What DMARC is, and why your email lands in spam
“Check your spam folder” shouldn’t be part of every phone call with a client. If your invoices, proposals or appointment reminders keep landing in spam, there’s a good chance the problem isn’t what you wrote. It’s that the receiving mail system can’t confirm the message really came from you.
That confirmation comes from three settings with unfriendly names: SPF, DKIM and DMARC. Here’s what each one does, in plain English.
The problem: anyone can put your name on an envelope
Email was designed decades ago without any built-in way to prove who sent a message. A scammer can send an email that says it’s from you@yourcompany.com, much like someone could write your return address on an envelope. Big email providers have gotten strict about this. If they can’t verify that a message really came from your domain, they are more likely to send it to spam or reject it outright.
That cuts both ways. It protects your clients from fake emails pretending to be you, but it also means your own real mail gets treated with suspicion if your settings aren’t right.
SPF: the approved sender list
SPF (Sender Policy Framework) is a record you publish in your domain’s DNS settings that lists which servers and services are allowed to send email for your domain. Microsoft 365 is usually on that list. But many offices also send mail through other services: a billing system, a website contact form, a newsletter tool, a scanner that emails documents. If those aren’t listed, their messages can look fake.
DKIM: the tamper-proof seal
DKIM (DomainKeys Identified Mail) adds a digital signature to each message. The receiving system checks that signature against a key you publish in DNS. If it matches, it knows the message came from an approved source and wasn’t changed along the way. Microsoft 365 supports DKIM, but in many tenants it has never been turned on for the office’s own domain.
DMARC: the instructions and the report card
DMARC (Domain-based Message Authentication, Reporting and Conformance) ties the other two together. It’s another DNS record that tells receiving mail systems two things:
- What to do with a message that claims to be from your domain but fails the checks: deliver it anyway, send it to spam, or reject it.
- Where to send reports about the mail they see using your domain, both real and fake.
Those reports are the part most people never use, and they’re the most valuable. They show you every service sending mail as your domain, including ones you forgot about and ones that are scammers.
Why your mail might be landing in spam
Common causes I find in small offices:
- No DMARC record at all. Some large email providers now expect one, especially from senders that send a lot of mail.
- An SPF record that’s missing a service, such as the billing system that sends your invoices.
- More than one SPF record, which breaks it. There should be only one.
- DKIM never turned on for your domain in Microsoft 365.
- A third-party service sending as your domain without its own DKIM set up.
Spam filters look at other things too, like the content of the message and your sending history, so these settings won’t solve every case. But they are the foundation, and without them other fixes don’t help much.
How to fix it without breaking your email
The risky mistake is jumping straight to a strict DMARC policy that tells the world to reject anything that fails. If you’ve missed a legitimate service, its mail, like your invoices, will start disappearing. The safe approach goes in stages:
- Take inventory of every system that sends email using your domain.
- Fix SPF so it lists all of them in a single, valid record.
- Turn on DKIM for Microsoft 365 and for each other service that supports it.
- Publish DMARC in monitoring mode, which changes nothing about delivery but starts the reports flowing.
- Read the reports for a few weeks and fix anything legitimate that’s failing.
- Tighten the policy step by step, first to quarantine, then to reject, once you’re confident.
Getting it done
You can check whether your domain has these records with free online lookup tools, but making sense of the results and the reports takes some experience. I set up SPF, DKIM and DMARC for small offices, move the policy to full protection in safe stages, and keep watching the reports so a new billing system or website form doesn’t quietly start landing in spam.
Want a second set of eyes? Greg offers a free 15-minute quick look at your Microsoft 365 sign-in and email forwarding settings. No cost, no obligation. Call or text (941) 479-1075 or email greg@squaredawaytechfl.com.
Book a quick lookSquared Away Tech serves offices of 5 to 100 people in Ellenton, Bradenton, Sarasota and Tampa Bay, with remote service anywhere in the U.S. Mon–Fri 5–9 PM and Sat 9 AM–5 PM (Eastern Time). Daytime and Sunday appointments available on request; daytime calls get a same-evening callback. Back to the home page · More guides
This guide is general information, not legal or insurance advice. Every office’s setup is different.