By: Luis Teijon

Why Your Emails Keep Landing in Spam (and How to Fix It)

Have you ever wondered why your emails end up in the Spam folder, even when you’ve put effort into writing them and sending them to known contacts? There are various reasons why an email fails to reach its intended inbox, but today we’re focusing on three DNS-based protocols that fix the majority of authentication-related deliverability issues: SPF, DKIM, and DMARC. The terms sound technical, but the underlying logic is simple, and we’ll use plain examples to walk through each one.

SPF (Sender Policy Framework)

How does it work?

When you send an email from your domain (e.g., @yourdomain.com), the receiving server (Gmail, Outlook, etc.) checks your DNS for the SPF record. This record acts like a “guest list,” specifying which servers are allowed to send emails as if they were from @yourdomain.com. The receiving server, acting like a “security guard,” verifies whether the sender is on this list. If the sender is listed, the email is trusted and more likely to reach the inbox. If not, the email is marked as suspicious, often landing in spam or getting rejected outright.

Example: Imagine attending a private party with a security guard at the entrance holding a guest list. If your name is on the list, you enter without issues. If not, entry is denied. Similarly, emails claiming to originate from your domain without proper SPF authorization are treated as unauthorized.

DKIM (DomainKeys Identified Mail)

What is it?

DKIM adds a digital signature to every email you send. This signature enables receiving servers to confirm that the message truly came from you and wasn’t altered in transit.

How does it work on the receiver’s end?

When an email server receives your message, it notes it’s from @yourdomain.com. The server then retrieves the public DKIM key you’ve published in your domain’s DNS. Using this public key, it verifies the signature included in your email. If the signature matches, it confirms the message was genuinely sent by you (or an authorized service) and hasn’t been modified. If there’s a mismatch, the email might be treated as fraudulent or tampered with, likely resulting in it being marked as spam.

Example: Every email is like a letter sealed with a unique wax stamp, created with your “private key.” Your domain publishes a “public key” in the DNS to verify this stamp. If the seal matches the public key, the recipient knows the message is genuine and intact.

DMARC (Domain-based Message Authentication, Reporting & Conformance)

What is it?

DMARC is an additional policy that combines SPF and DKIM. It dictates how a receiving server should handle emails from your domain that fail SPF or DKIM checks. DMARC also allows receiving servers to send you reports detailing which emails pass or fail these validations.

How is it executed upon reception?

The receiving server first checks whether the email complies with SPF and DKIM rules. It then consults your domain’s DNS for your DMARC policy, which specifies what action to take if validations fail — reject, quarantine in spam, or simply mark as suspicious. DMARC also instructs the receiver to send you reports about these events, so you can monitor failed validations, detect spoofing attempts, and take appropriate action.

Example: Besides your “guest list” (SPF) and your “wax seal” (DKIM), you establish a policy that says: “If someone isn’t listed or has an altered seal, either reject them or hold them aside for review.” That’s DMARC. You’ve also asked the “security guard” (receiving server) to inform you whenever such an incident occurs, helping you track fraudulent attempts.

Conclusion

These protocols matter because they enhance your domain’s credibility with email providers while protecting your recipients from phishing and fraud. If you’re experiencing high bounce rates or emails consistently landing in spam, confirm that SPF, DKIM, and DMARC are correctly configured. An unauthenticated domain isn’t just a deliverability problem — it’s also an open door for anyone to impersonate you in a phishing campaign, since there’s nothing stopping an attacker from sending mail that appears to come from you.

  →  Run your free External Attack Surface Scan
teisoftllc.com/free-vulnerability-scan/ — find out in minutes whether your domain’s SPF, DKIM, and DMARC records are correctly configured, along with the rest of your externally discovered attack surface.
Share:
Tags

Search

Recent Posts

Free WordPress Website Audit

Hidden threats: we find the vulnerabilities that could take you out of business.