“Did you get my email?” If you hear that question regularly, or customers tell you they found your quote in their junk folder, it is worth checking how your domain’s email is set up, because poor email deliverability costs business. Mail providers have become much stricter about checking that emails genuinely come from the domain they claim to, and businesses without the right settings are increasingly penalised.
Three DNS records do most of the work for email deliverability: SPF, DKIM and DMARC. Here is what each one does.
SPF: who is allowed to send
SPF, or Sender Policy Framework, is a DNS record listing the services allowed to send email using your domain. That might include your email provider, such as Microsoft 365 or Google Workspace, your website server, your CRM and your email marketing platform.
When a receiving server gets an email claiming to be from your domain, it checks whether it came from one of the listed services. Common problems include forgetting to add a service, such as the website that sends contact form notifications, and having more than one SPF record, which breaks it entirely.
DKIM: proof the message is genuine
DKIM, or DomainKeys Identified Mail, adds a digital signature to each email you send. The receiving server uses a public key published in your DNS to check the signature. If it matches, the receiver knows the email really came from an authorised sender for your domain and was not altered on the way.
Each sending service usually has its own DKIM setup. Your email provider and marketing platform will give you the records to add.

Photo by Brett Garwood on Unsplash
DMARC: what to do when checks fail
DMARC, or Domain-based Message Authentication, Reporting and Conformance, ties SPF and DKIM together. It tells receiving servers what to do with emails that fail the checks, and it can send you reports showing who is sending email using your domain.
A DMARC policy has three levels:
- p=none: monitor only, with no change to delivery. This is where everyone should start.
- p=quarantine: send failing emails to spam.
- p=reject: block failing emails altogether.
Starting with monitoring lets you spot any legitimate services you forgot to authorise before you begin blocking anything. Once the reports show everything genuine is passing, you can move gradually to a stricter policy, which also makes it much harder for criminals to send phishing emails pretending to be you.
Why email deliverability matters more now
In 2024 Google and Yahoo introduced requirements for bulk senders, including authenticated email and a DMARC record. Even if you only send a modest number of emails, these standards influence how all mail is treated, and properly authenticated domains are simply more trusted.
Website emails need attention too
Contact form notifications and order confirmations from your website are among the most commonly lost emails. Many websites send directly from their web server, which may not be included in SPF and does not sign with DKIM. Sending website email through your main provider or a dedicated transactional email service, set up with proper authentication, usually solves the problem.
Other good habits
- Send from your own domain, not a free email address.
- Only email marketing to people who have opted in, and make unsubscribing easy.
- Avoid sending from “noreply” addresses for customer communications.
- Keep mailing lists clean by removing addresses that bounce.
Checking your setup
Free online tools can show your current SPF, DKIM and DMARC records and flag obvious problems. If the results look confusing, or you have several services sending on your behalf, it is worth getting help, because a small mistake in a DNS record can stop email working.
We set up and fix email authentication as part of our hosting and website work. If your email deliverability is poor and messages are going missing, get in touch and we will take a look.


