Infrastructure · 4 min read

Why Business Emails Go to Spam: SPF, DKIM and DMARC Explained

Why legitimate business emails land in spam, and how SPF, DKIM and DMARC records authenticate your domain. A plain guide with a setup checklist.

When quotations, invoices and statements land in a customer's spam folder, the cause is often technical and not the wording of the message. Three email authentication standards, SPF, DKIM and DMARC, tell receiving mail servers whether a message really comes from your domain. This guide explains each in plain terms for Philippine business owners and managers.

Why legitimate business emails go to spam

Receiving mail servers assess every message before it reaches an inbox. Common reasons a genuine email fails that assessment:

  • The domain has no authentication records, or the records are wrong.
  • Mail is sent from a shared server with a poor reputation.
  • A third-party tool, such as an accounting system, CRM, newsletter service or website contact form, sends as your domain without being authorised.
  • A sudden burst of messages from a domain that normally sends few.
  • Content signals such as misleading subject lines, shortened links or unusual attachments.
  • Recipients marking earlier messages as spam.

SPF: which servers may send for your domain

SPF stands for Sender Policy Framework. It is a record in your domain's DNS, the public settings that tell the internet where your website and email are handled. The record lists the servers and services permitted to send email for your domain. The receiving server checks whether the sending server is on that list.

Common SPF problems:

  • More than one SPF record on a domain. Only one is permitted.
  • A sending service left off the list.
  • Too many included services, which exceeds the lookup limit built into the standard and causes the check to fail.

SPF can also fail when a message is forwarded, which is one reason it is not sufficient alone.

DKIM: a digital signature on each message

DKIM stands for DomainKeys Identified Mail. The sending server attaches a digital signature to each message using a private key. The matching public key is published in your DNS. The receiving server uses it to confirm two things: that the message was signed by your domain, and that it was not altered on the way.

Each service that sends on your behalf usually needs its own DKIM setup. Because the signature travels with the message, DKIM generally survives forwarding better than SPF.

DMARC: the policy that ties SPF, DKIM and DMARC together

DMARC stands for Domain-based Message Authentication, Reporting and Conformance. It does three things.

  • Alignment: it requires that the domain shown in the visible From address matches the domain confirmed by SPF or DKIM.
  • Policy: it tells receiving servers what to do with mail that fails. The options are to take no action and only monitor, to quarantine the message (usually the spam folder), or to reject it.
  • Reporting: it asks receiving servers to send you reports on who is sending mail as your domain.

DMARC also protects your customers. Without it, a fraudster can more easily send a fake invoice or a notice of changed bank details that appears to come from your company.

The safe approach is staged. Start in monitoring mode, read the reports, fix every legitimate sender, then move to quarantine and finally to reject. Going straight to reject can block your own invoices.

Email authentication setup checklist

  1. List every system that sends email using your domain, including ones set up years ago.
  2. Publish a single, correct SPF record covering all of them.
  3. Enable DKIM signing for each sending service.
  4. Publish a DMARC record in monitoring mode with a reporting address.
  5. Review the reports over several weeks and correct any failures.
  6. Tighten the DMARC policy in steps.
  7. Repeat the review whenever a new tool that sends email is added.

How AI affects spam filtering

Mailbox providers use machine learning to judge sender reputation and message content, which is why there is no fixed formula that guarantees the inbox. On the sender's side, AI tools can summarise DMARC reports, which arrive as technical files that are hard to read, and point out unfamiliar sending sources.

Authentication itself is strictly rule-based. A record is either correct or it is not, and no AI tool compensates for a missing DKIM signature. Policy changes should be reviewed by a person who knows which senders are legitimate, since a wrong decision can stop business email.

Frequently asked questions

Will SPF, DKIM and DMARC guarantee inbox delivery?

No. They prove that a message comes from your domain, which is a precondition, but sender reputation and content still count.

Do we need them if we send only a few emails a day?

Yes. Low-volume domains are checked in the same way, and the protection against spoofing applies regardless of volume.

Who should set these up?

Whoever manages your domain's DNS and email hosting, working with the providers of any third-party tools that send email for you.

WCube Solutions provides business email for Philippine companies with authentication configured and maintained. The Email Hosting service includes SPF, DKIM and DMARC setup and review of the services that send on your domain's behalf.

Solution consultation

Request a Solution Consultation.

Tell us how the process runs today. The first conversation is a requirements exercise, not a demo.

  1. Initial consultationWe walk through the current process, systems and handoffs.
  2. Requirements reviewWhere the time goes, and which interfaces the work would touch.
  3. Written scopeDocumented before anything is quoted or built.