Stop your email going to spam: SPF, DKIM and DMARC

If your messages land in junk folders, or Gmail shows a "via" line next to your address, the usual cause is missing email authentication. Three DNS records tell receiving mail servers that your mail is genuinely yours.

We set all three up for you. When your domain is with us, SPF, DKIM and DMARC are configured as part of provisioning your mail. There is nothing for you to add and nothing to renew.

This article is here so you know what they are, how to confirm they are working, and the two situations where you do need to tell us something.

What the three records do

  • SPF lists the servers allowed to send mail using your domain. A receiving server checks the sender against that list.
  • DKIM adds a cryptographic signature to every message you send, proving it was not altered in transit. This is the one that survives forwarding, which SPF does not.
  • DMARC ties the two together and tells receiving servers what to do when a check fails.

Without them, modern providers treat your mail as suspicious regardless of what it says. With them, you are a known sender.

Checking it is working

Send a message to a Gmail address. Open it there, choose Show original, and look at the top of the page:

SPF: PASS   DKIM: PASS   DMARC: PASS

All three should say PASS. If any says FAIL, NEUTRAL or NONE, open a ticket from the client area with that page and we will look at it — do not start editing DNS records yourself, because a partly-correct SPF record is worse than none at all.

When you do need to tell us

Two situations, and both are common enough to be worth checking before you assume something is broken.

1. You send mail through another service

If a newsletter tool, CRM, invoicing system or website contact form sends mail as your domain, that service also has to be authorised — otherwise its messages fail SPF and go to spam even though your normal mail is fine.

Tell us which service you are using and we will add it. Please do not add a second SPF record yourself. A domain may only have one, and adding another makes SPF fail completely for all of your mail, including the messages that were working perfectly beforehand. This is the single most common way a working setup gets broken.

2. Your DNS is hosted somewhere else

We can only manage records on domains whose DNS we control. If your domain points at another provider's nameservers — your registrar, Cloudflare, a web designer's account — we cannot add anything, and none of the above is in place.

Open a ticket and we will send you the exact records to add there, or help you move DNS to us.

Still going to spam with all three passing

Authentication proves the mail is genuinely yours. It does not prove it is wanted, and the two are different problems.

If all three checks pass and messages still land in junk, the likely causes are the content itself, a sending reputation damaged by earlier spam from the domain, or the sending address appearing on a blocklist.

Open a ticket with the full message headers — the Show original output above — and we can check the sending reputation for you.

  • 0 משתמשים שמצאו מאמר זה מועיל
?האם התשובה שקיבלתם הייתה מועילה

מאמרים קשורים

Can individual email users see their email storage usage percentage?

DETAILSYes, individual email users can see their email storage usage percentage within...

Can individual email users update their passwords?

DETAILSYes, individual email users can update their passwords within the webmail client.Log into...

General OISSite.com Mail Server Information

SUMMARYThis document contains the general information for accessing the OISSite.com mail server...

How does the autoresponder work?

The autoresponder is a unique email address that has two functions.1. When you receive an...

SPAM Blocking FAQs

What incoming emails do you block?We block emails from known SPAM sources and open relay mail...