Email Deliverability: How to Stop Emails Going to Spam (SPF, DKIM, DMARC) for Small Business

()


Most Viral Tool - SEO Audit Tool  | Reseller Profit Tracker Generator | Freelance Invoice Generator | ADHD Planner Generator

Why Your Business Emails Keep Landing in Spam

You send a perfectly normal email to a potential client, and it never arrives. Or worse — it arrives in their spam folder, where 85% of email users never look. For small businesses, this is not just an annoyance — it directly costs revenue. Every email that hits spam is a proposal unread, a follow-up ignored, a lead lost.

The good news: most email deliverability problems for small businesses come down to three DNS records that you can set up in under an hour. They are called SPF, DKIM, and DMARC. If you have never heard of them, this guide will explain exactly what each one does, why email providers require them, and how to set them up step by step using cPanel or your hosting control panel.

Why Emails Land in Spam: The Technical Reality in Plain Language

When you send an email, the receiving server (Gmail, Outlook, Yahoo, etc.) runs several checks to decide whether to deliver it to the inbox or the spam folder. The three biggest factors are:

  • Authentication — Can the receiving server verify that you are really who you say you are? This is where SPF, DKIM, and DMARC come in.
  • Sender reputation — Has your domain or IP address sent spam before? Have people marked your emails as spam?
  • Content and behavior — Does your email look like spam? Are you sending to invalid addresses? Are recipients engaging with your emails?

Most small business email problems are authentication issues, not content problems. You can write the most professional email in the world, but if your DNS records are not set up correctly, email providers assume you are either spoofing the domain or sending from an unauthorized server.

Trending Today- Earn $$$ FREE  | Trending LIFE Quotes | HOT DEBATES | Autograph | FREE PAID Tools | Advertise FREE |

SPF: Proving You Own the Servers That Send Your Email

What it is: SPF (Sender Policy Framework) is a DNS TXT record that lists the mail servers authorized to send email from your domain.

Why it matters: Without SPF, anyone can forge an email that appears to come from your domain. Email providers cannot tell the difference between a legitimate email from your server and a phishing email sent from a criminal’s server. SPF gives them a reference list to check against.

How to set it up:

  1. Log into your hosting control panel (cPanel or similar)
  2. Go to “Zone Editor” or “DNS Zone Editor”
  3. Add a new TXT record with the following values:

Host: @ (or leave blank, depending on your DNS provider)

Type: TXT

Value: v=spf1 include:_spf.google.com include:relay.kagou.net ~all

Replace the include values with the ones provided by your email host. If you use Google Workspace, the value above works. If you use Microsoft 365, use include:spf.protection.outlook.com instead. If you use a third-party email service like Mailchimp or Campaign Monitor, check their documentation for the correct include value — for instance, when comparing email platforms like Campaign Monitor and Mailchimp, each provides their own SPF include value in their authentication setup docs.

The ~all at the end tells receiving servers to softly fail emails from unauthorized senders (mark them as suspicious but not reject outright). Use -all (hard fail) only after you are confident all your legitimate mail sources are listed.

DKIM: Adding a Digital Signature to Every Email

What it is: DKIM (DomainKeys Identified Mail) adds a cryptographic signature to each outgoing email. The receiving server uses your public DNS record to verify that the email was sent by an authorized server and was not modified in transit.

Why it matters: Even if SPF passes, a determined attacker can still alter an email’s content after it leaves your server. DKIM ensures the email that arrives is exactly what you sent. Major email providers like Gmail and Outlook heavily weight DKIM when deciding inbox placement.

How to set it up:

  1. In cPanel, look for the “Email Deliverability” or “DKIM” section
  2. cPanel can often auto-generate your DKIM record — click “Enable” or “Install” next to your domain
  3. If auto-generation is not available, your email provider (Google Workspace, Microsoft 365, etc.) will give you a specific DNS TXT record to add. It will look something like:

Host: google._domainkey (or a unique selector your provider specifies)

Type: TXT

Value: A long string starting with v=DKIM1; k=rsa; p= followed by a long public key

Save the record and wait for DNS propagation. You can verify it is active using MXToolbox’s DKIM lookup tool.

DMARC: Telling Email Providers What to Do When Authentication Fails

What it is: DMARC (Domain-based Message Authentication, Reporting & Conformance) builds on SPF and DKIM. It tells the receiving server what to do if both SPF and DKIM checks fail — and where to send reports about your email authentication.

Why it matters: Without DMARC, you have no control over what happens when authentication fails, and you get zero visibility into who is sending email from your domain. DMARC is also increasingly required by major email providers — Google and Yahoo announced in 2024 that bulk senders must have DMARC in place.

How to set it up:

  1. Add a new TXT record in your DNS zone editor
  2. Host: _dmarc
  3. Type: TXT
  4. Value (start with monitoring mode):

v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com; pct=100

Start with p=none — this tells email providers to just report failures without actually rejecting your emails. Monitor the reports for 2-4 weeks. Once you confirm legitimate email is passing authentication, move to p=quarantine (send failures to spam) and eventually p=reject (block failures entirely).

This gradual rollout prevents you from accidentally blocking your own legitimate email while you are still verifying that everything is configured correctly.

Warming Up a New Sending Domain

Even with perfect DNS configuration, a brand-new sending domain will have no reputation. Email providers are naturally suspicious of emails from domains they have never seen before. You need to warm up the domain gradually:

  • Week 1: Send 5-10 emails per day to people you know will open and reply (friends, colleagues, loyal customers)
  • Week 2: Increase to 20-30 per day, continuing to recipients who engage
  • Week 3-4: Gradually increase to your normal sending volume

During warmup, avoid sending bulk marketing emails from the same domain you use for personal and sales communication. Use your marketing platform (Mailchimp, Campaign Monitor, etc.) which has its own established sending reputation — if you are evaluating options, our Campaign Monitor vs Mailchimp comparison covers deliverability features side by side.

Avoiding Spam-Trigger Words (Without Writing Like a Robot)

Content still matters. While SPF/DKIM/DMARC solve the authentication side, certain email content patterns still trigger spam filters:

  • ALL CAPS subject lines
  • Excessive exclamation marks!!!
  • Phrases like “100% FREE,” “Act NOW,” “Limited time offer,” “No cost”
  • Large amounts of red text or oversized fonts
  • Too many links in the body, especially to unfamiliar domains

The fix is simple: write like a professional human. If your email reads like something you would say in a conversation, it will almost always pass content filters. The goal is not to avoid every possible trigger word — it is to write genuine, relevant emails to people who expect to hear from you.

List Hygiene: The Deliverability Factor Most People Ignore

Sending emails to invalid or unengaged addresses actively damages your sender reputation. Email providers track your bounce rate, and if it climbs above 2-3%, they start treating your domain as a spam source.

Bounce Management

Hard bounces (invalid addresses, nonexistent domains) should be removed from your list immediately after the first bounce. Soft bounces (full inboxes, temporary server issues) should be retried 2-3 times over a few days, then removed if they persist.

Re-engagement Campaigns

For subscribers who have not opened an email in 90+ days, send a re-engagement sequence:

  1. Email 1: “We miss you — here is what you have been missing” with a summary of recent content or offers
  2. Email 2: “Is everything okay?” — a direct, personal check-in
  3. Email 3: “We are removing you from our list unless you want to stay” — final notice

Anyone who does not engage with all three emails should be removed. A smaller, engaged list delivers better results than a large, unresponsive one. If you are considering switching email platforms to improve deliverability, we compared the costs and features in our email marketing platform comparison.

Monitoring Tools: Verify Your Setup Is Working

After setting up SPF, DKIM, and DMARC, verify everything is configured correctly:

  • MXToolbox (free) — checks your SPF, DKIM, and DMARC records, shows you exactly what email providers see
  • mail-tester.com (free) — send a test email to the address they provide, and they give you a detailed score out of 10 with specific fixes for any issues
  • Google Postmaster Tools (free) — if you send volume to Gmail users, this shows your domain reputation, authentication rates, and spam rates directly from Google
  • DMARC reports — once your rua address is set up, you will receive daily reports showing which emails passed or failed authentication

Check these tools monthly — DNS records occasionally get overwritten during hosting migrations or website updates, and a broken SPF record can silently wreck your deliverability overnight.

The Bottom Line

Email deliverability is not a mystery. Set up SPF, DKIM, and DMARC correctly. Warm up new domains gradually. Send emails to real people who want to hear from you. Keep your list clean. And verify everything with free tools once a month.

These are not advanced techniques reserved for enterprise companies — they are baseline hygiene that any small business owner can implement in under an hour. If your website and digital presence need a broader overhaul, our website redesign guide covers how to audit and improve your entire online infrastructure.

About the Author

Written by Steve | Digital Strategist at Web1Expert | 5+ years helping businesses build, optimize, and grow their online presence through web design, SEO, and content marketing.


Frequently asked questions

What is SPF and why does my business email need it?
SPF (Sender Policy Framework) is a DNS record that tells the internet which mail servers are allowed to send email from your domain. Without it, email providers like Gmail cannot verify that your emails are legitimate, and they are much more likely to land in spam.

What is the difference between SPF, DKIM, and DMARC?
SPF verifies which servers can send mail from your domain. DKIM adds a digital signature to each email proving it was not altered in transit. DMARC tells receiving servers what to do when SPF or DKIM checks fail. All three work together — you need all of them for reliable deliverability.

How long does it take for SPF, DKIM, and DMARC records to take effect?
DNS changes typically propagate within 15 minutes to 48 hours, with most taking effect within 1-4 hours. You can check propagation using a free tool like MXToolbox or dnschecker.org.

Can I set up SPF, DKIM, and DMARC myself in cPanel?
Yes. Most managed hosting and cPanel environments have built-in tools for DKIM and SPF. You add DNS records through your hosting control panel or domain registrar. The process takes 30-60 minutes for all three records.

How do I know if my emails are actually reaching inboxes?
Send a test email to mail-tester.com (free tool) — it will score your email on a 10/10 scale and tell you exactly what is wrong. You can also check your domain reputation on MXToolbox and monitor Google Postmaster Tools if you send high volumes.

How useful was this post?

Click on a star to rate it!

Steve

Steve is a digital strategist and side-hustle expert with over 5 years of experience in growing online platforms. He specializes in web optimization, productivity workflows, and turning creative habits into profitable online businesses.

Leave a Reply