Skip to main content
Login

Why Are Emails From My Website Not Arriving? SPF, DKIM, and DMARC in Plain English

Part of AI for Small Business, our plain-English guide to what AI can and can't do for your business.

Email providers now require proof that your website is allowed to send mail as your domain. Most small-business sites can't show that proof, and don't find out until a customer says they never got the email.


Think of it like showing ID at the front desk

Picture walking into an office lobby and telling the front desk you're delivering a package for someone upstairs. Show company ID and you're waved through. Show nothing and security calls up first, or turns you away.

Email works the same way now. When a message claims to come from yourbusiness.com, the receiving mail server checks whether that message is actually allowed to say that. SPF, DKIM, and DMARC are the three pieces of ID a domain can show. Show all three cleanly and mail moves through. Show none and more of your mail sits in spam folders, bounces, or never arrives at all.


SPF, DKIM, and DMARC, explained without the acronym soup

SPF (Sender Policy Framework)

SPF is a list of the mail servers allowed to send email using your domain name. Add a server that isn't on the list and receiving mail providers can flag or reject the message.

DKIM (DomainKeys Identified Mail)

DKIM attaches a digital signature to each email your domain sends, proving the message wasn't altered on the way there. A missing or broken signature makes a message look more suspicious to spam filters, even when it genuinely came from you.

DMARC (Domain-based Message Authentication, Reporting, and Conformance)

DMARC tells receiving mail servers what to do when a message fails the SPF or DKIM check: let it through anyway, mark it as spam, or reject it outright. Without a DMARC record, each provider picks its own default, and that default is rarely in your favor.


Check your domain

Trust Check is a free tool that reads your domain's public DNS records and tells you whether SPF and DMARC are set up and passing.

Trust Check tests SPF and DMARC. It does not test DKIM. DKIM's public key lives at a provider-specific address, something like selector._domainkey.yourdomain.com, and the selector name is different for every email service. There's no single universal address to look up the way there is for SPF and DMARC. To check DKIM specifically, use the authentication test built into your email provider, whether that's Google Workspace, Microsoft 365, or your hosting company's email tool.

If it's specifically your contact form going missing, and not all your outbound mail, that's often a separate problem in how WordPress sends the message. SeeWordPress Contact Form Not Sending Emails.


Reading your results

A green result next to SPF means receiving mail servers recognize your sending servers as authorized. A red or missing result means they don't, and messages claiming to come from your domain are more likely to get flagged.

DMARC works a little differently. Even a basic DMARC record set to monitor rather than block is worth having, as long as it includes a reporting address (the rua tag). With that address in place, mail providers send you reports when someone else sends mail as your domain, which is exactly the kind of impersonation SPF and DKIM exist to catch. A monitor record without a reporting address watches silently and tells you nothing.


Fixing what's broken

SPF, DKIM, and DMARC all live in your domain's DNS records, the same place your website's address lives. Fixing them usually means adding or correcting a few lines of text, not rebuilding anything.

  1. Add or correct your SPF record

    List every service that sends email as you: your website's contact form, your email provider, any marketing tool you use. Miss one and its mail may start failing.

  2. Turn on DKIM through your email provider

    Most providers generate the DKIM record for you inside their own settings. You paste it into your DNS as a new record, and it takes over from there.

  3. Publish a DMARC record

    Start with a monitoring-only policy so you can see what's happening before you tell servers to reject anything. Tighten it once you trust what the reports are showing you.

Hand this section to whoever manages your domain. That's often your web host or IT provider, and it isn't always the same person who manages your website's design.


Why this got stricter in 2024

In February 2024, Google and Yahoo started requiring SPF and DKIM authentication, plus a DMARC record, from anyone sending more than 5,000 emails a day to their users. Smaller senders weren't technically required to comply, but Gmail and Yahoo also started treating unauthenticated mail from any domain with more suspicion across the board.

That's the practical shift. DNS records that used to be optional best practice for a small business are now closer to a baseline requirement for mail to arrive reliably at the two largest inbox providers most of your customers use.

None of this guarantees inbox placement on its own. A domain with clean SPF, DKIM, and DMARC records can still land in spam if a message's content looks spammy or a sending pattern changes suddenly. And Surmado doesn't operate your email inbox: we can help you get the DNS records right, but Gmail, Microsoft 365, or whatever service holds your actual mailbox stays a separate account you manage yourself.

Email authentication is one piece of a bigger pattern: DNS records, security headers, and crawler access all sit in the same category of things a website needs to get right once and then keep right. A moving company in Fort Worth found that out the hard way when 32 spam links were quietly injected into their WordPress site for months before anyone noticed. If you'd rather have someone else own DNS, hosting, and monitoring together, that's what Surmado Sites does.

Fix it yourself

The steps above are the honest version, in order. Jump back to the steps and work through them. No account, no email, nothing to buy.

Never deal with this again

Hand Surmado the site. We rebuild it, run it, and keep everything you've built along the way.

How do you feel about your current site?

We rebuild it free and send you a preview. A human checks it before delivery. You pay nothing until you approve it and your domain moves. Most rebuilds are ready within 24 hours.

$99/mo. Hosting, maintenance, and updates included. We rebuild your site free. You see it before you pay anything.

Veterans Moving America's decaying WordPress site was quietly costing them leads until Scout found it. Read the case study

Questions

What is SPF in plain English?

SPF is your domain's list of approved senders. It tells receiving mail servers which servers are allowed to send email claiming to be from you, so a stranger can't easily send spam that looks like it came from your business.

Emails reach Gmail but not Outlook, why?

Different providers enforce authentication differently and update their spam filters on their own schedule. A domain with a weak or missing DMARC record can pass through one provider's filter today and get caught by another's tomorrow. Checking your SPF and DMARC records directly, instead of guessing from where mail lands, gives you a straight answer.

Is this my website's fault or my email provider's?

Usually neither one on its own. Your website's contact form and your email provider typically send mail through different servers, and every service that sends mail as your domain needs to be authorized in that domain's SPF record. Add only the services that actually send as your domain; SPF also has a lookup limit, so a record stuffed with unused services can itself become the problem. The DNS records live with your domain, not inside your website's code or your email provider's settings.

What happens if I have no DMARC record?

Receiving mail servers fall back to their own default handling for messages that fail SPF or DKIM, and that default varies by provider. Some quarantine the message, and some let it through anyway. None of them tell you it happened. A DMARC record puts that decision back in your hands, and one that includes a reporting address (the rua tag) also gets you the reports.

Fix it yourself

The steps above are the honest version, in order. Jump back to the steps and work through them. No account, no email, nothing to buy.

Never deal with this again

Hand Surmado the site. We rebuild it, run it, and keep everything you've built along the way.

How do you feel about your current site?

We rebuild it free and send you a preview. A human checks it before delivery. You pay nothing until you approve it and your domain moves. Most rebuilds are ready within 24 hours.

$99/mo. Hosting, maintenance, and updates included. We rebuild your site free. You see it before you pay anything.

Veterans Moving America's decaying WordPress site was quietly costing them leads until Scout found it. Read the case study