Why your business emails land in spam (and the three DNS records that fix it)

Emails going to spam? SPF, DKIM, and DMARC are the three DNS records that prove your mail is yours. Here's how to check your domain and fix what's wrong.

Published: September 29, 2026Reading time: ~3 min

Your quotes are going unanswered. A customer swears they never got the invoice. Your newsletter open rate fell off a cliff. Before you blame your subject lines, check something most business owners have never looked at: whether your domain is set up to prove your email is really yours.

Since 2024, Gmail and Yahoo have required sender authentication. Mail that can't prove where it came from gets filtered to spam or rejected outright, and nobody tells you it happened. Three DNS records decide the outcome: SPF, DKIM, and DMARC.

Three records decide it

In plain terms:

  • SPF is the guest list. It's a record on your domain naming every service allowed to send email as you: Google Workspace, your CRM, your newsletter tool, your invoicing software. If a sender isn't on the list, receiving servers get suspicious.
  • DKIM is the signature. Each outgoing email gets cryptographically signed by your domain, so the receiver can verify it wasn't forged or altered in transit.
  • DMARC is the instruction. It tells receiving servers what to do with mail that fails the first two checks (let it through, send it to spam, or reject it) and sends you reports about who is sending as your domain. Without DMARC, anyone can spoof your address and you'd never know.

Check yourself in five minutes

  • Send an email from your business address to a Gmail account you control.
  • Open it in Gmail, click the three dots in the top right, and choose Show original.
  • Look at the top three lines: SPF, DKIM, DMARC. You want PASS on all three.
  • Check that the DKIM line names YOUR domain. If it says gmail.com instead of your business domain, your mail is being signed by Google's generic key, not yours, and stricter DMARC settings will fail even though everything looks fine today.

The three failures we see most

These aren't rare. We recently audited nine domains under our own management, businesses and apps we run ourselves, and only two passed all three checks. One was a newsletter brand actively mailing a subscriber list with no authentication of any kind. Every send was rolling the dice on the spam folder.

  • Two SPF records. SPF only allows one record per domain. When a second tool tells you to add its SPF record and you do, both records become invalid and every SPF check fails. The fix is one merged record that includes every sender.
  • DKIM signing as gmail.com. This is the default on Google Workspace domains until someone turns real signing on in the admin console. It's invisible unless you run the Show original check.
  • No DMARC at all. The record simply doesn't exist, so there's no policy and no visibility into spoofing.

You can fix this yourself

Each record is a TXT entry at your domain registrar. Your email provider and each sending tool publish the exact values you need. DMARC can start in monitoring mode (p=none) so nothing breaks while you watch the reports come in. Budget an afternoon, plus a few days of waiting for DNS to propagate and verification to pass.

Or we will do it for you

Framework Studio runs the full setup: audit, one correct SPF record, DKIM verified for every sender, DMARC with reporting, and before and after proof from real test emails. Flat fee per domain, about 15 minutes of your time. It's the same check we run as part of the free technical audit on every site we look at.

The check on its own is free too. Get in touch and send us your domain, and within a day we'll tell you whether you pass. If you're already clean, that's the whole conversation.

FAQ

What does DMARC p=none mean?

It puts DMARC in monitoring mode. Receiving servers still deliver mail that fails SPF or DKIM, but they send you reports showing who is sending as your domain. It's the safe starting point: you see what's happening before you tell servers to quarantine or reject failing mail.

Can I have two SPF records?

No. SPF only allows one record per domain, and a second one invalidates both. If a tool asks you to add its own SPF record, merge it into your existing record instead of publishing a new one.

Why does my DKIM line say gmail.com instead of my domain?

That's Google Workspace's default signing key. It works, but it won't hold up once DMARC gets stricter. Turning on custom domain DKIM signing in the admin console fixes it.

How long does this take?

The check itself is same day. The fix is usually an afternoon of work plus a few days for DNS changes to propagate and verification to pass.

Want help applying this to your site?

Get a clear action plan and a build that holds up. Based in St. Louis, working with small businesses nationwide.