They will not.

The 30-minute fix

Minute 0-5: check what you have. Look up your domain on Google's Admin Toolbox Check MX tool or MXToolbox and read the SPF, DKIM, and DMARC results. Most small business domains are missing at least one. Knowing which one is the whole diagnosis.

Minute 5-15: publish SPF. Add a TXT record to your domain's DNS. If you send from one service, it is one record naming that service. If you send from your host, your CRM, and your invoicing app, every one of them has to be in it. More than ten DNS lookups in the record breaks it, so keep it tight.

Minute 15-25: enable DKIM. This one lives in your sending service, not your registrar. Google Workspace, Microsoft 365, and every real email platform have a DKIM page that generates the key; you paste the TXT record it gives you into DNS. Two records, done.

Minute 25-30: publish DMARC at p=none. Start at the monitoring level so you get reports without breaking anything, then tighten it once you see clean reports for a week or two. A basic record is one TXT line. Perfect is the enemy of published.

The habits that keep you out of spam afterward

Authentication gets you in the door; behavior keeps you there. Gmail wants your spam complaint rate under 0.3%, per Google's sender FAQ, and anything you send in bulk needs a one-click unsubscribe. Beyond the rules, the practices that matter: never buy an email list, ever; make the unsubscribe link obvious instead of hiding it; and send from a domain you own, not a free address. Every "great deal on 50,000 leads" email is a spam-complaint factory aimed at your own domain's reputation.

When to call someone

If you did all of the above and your mail still lands in spam, the problem is usually a burned domain reputation from an old list or a compromised account sending junk in your name. That is a cleanup job, not a settings job, and it is worth paying someone for an hour. But nine times out of ten, the three records are the whole story. Thirty minutes, three DNS records, and your quotes start reaching people again.

Sources