Why are my emails going to spam?

Answer one question about what you are seeing and go straight to the specific fix.

Free. No sign-up. Grades SPF, DKIM, DMARC, alignment, MX, BIMI, MTA-STS and TLS-RPT.

Most answers to this question are the same list of ten things, and the list is not wrong — it is just not about *your* domain. Spam placement has one of a small number of concrete causes, and your own mail already tells you which one. You do not have to work through the list.

So this page is a decision tree rather than a guide. Run the check above to see what your domain publishes, open one message that landed in spam, and match the line you find to a branch below. Each branch ends on a page about that one failure, with the record to change.

If the check comes back clean and every branch below misses, that is useful information too: the cause is not authentication, and the last section says what to look at instead.

Step 1: read one message that went to spam

  1. 1Find a message that actually went to spam. Use a real one, from the mailbox that filtered it. A message you send to yourself inside the same organisation never leaves the building and tells you nothing.
  2. 2Open the original headers. Gmail: the ⋮ menu on the open message → Show original. Outlook on the web: ⋯ → View → View message source. Apple Mail: View → Message → All Headers.
  3. 3Find the Authentication-Results line. It is near the top and reads like `spf=pass … dkim=pass … dmarc=pass header.from=example.com`. The three verdicts, and the domain each one authenticated, are everything the branches below need.
  4. 4Compare the domains, not just the verdicts. A `pass` on a domain that is not yours is a DMARC failure. Check that the domain after `spf=pass` and the `header.d=` on the DKIM result both match the domain in your visible From address. That comparison is what alignment means.

Step 2: match what you found

Find the line below that matches your headers. Work top to bottom and take the first one that applies — they are ordered by how often each cause is the real one.

  • dmarc=fail, but spf=pass and dkim=pass

    Both checks passed for someone else’s domain. This is an alignment failure, and it is the single most common cause of a sending tool’s mail being filtered.

    DMARC fail: which of the three failure modes applies →

  • dmarc=none, or "no DMARC record found"

    You have no policy published, so receivers have no instruction and you get no reports. Gmail and Yahoo require bulk senders to publish one.

    No DMARC record found: what to publish →

  • spf=permerror, or "too many DNS lookups"

    Your SPF record was abandoned mid-evaluation, so nothing in it counted. DMARC treats that as an SPF failure.

    SPF PermError: too many DNS lookups →

  • spf=softfail or spf=fail

    The server that sent the message is not in your SPF record. Either it is a sender you forgot, or the message was forwarded.

    SPF softfail vs hardfail: ~all or -all →

  • dkim=none, or dkim=fail (no key for signature)

    Receivers could not fetch your public key — or your provider is not signing at all. Publishing the key and enabling signing are two separate steps.

    dkim=fail (no key for signature) →

  • dkim=fail (body hash did not verify)

    The key was found and the signature parsed; something edited the message after it was signed. Usually a footer, a disclaimer appliance or a mailing list.

    dkim=fail (body hash did not verify) →

  • Everything passes, and only mail from your website is filtered

    Your domain is fine and the site is the unauthenticated sender. WordPress sends through PHP `mail()` by default, which nothing authorises.

    WordPress emails going to spam →

  • There are no headers to read, because nothing arrives at all

    Not a filtering problem. Check that the domain can receive mail — a broken MX also means you never see the bounce that would have told you why.

    MX lookup: check your mail servers →

  • Everything passes and the message still looks wrong on arrival

    Send one through and read what the receiver actually got: the headers, the From, the unsubscribe headers and the links, over the raw bytes.

    Inbox test: send a real message →

Step 3: fix it where the mail is sent from

Every branch above ends at a record, and the record belongs to whatever is doing the sending. Each sender needs its own authentication, so a domain with four tools has four setups to get right — not one.

  • Google Workspace — Your business mail, from Gmail or the Workspace web client
  • Microsoft 365 — Your business mail, from Outlook or Exchange Online
  • SendGrid — Transactional mail — receipts, password resets, API-sent notifications
  • Mailchimp — Newsletters and campaigns
  • Klaviyo — Ecommerce campaigns and flows
  • WordPress — Your website — contact forms, order confirmations, password resets

If authentication is already clean

Then the cause is not something a DNS record fixes, and MailVakt cannot fix it for you. These are the remaining reasons a fully authenticated message still gets filtered.

List quality and complaint rate
Bought, scraped or stale lists generate spam complaints and hit dead addresses, and both are weighted heavily. Perfect authentication does not survive a bad list. Remove addresses that have not engaged, and never add one that did not ask.
Missing one-click unsubscribe
Since 2024 Gmail and Yahoo require bulk senders to support one-click unsubscribe via the `List-Unsubscribe` and `List-Unsubscribe-Post` headers. Good sending tools add these; a hand-rolled script does not.
A new domain or a sudden volume jump
A domain with no sending history has no reputation, and going from nothing to thousands of messages in a day looks exactly like a compromised account. Ramp up gradually.
Content and links
Link shorteners, a single image with no text, a tracking domain that does not match the sender, and attachments all push a message toward the spam folder independently of your DNS.
The recipient filtered you
An individual mailbox rule, a prior "mark as spam", or an organisation-level block will filter a message that every public check says is perfect. Ask the recipient to look in their own rules and allow-list.

Questions

Why are my emails going to spam all of a sudden?
Something changed on one of three axes: your DNS (a record edited or expired), your sending path (a new tool, a provider that rotated a DKIM selector), or your volume and complaint rate. Run the check above first — a DNS cause is the fastest to confirm and the fastest to fix.
How do I stop my emails going to spam?
In this order: get an aligned DKIM signature on every tool that sends as your domain, get SPF correct and under the 10-lookup limit, publish DMARC and read the reports, then move the policy to enforcement. After that it is list hygiene and content, not configuration.
My emails go to spam even though SPF passes. Why?
Because SPF passing is not the same as SPF aligning. If your sending tool uses its own envelope sender, SPF passes for the tool's domain, and DMARC compares against your visible From domain instead. Look at the domain next to `spf=pass`, not just the verdict.
Is this a DNS problem or a content problem?
The headers tell you. Any `fail`, `none` or `permerror` on the SPF, DKIM or DMARC line is a DNS or sending-path problem and is fixable today. All three passing and aligned means the cause is reputation, list quality or content — the last section above.
How long does it take to come back out of spam?
The DNS change itself takes effect within the TTL, usually under an hour. Reputation recovers more slowly, over days to weeks of clean sending, because receivers are reacting to a history rather than to a record.
Do I need a paid tool to fix this?
No. The checks on this site are free and need no account. An account only collects DMARC aggregate reports for a domain, and you can point `rua` at any mailbox you control instead.

Fix this from ChatGPT or Claude

MailVakt is an MCP server, so your assistant can run this check itself, read the findings and walk you through the DNS edit. Ask it:

“My emails from example.com are going to spam. Check the domain, then tell me in priority order which authentication problem to fix first and why.”
  • Claude: Settings → Connectors → Add custom connector, then paste https://mcp.mailvakt.com/mcp.
  • Cursor and other MCP clients: add the same address as an MCP server. Setup details.

Checks are free and need no account. Sign in only to collect DMARC reports for a domain.