Why are business emails going to spam?
Business emails go to spam when the receiving mail server is not confident the message is genuine and wanted. It decides using authentication results, the sending server’s reputation, the domain’s history and how recipients have reacted to similar mail.
Think of the receiving server as a security guard. First it checks identity: does the domain in the From address authorise this server to send for it (SPF)? Is the message signed with the domain’s key (DKIM)? Does the domain publish a policy saying what to do with failures (DMARC)? Then it checks reputation: has this IP address or domain sent spam before, is it on public blocklists, do recipients mark its mail as spam? Finally it looks at the message: suspicious links, misleading subjects, image-only content.
For small Indian businesses, the causes we find most often are mundane. SPF records that list the web host but not Google Workspace or Zoho. DKIM never switched on after buying mailboxes. No DMARC record at all. Two SPF records added by different people over the years. And, very often, the website’s contact form sending mail through the shared hosting server, from an address on your domain, with no authentication.
The good news is that most cases of business emails going to spam are fixable in DNS and settings, without changing your email provider or your address.
When business emails are going to spam, open one that landed there, view its original headers, and find the Authentication-Results line. It states whether SPF, DKIM and DMARC passed or failed, which tells you where to start.
In Gmail, open the message, choose “Show original”, and Gmail displays SPF, DKIM and DMARC results at the top. In Outlook, message headers sit under the message properties or “view source” options. Ask a friend with a Gmail account to send your spam-foldered message back to you as an attachment if you cannot see it yourself.
What the results usually mean:
- SPF fail or softfail: the server that sent the message is not listed in your SPF record. Common with website mail and third-party tools.
- SPF permerror: the record is broken, for example two SPF records or more than ten DNS lookups.
- DKIM none: signing is not enabled at your provider, or the DNS key is missing.
- DKIM fail: the key in DNS does not match, often after a provider change or a copy-paste error.
- DMARC fail: SPF or DKIM may pass, but not for the domain in the From address; this is the alignment problem.
- Everything passes, still spam: reputation or content is the issue, covered further down.
Reading headers is the first thing we do on any job involving business emails going to spam, because it turns guesswork into a specific failing check.
SPF: the record that lists who may send for your domain
SPF (Sender Policy Framework) is a DNS TXT record listing the servers allowed to send email for your domain. If mail comes from a server not on the list, SPF fails and spam filters grow suspicious.
A typical record for a business on Google Workspace that also sends through a newsletter service looks like v=spf1 include:_spf.google.com include:[your newsletter provider’s domain] ~all. Each include pulls in that provider’s list. The final ~all (softfail) or -all (fail) tells receivers what to do with everything else.
Two rules from the SPF standard, RFC 7208, catch many businesses. First, a domain must not have multiple SPF records; if two exist, evaluation returns an error. We regularly find one added by the web host and another by whoever set up Workspace. Second, SPF evaluation is limited to 10 DNS-querying terms (include, a, mx, ptr, exists and redirect); exceeding it produces a permerror. Businesses using email, a CRM, a helpdesk, an invoicing tool and a newsletter platform hit that limit quickly.
When SPF is the reason business emails are going to spam, our fix is one merged record, trimmed of services you no longer use, within the lookup limit. Where a tool sends from its own domain rather than yours, it may not need to be in your SPF at all. SPF alone is not enough, though: it breaks when mail is forwarded, which is why DKIM matters.
DKIM: signing your mail so it cannot be faked
DKIM (DomainKeys Identified Mail) adds a cryptographic signature to each message, which receivers verify using a public key published in your DNS. A valid signature proves the message came from a system authorised by your domain and was not altered in transit.
Most business mail providers support DKIM but do not always enable it automatically. In Google Workspace, Microsoft 365 and Zoho Mail, an administrator generates a key, publishes it as a TXT or CNAME record under a selector name, then turns signing on. Skipping the final switch is surprisingly common: the key sits in DNS, but outgoing mail is unsigned.
Each service that sends as your domain should sign with its own DKIM key: your mailbox provider, your newsletter tool, your transactional email service for the website, your CRM. Each uses a different selector, so several DKIM records can coexist without conflict, unlike SPF.
DKIM survives forwarding better than SPF, which is why DMARC can pass on a forwarded message when SPF fails. When we fix business emails going to spam, DKIM for every legitimate sender is usually the single change with the biggest effect.
DMARC: what policy should a business start with?
Start with p=none and a reporting address, read the reports for a few weeks, fix every legitimate sender, then move to p=quarantine and later p=reject. Jumping straight to reject can block your own invoices and form mail.
DMARC ties SPF and DKIM to the domain people actually see in the From field. A message passes DMARC if either SPF or DKIM passes and is aligned with that visible domain. The policy then tells receivers what to do with failures: nothing (none), send to spam (quarantine) or refuse (reject).
A starting record might be v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.in. The rua address receives aggregate reports from large mailbox providers listing every server that sent mail claiming to be you, and whether it passed. Those reports often reveal forgotten senders: an old billing tool, a website on a previous host, or a spammer impersonating your domain.
Google’s bulk sender FAQ lists p=none as the minimum DMARC policy for bulk senders. For businesses worried about impersonation, such as those sending invoices or payment requests, moving towards quarantine or reject after reports are clean gives much stronger protection. We summarise the reports in plain language so the decision is yours.
How shared hosting IP reputation sends business emails to spam
On shared hosting, hundreds of websites can send mail from the same server IP address. If one of them sends spam or is hacked, that IP’s reputation falls and receivers treat everyone’s mail from it with suspicion, including yours.
Shared servers explain many cases of business emails going to spam, and they affect two kinds of mail. Mailboxes created in cPanel on the hosting account send through the shared server, so ordinary replies to customers can suffer. And the website itself, especially WordPress, sends notifications, order confirmations and password resets through the same server using PHP’s mail function, often with no DKIM signature and an SPF record that does not match.
Signs that shared hosting is the cause: headers show your mail leaving from a hosting server name; a blacklist check lists the server IP; and the same email sent from a Gmail account reaches the inbox fine. You cannot fix another customer’s spam on that server, so the reliable remedy is to stop sending important mail through it.
For mailboxes, that usually means a dedicated business email provider such as Google Workspace, Microsoft 365 or Zoho Mail. For website mail, it means authenticated SMTP or a transactional email service, described in the next section. Hosting is still fine for the website itself; it just should not be your mail server. If the site also shows browser warnings, our page on a website showing not secure covers certificate fixes.
Contact form emails go to spam because the website sends them from its hosting server while claiming to be from your domain, or even from the visitor’s own address. Receivers see an unauthenticated message pretending to be someone else, which is exactly what spam looks like.
The worst pattern is a form that puts the visitor’s email in the From field. If a customer with a Gmail address fills your form, your server sends a message “from” their Gmail address, which fails every check Gmail runs. Many older themes and form plugins do this by default.
The fix has three parts. First, send form notifications from an address on your own domain, such as website@yourdomain.in, and put the visitor’s address in the Reply-To header so replying still works. Second, route the mail through authenticated SMTP: either your business mailbox’s SMTP server with an app password, or a transactional email service that signs with DKIM for your domain. On WordPress, an SMTP plugin replaces the default PHP mail transport. Third, add the chosen service to SPF and publish its DKIM key.
We also recommend storing form submissions in the website database or a Google Sheet, so an enquiry is never lost even if an email fails. That backup is part of how we build forms, and it links to lead counting on our GA4 setup service page.
How to check if your domain or IP is blacklisted
If business emails keep going to spam after authentication passes, look up your sending IP addresses and your domain on public blocklist checkers, which query many lists at once. A listing on a major list, such as those run by Spamhaus, can send mail to spam or get it rejected outright.
First find the real sending IP from the headers of a message you sent; it is often not your website’s IP. Then check it and your domain. Results need interpretation: some minor lists are rarely used by major providers, while a listing on a widely used list is serious and urgent.
Before requesting delisting, fix the cause. Common causes are a hacked website sending spam through a form or a vulnerable plugin, a compromised mailbox password, a newsletter sent to a purchased or very old list, or a shared hosting neighbour you cannot control. Most blocklists provide a removal request process, and some remove listings automatically once spam stops. Requesting removal while the problem continues usually leads to relisting.
If a hacked WordPress site is the source, cleaning it comes first; our WordPress critical error fix and maintenance pages describe that work. Shared hosting IP listings are usually resolved by moving mail off the shared server rather than waiting for the host.
Gmail and Yahoo bulk sender rules that affect business emails
Since February 2024, Gmail requires every sender to authenticate with SPF or DKIM, and bulk senders to use SPF, DKIM and DMARC with alignment, one-click unsubscribe and a low spam complaint rate. Yahoo publishes matching requirements.
According to Google’s sender guidelines, all senders must set up SPF or DKIM, have valid forward and reverse DNS for sending IPs, use TLS, and keep spam rates reported in Postmaster Tools below 0.3%. Google’s FAQ defines a bulk sender as one sending close to 5,000 messages or more to personal Gmail accounts within 24 hours, counts messages from the same primary domain together, and says bulk sender status is permanent once assigned.
Bulk senders must also publish DMARC (minimum p=none), align the From domain with SPF or DKIM, and support one-click unsubscribe on marketing and subscribed messages. Yahoo’s sender best practices add that unsubscribe requests should be honoured within 2 days.
- A small business emailing a few customers a day is not a bulk sender, but the all-sender rules still apply.
- A business sending festival offers to a large customer list in one go can cross the bulk threshold, and the status then stays.
- Newsletter tools handle unsubscribe headers, but only if you send through them, not by BCC from your mailbox.
- Mail to Google Workspace addresses is outside these specific consumer Gmail rules, according to Google’s FAQ.
For WhatsApp broadcasts, which have their own rules, see WhatsApp bulk message API.
Content and sending habits that push business emails into spam
Even with perfect authentication, mail lands in spam if recipients do not want it, if it looks like spam, or if a new domain suddenly sends a lot. Reputation is built by consistent, wanted mail.
Habits that keep business emails going to spam, which we ask clients to change:
- Sending bulk offers from a personal mailbox with everyone in BCC. Use a proper newsletter tool with unsubscribe handling, ideally from a subdomain such as news.yourdomain.in so marketing reputation does not affect everyday mail.
- Buying or scraping lists. These produce complaints, bounces and spam traps that damage reputation quickly.
- Link shorteners and many tracked links. Shortened URLs shared by spammers can drag your message down.
- Image-only emails or a single large attachment with little text.
- Misleading subjects such as fake “Re:” prefixes or all-caps urgency.
- Sudden volume from a new domain. Warm up gradually over several weeks.
- Ignoring bounces. Keep removing addresses that hard-bounce.
Asking customers to add your address to contacts and to mark mistaken spam as “not spam” helps too, because receivers learn from those actions. For automated follow-ups built on these principles, see email automation services.
Business emails going to spam in Outlook and Microsoft 365
Outlook and Microsoft 365 apply the same authentication principles, SPF, DKIM and DMARC, but they also weigh sender reputation and recipient behaviour heavily, so mail can reach the inbox in Gmail and still land in Junk in Outlook.
When business emails are going to spam only for Outlook recipients, we check a few extra points. Is DKIM enabled for your domain in Microsoft 365 if you use it, rather than relying on the default onmicrosoft.com signature? Does the sending IP have a clean reputation, particularly if mail leaves from a small hosting server? Is the recipient organisation using its own filtering rules that quarantine unfamiliar senders?
For corporate recipients, their IT team’s filters may be stricter than consumer Outlook. If an important client keeps missing your mail, asking their IT team to check quarantine logs or allow your domain is sometimes the fastest fix, once your authentication is proven correct.
Microsoft’s own documentation and sender support pages are the right reference for its requirements, and we follow them when configuring Microsoft 365 tenants. We avoid quoting thresholds here that may change, and verify current rules at the time of each job.
How much does it cost to fix business emails going to spam?
The cost depends on how many systems send mail as your domain and how tangled the current setup is. A single missing DKIM key is a small job; untangling hosting mail, website mail, a newsletter tool and a CRM is larger.
What goes into an itemised quote for business emails going to spam:
- Number of services sending as your domain (mailboxes, website, newsletter, CRM, billing, helpdesk).
- Whether SPF must be consolidated to fit the 10-lookup limit.
- DKIM setup for each sender and DMARC rollout with report reading.
- Moving website mail to authenticated SMTP, including plugin or code changes.
- Blacklist investigation, hacked-site clean-up and delisting requests if needed.
- Migrating mailboxes off hosting to a dedicated provider, if you choose to.
- Ongoing monitoring after DNS or hosting changes.
Ongoing checks can be part of a care plan from ₹8,000/mo (US$120/mo). If the website itself needs rebuilding, sites start at ₹10,000, with forms that store every enquiry and send through SMTP from day one. See website maintenance charges for how upkeep is usually priced.
Step by step: how we fix business emails going to spam
We diagnose from headers and DNS first, list every system that sends as your domain, fix records and sending routes in a safe order, then verify with test messages to Gmail, Outlook and Yahoo addresses.
The order matters because a wrong DNS change can stop mail entirely. We never change MX records without a plan, and we lower DNS TTL values before planned changes where possible, so a mistake can be reversed quickly. SPF gets merged and validated before publishing. DKIM is published first and switched on only once DNS shows the key. DMARC begins at p=none.
Website mail comes next: SMTP configured, the From address set to your domain with visitors in Reply-To, every form tested, and submissions stored as a backup. Blacklists are checked, causes fixed, and removal requested where appropriate.
Finally we send test messages to several mailbox providers, read the resulting headers to confirm SPF, DKIM and DMARC all pass, and hand over a short note of every record changed, with its old and new values. Another of us usually handles the DNS and diagnosis; one of us handles website and SMTP changes.
Access, ownership and security while fixing email
You keep ownership of your domain, DNS and mail accounts throughout. We need editing access to DNS, admin access to the mail provider and website admin, ideally through separate user accounts you can remove afterwards.
Where your DNS host or email provider supports delegated users, we use them instead of your main login. Where it does not, we recommend changing the password once the work is done. We never move your domain to an account of ours.
Email fixes are also a chance to tighten security. We suggest two-step verification for mailbox admins, removing former staff accounts, checking forwarding rules that attackers sometimes add to hacked mailboxes, and using app passwords for SMTP rather than your main password. A DMARC policy of quarantine or reject, once safe, makes it much harder for fraudsters to send fake invoices using your domain.
We do not give legal advice on email marketing consent. If you send promotional mail, confirm your consent practices with your own advisers, particularly under India’s Digital Personal Data Protection framework and any overseas rules that apply to your recipients.
Worked example: a CA practice whose invoices land in spam
A hypothetical case shows how the fix unfolds. Say a chartered accountant practice in Kanpur uses Google Workspace for staff email, a WordPress site on shared hosting for enquiries, and an accounting tool that emails invoices as billing@ their domain. Clients complain that invoices and form replies land in spam.
Header checks on business emails going to spam from this practice would likely show three different stories. Staff email passes SPF but has no DKIM signature, because signing was never switched on. Form notifications leave from the hosting server via PHP mail, fail SPF and claim to be from the visitor. Invoices from the accounting tool pass DKIM for the tool’s own domain, not the practice’s, so DMARC alignment fails. DNS would show two SPF records, one from the host and one from Workspace setup.
The fix sequence: merge SPF into one record covering Workspace and the accounting tool; enable DKIM in Workspace; set up custom DKIM in the accounting tool; publish DMARC at p=none with reports; install an SMTP plugin on WordPress sending from website@ through Workspace with an app password, putting the visitor in Reply-To; and store form entries in the database.
After a few weeks of clean reports, the practice could move DMARC to quarantine, protecting clients from fake invoices sent in its name. That combination of better delivery and impersonation protection is typical of a well-handled case of business emails going to spam.
Business emails going to spam: a checklist to run today
If your business emails are going to spam, work through these lines with your DNS panel and a spam-foldered message open. Any failed line is a likely cause.
- Exactly one SPF record exists, and it lists every service that sends as your domain.
- SPF stays within 10 DNS lookups.
- DKIM is published and switched on for your mailbox provider and each sending tool.
- A DMARC record exists, at least p=none, with a report address you read.
- Headers of a test message show SPF, DKIM and DMARC all passing.
- Website forms send from your domain through authenticated SMTP, with the visitor in Reply-To.
- Form entries are also stored on the site or in a sheet.
- Sending IPs and domain are not on major blocklists.
- Bulk mail goes through a newsletter tool with one-click unsubscribe.
- Marketing mail uses a subdomain, separate from everyday mail.
If several lines fail, send us a screenshot of your DNS records and the headers of one spam-foldered message, and we will tell you where to start. Lost form mail often means lost leads; our page on a website not generating leads looks at the wider picture.