Computer Techie

SPF, DKIM, and DMARC: Why Your Emails Land in Spam (and How to Fix It)

SPF, DKIM, and DMARC: Why Your Emails Land in Spam (and How to Fix It)

Why Your Business Email Started Landing in Spam: Gmail, Yahoo, and Now Outlook

A supplier here in Biñan sends the same statement of account it has used for three years. The client swears it never arrived. There is no bounce, no error, no warning — the message is sitting unread in Outlook's Junk folder. Nothing is wrong with your email. Something is missing from your DNS, and this is SPF, DKIM, and DMARC explained in plain English.

Google and Yahoo began enforcing bulk-sender rules on 1 February 2024: SPF and DKIM both, a DMARC record, an aligned From: header, one-click unsubscribe on marketing mail, and a spam rate under 0.30% (Google Workspace Admin Help; Yahoo Sender Hub). Microsoft applied the same bar to Outlook.com, Hotmail.com, and Live.com on 5 May 2025 (dmarcian): failing mail is filtered out of the inbox, with rejection signalled as the end state. This month, all three inboxes your customers use want the same thing.

Kill one myth first. The rules bite at 5,000 messages a day to consumer addresses, but filtering is not gated on volume — a 40-person firm sending 300 invoices a day is scored the same way. The floor became the norm.

Moving off a free address was step one; our 2022 piece on why your business needs a professional email address got you @yourcompany.com. Authenticating that domain is step two, and most Philippine SMEs never did it.

Do it this week. PAGASA declared the rainy season on 2 June (DOST-PAGASA), so advisories and cut-off notices are weekly mail now. Independence Day on 12 June will be the quarter's biggest promo send, and a broken SPF record announces itself mid-send.

SPF, DKIM, and DMARC Explained in Plain English

All three are DNS TXT records: free, no software, edited in the same panel as your domain's A record. A 30-minute job, not a mail server migration — and the panel our team works in during server and email infrastructure support.

Think of a courier delivering a company check to a client's front desk:

  • SPF — the guard's list of couriers you authorized.
  • DKIM — the tamper-evident seal on the pouch.
  • DMARC — your standing order when a delivery fails either check, plus a daily logbook.

SPF (RFC 7208, April 2014) and DKIM (RFC 6376, September 2011) are Standards Track. DMARC (RFC 7489, March 2015) is only an Informational independent submission — which is why implementations vary.

SPF: The List of Servers Allowed to Send as You

One TXT record on your root domain, listing the services allowed to send mail as you:

v=spf1 include:_spf.google.com include:servers.mcsv.net ~all
  • v=spf1 — the version tag.
  • include: — one line per authorized service; here, Google Workspace and Mailchimp.
  • ~all — softfail: anything not listed is suspicious, not rejected.

Three mistakes recur. Two SPF records at once is an automatic permanent error — publish one, merge the includes. More than 10 DNS lookups also fails, and each include: costs one. A leftover +all authorizes the whole internet. Audit on ~all, then tighten to -all.

SPF's blind spot: it checks the Return-Path envelope sender, not the From: address your customer reads — which is why DKIM and DMARC exist.

DKIM: The Cryptographic Seal on Each Message

Your platform signs each message with a private key; the public key sits in DNS at <selector>._domainkey.yourdomain.com, such as google._domainkey.abctrading.com. Receivers verify the signature, proving nothing was altered in transit.

DKIM is switched on in the platform, not just DNS: Google Workspace under Apps > Google Workspace > Gmail > Authenticate email (2048-bit key, publish the TXT record, Start authentication), Microsoft 365 in the Defender portal, cPanel in Email Deliverability, each marketing platform with its own CNAME selector.

The gotcha: every sender needs its own DKIM. Signing your Google Workspace mail does nothing for the newsletter leaving through your email platform, or the invoices your POS generates.

Forwarding matters too: when staff auto-forward to a personal address, SPF usually breaks while the DKIM signature survives — which makes DKIM alignment the more reliable of the two.

DMARC: The Policy That Ties Them Together — and Reports Back

A TXT record at _dmarc.yourdomain.com, telling receivers what to do when mail claiming to be from you fails both SPF and DKIM alignment.

v=DMARC1; p=none; rua=mailto:[email protected]; fo=1; pct=100
  • p= — the policy: none (monitor), quarantine (spam), or reject.
  • rua= — where daily aggregate reports go; fo=1 requests a failure report on an unaligned pass.
  • pct= — the share of failing mail the policy applies to; the standard way to ramp up.
  • sp= — policy for subdomains; adkim= and aspf= set relaxed (r, default) or strict (s) alignment.

The underrated half is reporting. Even p=none — the minimum all three providers require, and no change to delivery — turns on daily reports naming every IP sending as your domain: the forgotten CRM, the old web host, anyone spoofing you. An entry ticket, not a destination.

Domain Alignment: The Silent Reason DMARC Still Fails

SPF can pass. DKIM can pass. DMARC can still fail. It checks that the From: domain your customer sees matches the domain that passed SPF or signed with DKIM — an alignment all three providers name as a separate requirement.

The classic break: a platform sends as "Juan from ABC Trading [email protected]" but signs and bounces on its own domain. Both checks pass there, aligning with neither. Finish the platform's custom-domain or CNAME wizard so DKIM signs as yours.

Alignment also stops other people wearing your name — the same fight as how to spot fake emails before they cost you, won at the DNS layer. Aggregate reports name every system sending as you, and reading them is where our cybersecurity services start.

Under relaxed alignment, news.abctrading.com aligns with abctrading.com: same organizational domain, resolved through the Public Suffix List. Strict demands an exact match. Relaxed suits most SMEs, but on a .com.ph check how your provider resolves it.

The second break has no fix: mail sent "from" an @gmail.com address borrows someone else's domain and its DMARC policy. You cannot authenticate a domain you do not own.

How to Check Whether Your Domain Passes Today (5 Minutes, No Tools to Buy)

With SPF, DKIM, and DMARC explained, does your own domain pass right now?

Method 1 — fastest. Send from your business address to a Gmail account you control, open it, and choose Show original. The panel lists SPF, DKIM, and DMARC, each PASS or FAIL with the domain it passed on. Healthy is PASS on all three with your own domain beside each; a marketing platform's domain there is an alignment failure.

Method 2 — the DNS check. From any Windows machine, open Command Prompt:

nslookup -type=TXT yourdomain.com
nslookup -type=TXT _dmarc.yourdomain.com
nslookup -type=TXT google._domainkey.yourdomain.com

Expect one v=spf1 line, a v=DMARC1 line, and your DKIM public key — swap google for your platform's selector.

Method 3 — a free checker. MXToolbox and similar tools verdict SPF syntax, lookup count, DMARC policy, and blacklist status in one page.

Method 4 — for volume senders. Enroll in Google Postmaster Tools and watch the spam-rate graph: under 0.30% for Google, 0.3% for Yahoo. Recipients set that number; no DNS record fixes it.

What the check shows What to do first
All three PASS, your domain beside each Nothing; move on to list hygiene
No v=DMARC1 record Publish p=none today
Two SPF records, or a permanent error Fix this before anything else
DKIM missing on one platform That platform is your leak

Fixing It: Publish SPF, Turn On DKIM, Then Roll Out DMARC Safely

Step 1 — inventory every system that sends as your domain, before touching DNS. At a typical SME: Google Workspace or Microsoft 365, the website contact form on shared hosting, the newsletter platform, the POS or invoicing system, an old cPanel account nobody decommissioned. Miss one and you black-hole your own mail.

Step 2 — publish exactly one SPF record covering that inventory, under 10 DNS lookups, ending in ~all. Do not flatten it into raw IPs blindly, and do not keep an include for a service you dropped years ago.

Step 3 — enable DKIM in each platform, one at a time, verifying with Show original after each. Choose 2048-bit keys; some panels still default to 1024-bit.

Step 4 — publish DMARC at p=none with a working rua mailbox and read the reports for two to four weeks. They arrive as zipped XML, so use a free report reader. You are hunting the legitimate but unaligned source: real mail from a service you recognize, passing its own checks but failing yours. Because p=none is safe on day one, publish it first even if that inventory takes a week.

Step 5 — ramp enforcement only when the reports are clean. Move to p=quarantine with pct=25, raise the percentage, then p=reject. Jumping straight to p=reject on an unaudited domain bins your own quotations, and we have been called in to undo exactly that.

Authentication Alone Won't Save a Bad Sending List

SPF, DKIM, and DMARC prove who you are; they do not make you welcome. Google and Yahoo cap spam complaints at roughly 0.3%, and recipients set that figure, not your DNS. Enforcement still matters — it keeps your domain out of the business email compromise scams targeting Filipinos that start with a spoofed supplier address.

One-click unsubscribe is a requirement, not a courtesy. The List-Unsubscribe and List-Unsubscribe-Post headers come from RFC 8058, January 2017, and Google also wants a visible unsubscribe link honored within two days. Reputable platforms handle this; a self-built PHP mailer does not.

Separate your streams: invoices, receipts, and storm advisories should not share a sending identity with promos, and a subdomain like billing.yourdomain.com with its own DKIM keeps a bad campaign from sinking the mail that pays you.

Before the 12 June send, purge addresses that have not opened in a year, never mail a purchased list, and warm up gradually if you are switching platforms.

One cost note. Since 1 June 2025 the 12% VAT on digital services under RA 12023 and BIR Revenue Regulations No. 3-2025 applies to the foreign SaaS invoices you pay, email platforms included (Grant Thornton Philippines). Paying more for a platform whose mail lands in Junk is the worst line on that bill.

If Show original says FAIL on any line — or you do not know which systems send mail as your domain — we can inventory every sender, publish the records, and read your first month of DMARC reports with you, inside a week and before the 12 June send. Storm advisories and holiday promos both have to land in an inbox. Book a call with us and we will start with the audit.

Empowering Businesses with Customized Software Solutions

Tell us what you need — we typically reply within the day. Let’s build something that drives your business forward.