Why your email lands in spam: SPF, DKIM, and DMARC in plain English
Two problems that look unrelated usually have the same cause. Your invoices and quotes keep landing in customers' junk folders. And a criminal, if one ever bothers to look, can send email that appears to come from your business and have it arrive looking legitimate. Both trace back to three small DNS records, SPF, DKIM, and DMARC, that most small offices have never fully set up. This guide explains what each one does in plain English, why a half-finished setup is the most common state, and how to find out where your own domain stands in about a minute.
What are SPF, DKIM, and DMARC?
When an email claiming to be from your business arrives somewhere, the receiving server has to decide whether to believe it. The three records are how your domain helps it decide. SPF is a published list of the servers allowed to send mail as you, like a registry of your legitimate return addresses. DKIM is a cryptographic signature stamped on each outgoing message, a wax seal proving the message left your systems and was not altered on the way. DMARC is the standing instruction that ties them together: it tells receiving servers what to do with mail that fails the first two checks, deliver it anyway, quarantine it, or reject it, and it sends you reports about who is out there sending as your domain.
Why your legitimate email lands in spam
The big mailbox providers stopped giving unauthenticated mail the benefit of the doubt. Google and Yahoo now require authentication outright for high-volume senders and treat everyone else's unauthenticated mail with growing suspicion, and Microsoft filters along the same lines. In practice, a domain with missing or broken records gets a percentage of its perfectly legitimate mail routed to junk, quietly, with no error message anyone sees. The office experiences it as customers who swear they never got the invoice. The fix is not asking recipients to check spam; it is making your domain provably yours, at which point your mail carries credentials instead of asking for trust.
Why criminals love a domain without DMARC
The same gap runs the other direction. Without an enforced DMARC policy, anyone on the internet can put your exact address in the from line, and many receiving servers will deliver it. That is the cheapest version of business email compromise: no hacking, no stolen password, just a forged sender on an urgent invoice or a changed bank detail. For businesses that move client money, law firms above all, this is the opening move of wire fraud. An enforced policy slams that particular door: receiving servers are instructed, by you, to refuse mail that is not provably yours.
The catch: DMARC only counts at enforcement
Here is the detail that separates a real setup from a checkbox. DMARC has three policy levels, and the first one, monitoring only, does not protect anything: it just watches and reports. A huge share of the domains that technically have a DMARC record are parked at monitoring, often because someone created the record years ago and never came back. The real work is the migration: read the reports, inventory every service that legitimately sends as you, the payroll system, the practice software, the newsletter tool, authenticate each one, and then move the policy to quarantine and finally reject. That sequence is why this is a project with steps rather than a checkbox, and skipping the steps is how offices break their own email.
How to check your own domain right now
All three records are public, which means anyone can check yours, including you, and including anyone deciding whether your business is an easy target. Free lookup tools will show the raw records if you like reading DNS. The friendlier route: checking them is the first thing my free Security Check does, from the outside, with the result in plain English rather than record syntax. Either way, the answer is worth having, because whichever state your domain is in, it is in that state today, visibly, for anyone who looks.
FAQ
We use Microsoft 365. Is this not handled automatically?
Only partly. Microsoft signs your mail with a default signature, but SPF has to list every service that legitimately sends as you, DKIM for your own domain has to be switched on, and a DMARC record is never created automatically. Most small-office domains have a partial setup that was never finished, which is worse than none because it looks done.
Will turning on DMARC break our email?
Done carefully, no. The record starts in monitoring mode, the reports show every service sending as your domain, the legitimate ones get authenticated one by one, and only then does the policy move to enforcement. What breaks email is skipping the inventory and jumping straight to reject while the payroll system is still sending unauthenticated invoices.
Does this stop phishing?
It stops one specific and dangerous kind: mail forged from your exact domain. It does not stop look-alike domains, and it does not help when a real mailbox at the other end of a conversation has been taken over. Those need mail filtering, multi-factor sign-in, and for anything involving money, a call-back verification habit.
What does it cost to get this fixed?
Finding out where your domain stands costs nothing: checking these records is the first thing the free Security Check does, from the outside, in about a minute. Work for businesses not on a plan is billed at $125 per hour, and larger projects are quoted up front so you approve the number before the work starts.
Want to know what your domain says about you right now? The free Security Check reads it from the outside and tells you in plain English, and the report is yours whatever it says. The law firm page shows how an engagement starts, and what ongoing support costs is published in what IT support costs a small law firm in Florida.
About the author
Mario Del Mazo is the owner of IT First Response, a managed IT and security practice in Fort Myers serving Lee County, Florida. His background is corporate IT for a healthcare organization operating under HIPAA and HITRUST standards. He publishes his prices, and every client environment is documented so nothing has to be explained twice. More about Mario.
