Skip to content
Not the Junk Folder

Email deliverability for small business

Your invoice went to junk.

Not because of what you wrote. Because four DNS records on your domain don't say what Gmail and Microsoft now insist they say. We find out which ones, explain it in English, and fix it with you.

The symptoms

Six ways a broken email setup shows up in a business that has no ideait's broken.

  • “I never got your invoice.”

    You sent it. It arrived. It went to junk, and nobody looks in junk. You find out three weeks later, when the payment doesn't.

  • Quotes go out. Nothing comes back.

    A quiet week can be a quiet market, or it can be a filter. Most businesses never learn which one it was.

  • Your accounting software sends as you.

    Xero, MYOB, your booking system, your newsletter — each one sends from your domain, and each one has to be authorised separately. Miss one and that one's mail gets filtered.

  • Someone is sending mail as your business.

    Without DMARC you have no way to know, and no way to stop it. Your customers get the fake invoice. Your domain wears the reputation damage.

  • You moved to Microsoft 365 and it got worse.

    Migrations leave the old records behind. Half-updated SPF, DKIM never switched on, mail still routing through a web host you stopped paying for in 2019.

  • You have DMARC. It's set to p=none.

    That's the setting that does nothing. It watches. It reports, if you configured reporting. It has never once stopped a spoofed email.

The free bit

See what Gmail sees when your email arrives.

Runs in your browser against public DNS. Nothing is sent to us, nothing is stored, no email address required.

This checks whether the records exist and whether they say something sensible. It can't tell you whether every system you send from is actually covered — that part needs a person.

Four records decide whether your mail is trusted: SPF, DKIM, DMARC and MX. Enter a domain to see all four.

What changed

Email didn't get harder by accident. It was changed on purpose, in 2024, and again in 2025.

The two companies that run most of the world's inboxes rewrote the rules within fifteen months of each other. Almost nobody told small business.

  1. Feb 2024

    Gmail and Yahoo stopped asking nicely

    From 1 February 2024, every sender to Gmail needs SPF or DKIM, valid reverse DNS, TLS in transit, and a spam complaint rate under 0.3%. Send more than 5,000 messages a day and you need SPF and DKIM and DMARC, aligned, plus one-click unsubscribe on anything marketing.

    Google sender guidelines
  2. May 2025

    Microsoft followed, and started rejecting

    From 5 May 2025, domains sending over 5,000 messages a day to Outlook.com, Hotmail or Live must pass SPF, DKIM and DMARC. Non-compliant mail was routed to Junk first; outright rejection followed — a hard bounce reading “550 5.7.515 Access denied, sending domain does not meet the required authentication level.”

    Microsoft's announcement
  3. The shift

    Authentication used to be a signal. Now it's the door.

    For twenty years, failing SPF nudged a score. Content, links and history did the rest, and a well-written email from a badly-configured domain still got through. That's over. Authentication is now checked at the door, before anyone reads a word of your message.

  4. The catch

    Every tool that mails on your behalf is its own problem

    The average small business sends from five or six systems without realising it: the mail host, the accounting package, the CRM, the newsletter, the website contact form, the appointment reminders. Each needs authorising. Nobody ever writes down the list.

  5. The trap

    Forwarding and aliases break it quietly

    info@ forwarding to a personal Gmail, an old address bouncing through a web host, a mailing list rewriting your headers — all of it breaks SPF alignment in ways that look fine from your desk and fail at the far end.

  6. The point

    You cannot see any of this from your own inbox

    Your mail to yourself always arrives. Your mail to your bookkeeper always arrives, because they've had you in their contacts for years. The failure is invisible precisely to the person who needs to know about it.

The longer version

What you get

A review, a report you can read, and someone to do the fixing.

  • 01

    Full authentication audit

    Every DNS record that decides whether your mail is trusted: SPF, DKIM, DMARC, MX, plus the quieter ones — BIMI, MTA-STS, TLS-RPT — checked and explained.

  • 02

    Sending-tool inventory

    Your accounting software, your booking system, your newsletter, that old contact form on the website. We find everything sending as you, and check each one is authorised.

  • 03

    A report you can actually read

    No dashboards full of red. A written report in plain English: what's wrong, what it costs you, and what happens if you leave it.

  • 04

    A prioritised fix list

    Ranked by impact, with the exact DNS records to add. Hand it to your IT person, or we do it with you.

  • 05

    A DMARC rollout plan

    Moving from none to quarantine to reject without cutting off your own mail. Staged, monitored, reversible.

  • 06

    A 45-minute consult

    We walk through the findings together, answer the questions the report raised, and agree what happens next.

How it runs

Three steps, and only one of them is yours.

  1. 01

    Send us your domain

    That's the whole onboarding. No access to your mailbox, no software to install, no agent on your server.

  2. 02

    Report in three business days

    We run the audit from the outside, exactly the way Google and Microsoft see you, and write it up.

  3. 03

    Consult and fix

    We talk it through, then either hand over the fix list or make the changes with you on a call.

Google Workspace*Microsoft 365*Xero*Mailchimp*Squarespace*Shopify*Klaviyo*HubSpot*cPanel*Cloudflare*Zoho Mail*ActiveCampaign*Stripe*SendGrid*WordPress*MYOB*

Pricing

Fixed fees. Published, because hiding themwastes everyone's afternoon.

The Check-up

$390one-off

Find out exactly where you stand. The full audit, written up, yours to act on however you like.

  • Full SPF, DKIM, DMARC and MX audit
  • Inventory of every system sending as your domain
  • Written report in plain English
  • Prioritised fix list with the exact records to add
  • Delivered within three business days
Book a check-up

The Fix

Most take this

$890one-off

The audit, then we do the work with you. Most businesses need this one — the fix list is the easy half.

  • Everything in The Check-up
  • 45-minute consult walking through the findings
  • DNS changes made with you, on a call
  • Staged DMARC rollout plan: none → quarantine → reject
  • Two weeks of follow-up while the changes settle
  • Re-check and confirmation once you're clean
Book the fix

Ongoing Watch

$120per month

Configuration drifts. New tools get added, staff leave, records get edited. This is the smoke alarm.

  • Quarterly re-audit of every record
  • DMARC aggregate reports monitored and summarised
  • Alerts when a record changes or a new sender appears
  • Email support for deliverability questions
  • Cancel any time
Start monitoring

Prices in AUD, GST inclusive. Fixed fee — if the audit turns up something bigger than expected, we tell you before we start, not after.

Questions

The ones people actually ask.

I already have SPF. Isn't that enough?

It hasn't been for a while. SPF authorises servers; DKIM signs the message itself; DMARC ties them to the name your customer actually sees and tells receiving servers what to do when they don't match. Gmail and Microsoft now expect the set. SPF alone also breaks the moment your mail is forwarded — which happens constantly, and invisibly.

Will any of this break my email?

Not if it's staged properly, which is most of the reason to have someone do it. The one genuinely risky move is turning DMARC up to reject before you know every legitimate sender. We roll that out in stages, watch the reports, and only enforce once the picture is clean. Everything we change is reversible in minutes.

Do you need access to my email or my systems?

No. The audit runs entirely from public DNS — the same view Gmail and Microsoft have of you. If you want us to make the changes rather than hand you the list, we do that on a call with you driving your own DNS provider, or with access you grant and revoke.

I only send twenty emails a day. Do the bulk sender rules apply to me?

The strict thresholds are for high-volume senders, so technically no. But the baseline requirements apply to everyone, filters increasingly treat unauthenticated mail as suspect regardless of volume, and small senders have no reputation cushion to fall back on. Low volume makes you less regulated, not more trusted.

My web developer set this up years ago. Isn't it still fine?

It was probably fine when they did it. Then you added a booking system, changed newsletter platforms, migrated to Microsoft 365, and someone added a third SPF record because the first two weren't working. That's the usual archaeology. Records rot.

Can't I just use one of the free online checkers?

Use them — the checker on this page is one. They'll tell you whether a record exists. They won't tell you that your SPF quietly exceeds the ten-lookup limit, that your DKIM key is a legacy 1024-bit one, that two of your five senders aren't covered, or which order to fix things in without cutting off your invoices.

How long does the whole thing take?

The audit and report: three business days. The DNS changes: an afternoon. DNS propagation and a staged DMARC rollout: a few weeks of watching, mostly hands-off. You're safer within the week and fully enforced within the month.

What if you find nothing wrong?

Then you get a short report saying so, a clean bill of health you can show a client or an insurer, and the knowledge that a quiet month was the market and not your mail server. It happens. Not often.

Get started

Send us a domain. We'll tell you what we find.

No access, no install, no obligation. Five fields and three business days.

Or skip the form — hello@notthejunkfolder.com