Why Your Emails Are Going to Spam — and the DNS Records That Actually Fix It

Email deliverability infographic showing emails going to spam, SPF, DKIM, and DMARC DNS records, authentication checks, inbox delivery, and spam folder prevention

By Sarah Dia, HostDroplet Support

You set up a shiny new email address on your own domain, send a test message to a friend on Gmail, and… it lands in the spam folder. Or worse — it bounces straight back with a cryptic error. It feels like something is broken with your hosting, but nine times out of ten it isn’t. It’s that the big inbox providers can’t yet prove the email really came from you.

The good news: emails going to spam is one of the most fixable problems in all of web hosting. It almost always comes down to three DNS records. This guide explains what they do in plain English, why they suddenly matter more than they used to, and — the part most articles skip — the order to actually check them in when something’s wrong.

The 30-second mental model

Every time you send an email, the receiving server (Gmail, Outlook, Yahoo) asks one question before deciding where to put it: “Can I verify this message really came from the domain it claims to be from?”

If it can’t verify you, it does the safe thing and treats you like a stranger — spam folder, or rejection. Three DNS records are how you answer that question with a confident “yes”:

  • SPF — lists which servers are allowed to send mail for your domain.
  • DKIM — adds a tamper-proof signature that proves the message wasn’t altered.
  • DMARC — ties the first two together and tells inbox providers what to do if either one fails.

Think of it as ID at a door: SPF is the guest list, DKIM is the signature that matches your ID, and DMARC is the instruction the bouncer follows when something doesn’t line up. All three are set up in your domain’s DNS.

Why this got urgent (and why “it worked last year” isn’t enough)

For a long time these records were “nice to have.” That era is over. Since February 2024, Gmail and Yahoo have required bulk senders — anyone sending roughly 5,000+ messages a day to their users — to have all three set up and aligned. As enforcement tightened through late 2025 and into 2026, non-compliant mail stopped going to the spam folder and started getting rejected outright at the server level.

Here’s the part that catches small site owners off guard: even if you’re nowhere near 5,000 emails a day, the same filters grade you too. An unauthenticated email from a small domain is now treated with suspicion by default. So whether you send ten emails a month or ten thousand, the baseline expectation is the same — authenticate, or expect the spam folder.

The three records, in plain English

1. SPF — the guest list

An SPF record is a single line in your DNS that lists every server allowed to send email as your domain. When Gmail receives a message claiming to be from you, it checks whether the sending server is on that list. If it isn’t, the message looks forged.

The most common SPF mistake isn’t a missing record — it’s a broken one. SPF is only allowed to trigger 10 DNS lookups; pile on too many third-party senders (your host, a newsletter tool, a CRM) and it silently fails for everything, even legitimate mail. Learn the mechanics in our guide to what an SPF record is, then confirm yours is valid with the free SPF Record Checker.

2. DKIM — the signature

DKIM attaches a cryptographic signature to every message you send. The receiving server checks that signature against a public key published in your DNS. If they match, it proves two things at once: the message really came from your domain, and nobody tampered with it in transit.

DKIM failures are especially common right after you switch email providers or make DNS changes — the old key stops matching and nothing tells you. Our DKIM record guide walks through how it works, and the DKIM Record Checker confirms your key is published and valid.

3. DMARC — the instructions

DMARC is the policy layer. It tells inbox providers what to do when a message fails SPF or DKIM — ignore it, quarantine it, or reject it — and it can send you reports showing who’s sending mail as your domain. Even a basic p=none policy now counts as “having DMARC,” which is the bare minimum the big providers look for. See our DMARC record guide for a plain-English walkthrough, the official DMARC.org project if you want the full technical standard, and the DMARC Record Checker to validate yours.

A quick word on MX records

People often lump these together, so it’s worth clearing up: your MX record controls where your incoming mail is delivered, not whether your outgoing mail passes authentication. If you can’t receive email, check your MX with the MX Record Checker. If you can receive fine but your sent mail lands in spam, MX isn’t your problem — the three records above are.

The silent killer: alignment

This is the piece almost no beginner guide explains, and it’s the reason plenty of people “set up SPF and DKIM” and still land in spam. It’s not enough for those checks to pass — the domain in your visible “From:” address has to match the domain that SPF or DKIM validated. That match is called alignment, and without it DMARC fails even when everything else looks green.

The classic trap: you send newsletters through a third-party tool, the mail authenticates under the tool’s domain instead of yours, and alignment breaks. If you use any external sending service, you have to configure it to sign with your domain — not leave it on the default.

The order to actually check things (a real troubleshooting flow)

When mail is going to spam, don’t randomly edit DNS. Work through it in this order:

  1. Confirm what’s actually happening. Send a test to a Gmail account, open the message, and choose “Show original.” Gmail shows PASS/FAIL for SPF, DKIM, and DMARC right at the top. That tells you which record to focus on instead of guessing.
  2. Check all three at once. Run your domain through our Email Deliverability Checker for a single view of what’s passing and what’s missing.
  3. Zoom in on the failing record using the SPF, DKIM, or DMARC checker, and cross-reference your live DNS with the DNS Lookup tool.
  4. Fix it at the source. If your email is hosted here in cPanel, the built-in Email Deliverability panel flags and repairs most SPF/DKIM issues for you — our step-by-step guide on fixing emails going to spam in cPanel walks through it.
  5. Wait for DNS to update. DNS changes aren’t instant. If a fix hasn’t taken effect, it may still be propagating — here’s how to handle DNS propagation.

When it’s not your DNS records

Sometimes authentication is perfect and mail still lands in spam. Editing DNS won’t help here, so it’s worth ruling these out honestly:

  • The content looks spammy. All-caps subject lines, “FREE!!!”, a single giant image with no text, or link-stuffed messages get filtered regardless of authentication.
  • The list is cold or purchased. Sending to people who never opted in spikes complaint rates fast. Gmail and Yahoo start penalizing you once complaints cross 0.3% — and on a small list, that’s only a handful of “report spam” clicks.
  • Reputation, not authentication. A brand-new domain or a noisy shared IP has no track record yet. This improves as you send consistent, wanted mail over time.
  • Your form sends from the wrong address. A contact form that sends “from” a Gmail address it doesn’t control will fail authentication every time. If your WordPress contact form isn’t sending email, this is usually why.

WordPress-specific note

WordPress sends mail (password resets, form notifications, order receipts) through PHP by default, and that mail frequently fails authentication because it doesn’t go through your properly configured mail server. The reliable fix is to route WordPress email through authenticated SMTP using your real mailbox — which you can create in cPanel in a couple of minutes. Once WordPress sends as an authenticated address on your domain, SPF and DKIM apply and delivery improves immediately.

FAQ

Do I need all three records if I only send a few emails?

Yes. The strict enforcement targets bulk senders, but the same filters grade small senders too. Unauthenticated mail from any domain is far more likely to be flagged, so SPF, DKIM, and DMARC are effectively the baseline for everyone now.

I set up all three and mail still goes to spam. Why?

Most often it’s alignment — the records pass, but the “From:” domain doesn’t match the authenticated domain, so DMARC fails. If alignment checks out, look at content, list quality, or sending reputation rather than DNS.

Do I need DMARC if I use Google Workspace or a tool like Mailchimp?

Yes. You still publish DMARC on your own domain, and you must configure the third-party tool to sign with your domain so it stays aligned. Skipping that step is one of the most common reasons “authenticated” mail still fails.

How long do DNS changes take to work?

Anywhere from a few minutes to a day or two, depending on caching. If a correct fix doesn’t seem to be working yet, it’s usually still propagating — confirm the live state with the DNS Propagation Checker.

The bottom line

Email landing in spam feels mysterious, but it’s rarely mysterious once you know what inbox providers are checking. Prove you’re really you — SPF, DKIM, DMARC, aligned — and most deliverability problems disappear. Start by running your domain through the free Email Deliverability Checker to see exactly where you stand.

Setting up email on a new domain and want it done right from day one? Our shared hosting and WordPress hosting plans include cPanel’s Email Deliverability tools, so SPF and DKIM are handled for domains you host with us.

Scroll to Top