Business Email Going to Spam? Audit SPF, DKIM, and DMARC Before Sending More
When business email goes to spam or starts bouncing, inventory every sender, verify SPF, DKIM, and DMARC alignment, read the SMTP evidence, and retest in a controlled sequence.

Deliverability becomes diagnosable when every system sending as your domain is mapped to the DNS record, signature, alignment result, and bounce evidence it actually produces.
If business email is going to spam or bouncing, stop increasing volume and map every service that sends as your domain: the main mailbox provider, marketing platform, CRM, invoicing tool, website forms, help desk, and any server or agency account. Then verify SPF, DKIM, and DMARC for the exact From domain, capture a full message header or SMTP error, and test one known-good stream at a time.
Do not paste a generic DNS record from a tutorial, publish a second SPF record, or tighten DMARC enforcement before you know which legitimate senders are passing and aligned.
The Email Domain Authentication + Deliverability Recovery Kit adds the editable sender inventory, DNS baseline, header-review sheet, provider request scripts, test log, and staged recovery tracker behind this free workflow.
Audit six email lanes before editing DNS
| Lane | What to capture | Decision it supports |
|---|---|---|
| Sending systems | Provider, purpose, From domain, return path, sending IP, owner, and current volume. | Which legitimate sources must authenticate. |
| Authoritative DNS | Registrar, DNS host, nameservers, current TXT and CNAME records, and change access. | Where a real correction must be published. |
| SPF | Single record, included services, lookup behavior, and pass or fail result. | Whether the envelope sender authorizes the sending source. |
| DKIM | Selector, public key record, signing domain, signature result, and key status. | Whether the message carries a verifiable domain signature. |
| DMARC alignment | Visible From domain, aligned SPF domain, aligned DKIM domain, policy, and reports. | Whether authenticated identity matches what the recipient sees. |
| Delivery evidence | SMTP code, bounce text, message header, recipient provider, date, campaign, and test result. | Whether the next move is authentication, reputation, content, volume, or provider escalation. |
Google's email sender guidelines require all senders to authenticate with SPF or DKIM and require higher-volume senders to use SPF, DKIM, and DMARC. Google says unauthenticated messages can be marked as spam or rejected, and its enforcement guidance uses distinct error codes for SPF, DKIM, DMARC, DNS, TLS, and rate problems. Use the exact error and header from your own message instead of assuming every spam placement is a DNS failure.
Use four rules during recovery
The owner adds records from three tutorials, deletes an unfamiliar selector, sends a large campaign immediately, and cannot tell which change helped or broke transactional mail.
The owner maps every sender, preserves the DNS baseline, validates authentication and alignment from real headers, makes one provider-supported correction, and retests a small stream.
Copy this authentication and delivery control sheet
Email authentication recovery log
Visible From address and domain: [address and domain]
Message type: [transactional, marketing, person-to-person, form, or other]
Sending provider and account owner: [provider and owner]
Envelope or return-path domain: [domain]
Sending IP if shown: [IP]
SPF result and aligned domain: [result and domain]
DKIM result, selector, and signing domain: [result, selector, domain]
DMARC result and policy: [result and policy]
Recipient provider: [provider]
SMTP or bounce code: [exact code]
Header evidence file: [file name]
DNS host and record changed: [host, type, old value, new value]
Provider instruction used: [URL or case]
Controlled test result: [recipient, time, inbox/spam/bounce]
Rollback trigger: [condition]
Next review: [date and owner]
Follow the evidence, not a universal fix
| Evidence | Likely lane to inspect first | Do not assume |
|---|---|---|
| SPF fail or related error | Envelope sender, sending IP, include chain, and authoritative SPF record. | That adding the visible From domain to SPF will fix it. |
| DKIM fail | Selector lookup, public key, provider signing status, and message alteration. | That an old selector is safe to delete without checking active senders. |
| DMARC fail | From-domain alignment with the authenticated SPF or DKIM domain. | That SPF pass by itself is aligned. |
| All authentication passes | Spam rate, consent, content, list quality, volume changes, reputation, and provider policy. | That authentication guarantees inbox placement. |
| Only one tool fails | That tool's domain setup, return path, selector, and account configuration. | That the entire domain needs to be rebuilt. |
Get the free Emergency Triage Sheet
The first three moves for any business emergency, plus one practical fix in your inbox each week.
No spam. Unsubscribe anytime.
Worked example: invoices fail after a marketing migration
A hypothetical repair company moves newsletters to a new platform, but its invoice service begins bouncing at Gmail. The owner finds two SPF records and cannot tell whether either includes the invoice provider. She exports the DNS values, inventories the mailbox, newsletter, invoice, form, and CRM senders, and captures a failed invoice header.
The invoice stream is not DKIM-signed for the company domain, and its return path does not align. The owner follows the invoice provider's current domain-authentication instructions, consolidates SPF through the DNS administrator, enables the provider's DKIM records, and runs small invoice and newsletter tests. She leaves DMARC at a monitoring policy until legitimate streams are visible. This sequence improves control; it does not guarantee inbox placement or make one provider's DNS values correct for another.
Email deliverability recovery checklist
- Pause volume increases and preserve recent bounce notices, headers, and provider alerts.
- List every system that sends mail using the domain or a subdomain.
- Confirm the authoritative DNS provider before editing records.
- Export current MX, SPF, DKIM, DMARC, and relevant CNAME records.
- Verify that the domain publishes one intentional SPF record.
- Verify DKIM signing and selector lookup for every important sender.
- Check alignment between the visible From domain and authenticated SPF or DKIM domain.
- Record DMARC policy and aggregate-report destination before changing enforcement.
- Separate authentication failures from reputation, consent, content, and volume issues.
- Use current instructions from each provider and record the support case or source.
- Make one controlled change with a rollback point.
- Retest person-to-person, transactional, marketing, and form streams separately.
FAQ: should you set DMARC to reject immediately?
Not when you do not yet understand your legitimate senders. A stricter policy can protect the domain, but it can also expose or block streams that were never configured correctly. Inventory, authenticate, align, monitor, and use qualified technical help before changing enforcement when email is operationally critical.
Connect authentication to continuity and security
If the domain itself expired or changed hands, start with the expired-domain email and website recovery checklist. If a mailbox or payment thread may be compromised, use the business email compromise first-hour response. The vendor ACH change verification workflow helps keep spoofed payment instructions from becoming a bank loss.
Free version vs. full kit
This article gives you the free version: the six-lane audit, authentication control sheet, evidence decision table, worked example, and recovery checklist. The paid kit adds editable sender, DNS, header, provider, test, rollout, and monitoring tools for a controlled repair.
Get the Email Domain Authentication + Deliverability Recovery Kit
The All-Access membership includes the full kit library while your membership is active. The one-time email authentication kit remains the primary next step for this article.
Fix the next one before it starts.
Join the list for the free Emergency Triage Sheet and a new practical fix every week.
No spam. Unsubscribe anytime.