You send an important quote. It never arrives — or it lands in the customer’s spam folder, unread. For a small business, email landing in spam is not a nuisance; it is lost revenue and lost trust. The good news is that the causes are well understood and almost always fixable, and since 2024 the major mailbox providers have made the fixes effectively mandatory anyway.
This is a plain-language explanation of why business email goes to spam, and how to fix it for good. It pairs with the technical detail in our DNS and email security whitepaper.
The real reason: mailbox providers can’t prove it’s really you
Spam filters are not judging your writing. They are asking a simpler question: can we prove this email genuinely came from the domain it claims to come from? If the answer is no, the safe choice for Gmail or Outlook is to treat it as suspicious — because spoofing a business’s domain is exactly what scammers do.
The way you prove it is three small DNS records: SPF, DKIM, and DMARC. Most businesses that struggle with deliverability are missing one or more of them, or have them configured incorrectly.
The three records that fix it
- SPF lists which servers are allowed to send email for your domain. It answers “is this sender authorised?”
- DKIM adds a tamper-proof digital signature to your mail. It answers “is this genuinely from the domain, and unaltered?”
- DMARC ties them together, tells receivers what to do with mail that fails, and — importantly — sends you reports showing who is sending email using your domain, including impostors.
With all three set correctly, mailbox providers can verify you, and your legitimate mail stops being treated as a risk.
Since 2024, this is non-negotiable
In February 2024, Google and Yahoo — which between them run most of the inboxes your customers use — began requiring senders to authenticate. Bulk senders now need SPF, DKIM, and a published DMARC policy, with the “from” address properly aligned, or their mail is filtered or rejected. Even if you are not a bulk sender, this is the new baseline every mailbox provider increasingly expects. Authentication is no longer optional hygiene; it is the price of reliable delivery.
The other common culprits
- A shared or low-reputation sending service — if your mail goes out through a server other senders have abused, you inherit their bad reputation.
- Sending bulk mail from your normal mailbox — newsletters and campaigns should go through a proper email platform, not your everyday account.
- No easy unsubscribe — marketing mail now needs a working one-click unsubscribe, and high complaint rates quickly hurt deliverability.
- Spammy content or broken formatting — still a factor, but a much smaller one than authentication.
The risk that goes beyond the spam folder
Deliverability is the visible problem. The hidden one is worse. If your domain is not authenticated, anyone can send email that appears to come from you — to your customers, your suppliers, even your own staff. Business email compromise, where a scammer impersonates a trusted sender to redirect a payment or harvest credentials, is one of the most common and costly attacks on small businesses, and South Africa is a heavily targeted market. The same SPF, DKIM, and DMARC records that keep your mail out of spam also make your domain far harder to impersonate. Fixing deliverability and closing a fraud vector are, conveniently, the same job — which is also why email authentication counts as a reasonable security safeguard under POPIA.
How to fix it properly
Set SPF and DKIM correctly for every system that sends on your behalf — your email provider, your CRM, your invoicing tool. Then publish DMARC and start in monitoring mode, watch the reports to confirm your legitimate senders pass, and tighten the policy to enforcement once they do. Done in that order, you reach full protection without ever losing a real email. Rushing straight to enforcement is how businesses accidentally block their own invoices — which is exactly why this is monitored work, not a one-time paste.
The practical next step
If your email sometimes lands in spam, or you have never heard of SPF, DKIM, and DMARC, your domain is almost certainly under-protected — and possibly being spoofed without your knowledge. A short DNS and email review through DNS Shield shows exactly what is configured, what is exposed, and what to fix first.
Published 16 June 2026. Last updated 16 June 2026.