Podcast/Episode 2026-2

Why Your Emails Keep Going To Spam

Episode 2026-2

If your business emails keep landing in spam, the cause is usually authentication and sender reputation, not luck. Here is what sends email to the junk folder and how to fix it.

Key Takeaways

  • SPF, DKIM, and DMARC are the three records that prove your email really comes from you and not a spoofed sender.
  • Since Google and Microsoft tightened their rules about 18 months ago, missing or incomplete records can push legitimate email into spam or block it entirely.
  • Deliverability problems usually surface first with bulk senders like HubSpot or Constant Contact that were never added to your SPF record.
  • Once configured correctly, email authentication is largely hands-off, as long as you keep new sending services included.
  • A quarantine policy holds suspicious inbound email in a secure container; rolling it out in monitor-only mode first avoids disruption.

Full Transcript

Shane Naugher: Welcome back to another edition of Give IT To Me Straight, where we go through common IT and technical issues and questions we get inside our operations, and walk through the explanations, the tips, and why they matter to you. I'm really excited today to have Anthony Chambers with us. Anthony is a favorite among our client base, he's been with us for many years, and he currently sits on our business innovation advisement team.

Shane Naugher: We're diving into a somewhat technical topic that's become very relevant to business operations, especially in the last 12 to 18 months: DKIM, SPF, and overall email deliverability. The way this is configured today can drastically impact your ability to communicate with your clients and vendors, and can potentially prevent you from communicating at all. So Anthony, kick us off. What is this, and what does it mean?

What Are SPF, DKIM, and DMARC?

Anthony Chambers: Happy to be on, by the way. It's been a long time since we did a podcast together, probably about eight years ago, so that's kind of crazy. There are three major components to authentication through email. Essentially, they establish confidence that when you send an email to a recipient, they know it's coming from you, and not from a threat actor who's decided to spoof or pretend to be your organization. Those three components are SPF records, DKIM records, and DMARC records.

Anthony Chambers: The way I like to think about it is that SPF records establish who is allowed to send email on behalf of your domain, so yourbusiness.com. In there you'd set things like Constant Contact and the different vendors that send email as your organization, not just your own email servers. DKIM then establishes trust by making the recipient compare a key. It says, "This handshake here, is this a legitimate sender?" It's not just something on a list; we're establishing a level of confidence that this is legitimate.

Anthony Chambers: The last one is DMARC, and I like to think of it as an advisor. It tells the recipient what to do if the SPF or DKIM record isn't matching up. Most recipients, the people you're sending to, have their own rules for what's acceptable. The DMARC record tells those recipients how confident you are about the services you're using and the security behind your sending protocols.

Why Email Authentication Became Urgent in the Last 18 Months

Shane Naugher: Historically this became an issue in the last 12 to 18 months, because the bigger email providers like Google and Microsoft said, "We have a problem with spam, phishing, and malicious email, and we need a common framework to verify that legitimate email is legitimate." About 18 months ago they implemented strict controls around this.

Anthony Chambers: Yeah, Google did, and it's been kind of nutty. With the larger publicly available or free options like Gmail and Outlook, they'd pushed it off for what seems like five or six years before this mandatory rollout. Now that it's in place, it's not always an exact science. Sometimes things slip through, and sometimes you get delivery, but it's very inconsistent without the DMARC record. The DMARC record ties everything together.

Why Legitimate Email Gets Flagged as Spam

Shane Naugher: Where we typically see this from clients is, "We've been sending out messages and our clients aren't getting them," or they're getting flagged as spam. When we investigate, it's usually because they're using a HubSpot, a Constant Contact, or a marketing agency to send email. It's not necessarily when they send from Outlook. It can affect those too, but for the most part we see it reported first with marketing, sales, or client-communication email. Then we find it's not set up, or even if it is set up, those providers weren't included as part of it.

Anthony Chambers: Yes. For implementing SPF, DKIM, and DMARC, as long as you know who's sending email on your behalf, getting those records in isn't typically a big deal. But you run into situations where maybe you procured a new system to send newsletters, and suddenly none of that is being delivered, and email from your employees to specific recipients can be affected too. So it's important to stay on top of.

Set It Up Once, Then Keep Your Senders Current

Anthony Chambers: Once you have it implemented, it's essentially a hands-off thing. It stays in place as long as you continue to maintain the services that need that type of access.

Shane Naugher: That's a good point. It's not something you have to tweak every month. There may be some setting changes, but for the most part, once you set it up, it's done. Most of the marketing platforms in use today have implemented a verification process, so if you set one up today it will say, "We need these DKIM, DMARC, and SPF settings configured before we let you send." What we typically see is, "Oh, we were using this application five years ago and forgot about it," so it's not part of that setup and it's causing deliverability issues on that specific platform.

Quarantine Policies for Inbound Email

Shane Naugher: The next piece we get questions on is the quarantine aspect of spam for inbound delivery. If you don't have a quarantine policy in place today, walk us through how that fits in and what it looks like to implement.

Anthony Chambers: When you establish SPF, DKIM, and DMARC records, it changes how recipients determine how they'll interact with your mail, and most often you'll have a quarantine. Everybody is aware of the junk email side of things, where Gmail shoves promotions into junk. A quarantine is a separate, secured container, so if a potentially malicious email reaches the tenant, it's held in a safe place. Typically you get a digest at the end of the day that says, "Here's the email we've marked as potentially malicious," which gives you a chance to catch an accidental flag.

Anthony Chambers: It prevents the end user from that initial uncertainty of "is this a legitimate email," especially when it has other warning signs, like an SPF record that doesn't match what's published or a DKIM record that doesn't look right. Your DMARC record gives you options for how you want recipients to handle that: you can tell them to outright reject it, quarantine it, or do nothing. We wouldn't recommend doing nothing. Quarantine is typically the one we'd suggest. You also want a thorough quarantine for your inbound email, plus an authorization process, so someone doesn't act on a message and end up getting their credentials compromised. That's ultimately what the quarantine is trying to prevent.

Rolling Out Quarantine Without Disruption

Shane Naugher: We've seen some confusion, especially with organizations that aren't using quarantine today, because reviewing and authorizing legitimate email on a periodic basis is a bit of a different process. A common question is whether it will slow things down. The short answer is it could, but it's for the best overall protection. A lot of times what we'll do is start with that policy in monitor-only mode for a defined timeline, maybe the first 30 days, so we can see what would be quarantined and build rules around it. Adding that quarantine policy protects the organization as best as possible from threats that come in through email. Fantastic, Anthony. This has been very enlightening, and it's great for us to connect again.

Anthony Chambers: I really appreciate you having me, Shane. This was a really fun experience.

Ready to Stop Worrying About IT?

Join hundreds of Missouri organizations who trust DaZZee IT as their technology partner. 25+ years, 80% same-day resolution.

60-day trial
100% satisfaction guarantee
No setup fees