Why do my business emails go to spam?
Scott Anderson · Last reviewed
Short answer
Most business email lands in spam because the receiving server can't prove it really came from your domain. Since 2024, Gmail and Microsoft check SPF, DKIM and DMARC before they weigh anything else. If those records are missing, contradictory, or don't cover the tool that sent the message, filtering follows — regardless of what you wrote.
Key facts
Since 1 February 2024, every sender to Gmail must have SPF or DKIM authentication, valid reverse DNS, a TLS connection, and a spam complaint rate below 0.3%. Google sender guidelines ↗
From 5 May 2025, Microsoft began routing non-compliant high-volume mail to Junk in Outlook.com, Hotmail and Live, and then rejecting it outright. Microsoft's announcement ↗
A domain may publish only one SPF record. Two or more is a permanent error, and receivers discard the lot. RFC 7208 §3.2 ↗
Nobody writes to tell you their copy of your invoice went to junk. They just don't pay it, and three weeks later there's an awkward phone call. That silence is the whole problem: the failure is invisible to the one person who could fix it.
So it's worth being precise about what's actually going wrong. Spam filtering used to be about the message — its words, its links, its attachments. That's now the second question. The first is whether the receiving server can prove the message came from where it claims.
The six reasons this usually happens
In practice, almost every case of small-business mail landing in junk traces back to one of these.
- You have no SPF or DKIM at all
- The baseline requirement since February 2024. Without at least one of them, you fail at the door — no reputation, no history, no second look.
- A tool that sends as you isn't authorised
- Your accounting package, booking system, CRM and newsletter each send from your domain. Each has to be listed separately. Miss one and only that tool's mail fails, which is why the symptom looks so random.
- Your SPF record has quietly stopped working
- Two SPF records instead of one, or more than ten DNS lookups. Both are permanent errors, both make receivers ignore SPF entirely, and neither produces any warning.
- DMARC is published but set to p=none
- The setting that monitors and does nothing. It satisfies a checkbox, protects nothing, and lets anyone keep sending as you.
- Forwarding and aliases break alignment
- info@ forwarding to a personal Gmail, a mailing list rewriting headers, an old web-host relay. SPF breaks on forwarding by design; if DKIM isn't also in place, the forwarded copy fails everything.
- A migration left records behind
- Moving to Microsoft 365 or Google Workspace without cleaning up the old host's MX and SPF entries. Half the configuration points somewhere you stopped paying for years ago.
Why your own testing never catches it
Email you send to yourself always arrives — same domain, trivially trusted. Email to your bookkeeper always arrives, because they have replied to you a hundred times and their provider has learned that you're wanted. Personal history overrides nearly everything.
The mail that fails is the mail to someone who has never heard from you: the new client, the prospect who filled in your form, the supplier you're quoting for the first time. Exactly the mail whose non-arrival is indistinguishable from disinterest.
How to work out which one is happening to you
- 01
Read your public records
Check what SPF, DKIM, DMARC and MX records your domain actually publishes right now. This is the view Gmail and Microsoft have of you, and it takes seconds.
- 02
Write down every system that sends as you
Mail host, accounting software, invoicing, CRM, newsletter, e-commerce, appointment reminders, the website contact form. Most businesses find five or six. Every one of them needs to be covered.
- 03
Turn on DMARC reporting
A DMARC record with a rua= address makes receiving servers send you daily reports of everything sent in your name — including the senders you forgot about, and anyone spoofing you.
- 04
Fix in order, then enforce
Get every legitimate sender authenticated first. Only then move DMARC from none to quarantine to reject. Enforcing before the picture is complete is how businesses block their own invoices.
What about the content of the message?
It still matters, just later in the process. Once you're authenticated, the usual advice applies and is worth following: avoid link shorteners, don't send a single large image with no text, keep your list clean, and make unsubscribing easy on anything that resembles marketing.
But content advice given to an unauthenticated domain is like rearranging furniture in a house with no front door. Fix the authentication, then tune the message.
Frequently asked
I only send a handful of emails a day. Do these rules apply to me?
The strict thresholds — five thousand messages a day — are for bulk senders, so the extra requirements don't apply. The baseline ones do, and they apply to everyone. Low volume also means you have no reputation cushion: a filter that isn't sure about you has very little history to reassure it.
My email worked fine for years. Why now?
Because the rules changed in 2024 and again in 2025, and because configuration drifts. You added tools, changed platforms, and someone added a second SPF record when the first one wasn't working. Both things happened at once.
Will fixing this guarantee my email reaches the inbox?
No, and be suspicious of anyone who promises that. Authentication gets you considered rather than discarded. Reputation and content decide the rest. What it does guarantee is that you stop failing for a reason that has nothing to do with the quality of your message.
Can I check this myself?
Yes. The free checker on this site reads your SPF, DKIM, DMARC and MX records straight from public DNS, in your browser, and explains each one. It won't tell you whether every tool you send from is covered — that part needs someone to inventory your systems.
Find out where your domain actually stands.
The checker reads your real records in a few seconds. The review works out whether they cover everything you send.