Make your email land in the inbox, not in spam

SPF, DKIM, DMARC, reverse DNS, relay and blacklist checks set up properly on your own server or provider, so order emails and enquiries arrive. Gmail, Yahoo and Microsoft expect it. From €290.

from€290excl. VAT 25.5%, one domain. proposed
inbox journey: [email protected] to a customereducational, does not query DNS
InboxDMARC passes: SPF and DKIM both pass and align. Content and sender reputation decide the rest.
what the receiving server writes into the messagesample header
Authentication-Results: mx.receiver.example;
       spf=pass smtp.mailfrom=example.fi;
       dkim=pass header.d=example.fi header.s=default;
       dmarc=pass (p=QUARANTINE) header.from=example.fi
Real mail still in spam with all three passing? Then it is reputation, and that is checkable too.Check my reputation and headers
try a situation
Gate 1: SPF
Is the sending IP listed in the SPF record of the envelope domain?
Gate 2: DKIM
Does the signature verify against the public key in DNS?
Gate 3: DMARC
Passes when SPF or DKIM passes for the same domain as the visible From address. The policy says what to do when it fails.

The records behind the gates

example.fi, generated here
who sends mail as example.fi?
SPF for everyone else
DMARC policy

$ dig +short TXT example.fi
"v=spf1 ip4:192.0.2.25 ip4:198.51.100.10 include:spf.protection.outlook.com -all"
# cPanel signs with the selector "default"; key shortened for display, the server generates the full 2048-bit key
$ dig +short TXT default._domainkey.example.fi
"v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA"
# Microsoft 365 signs with its own keys: CNAME records selector1._domainkey and selector2._domainkey, values from the Microsoft 365 admin centre
$ dig +short TXT _dmarc.example.fi
"v=DMARC1; p=quarantine; rua=mailto:[email protected]; adkim=r; aspf=r"
$ dig +short -x 192.0.2.25
mail.example.fi.
SPF DNS lookups at the top level: 1 of 10 (nested includes count too; I check the whole tree).-all tells receivers that anything not listed is not you.

Pick a situation or set each gate yourself. The records below change with your choices, and the DMARC policy is shared between both parts.

Before sending newsletters

Authentication gets you through the door. Reputation keeps you there. Each item below exists because of a specific way mail goes wrong; set your volume to see what Gmail treats as required.

4 required, 4 strongly recommended
  1. SPF and DKIM on every sending service

    Required: SPF or DKIM

    Why it exists: Receivers check the sending IP against SPF and the signature against DKIM before they look at the content. Set up both: DKIM survives forwarding, SPF does not.

  2. DMARC published, with the From domain aligned

    Strongly recommended

    Why it exists: It tells receivers what to do with mail that fails, and the reports show every service sending as your domain, including the ones nobody remembered.

  3. Reverse DNS that matches

    Required

    Why it exists: Mail from an IP whose PTR record does not resolve back to the same host name is refused or filtered by many receivers.

    $ dig +short -x 192.0.2.25
    mail.example.fi.
    $ dig +short A mail.example.fi
    192.0.2.25
  4. TLS on every connection

    Required

    Why it exists: Receivers flag mail delivered without encryption. Mail servers do this automatically once a valid certificate is installed.

  5. One-click unsubscribe headers (RFC 8058)

    Strongly recommended

    Why it exists: People can leave with the mail app’s own button instead of pressing Report spam. Gmail and Yahoo require it for bulk marketing mail and expect requests honoured within two days.

    List-Unsubscribe: <https://example.fi/unsubscribe/7f3a9c>, <mailto:[email protected]?subject=unsubscribe>
    List-Unsubscribe-Post: List-Unsubscribe=One-Click
  6. Complaint rate watched

    Required: under 0.3%

    Why it exists: Above 0.3% spam reports in Google Postmaster Tools, Gmail filters or refuses your mail. Aim for under 0.1%, and watch Microsoft SNDS and the Yahoo feedback loop too.

  7. List hygiene

    Strongly recommended

    Why it exists: Confirmed opt-in, hard bounces removed at once and inactive contacts retired. Old addresses become spam traps and bounces, and both damage the reputation of the sending domain.

  8. Order email and newsletters kept apart

    Strongly recommended

    Why it exists: Send campaigns from a subdomain such as news.example.fi or a separate service, so a bad campaign cannot push order confirmations and password resets into spam.

Based on the sender guidelines Google and Yahoo published in 2024 and the rules Microsoft added for Outlook.com in 2025. They change; check each provider's current pages before a large send.

From p=none to p=reject without losing mail

Jumping straight to reject blocks your own invoices and newsletters if one sender was missed. The safe route takes a few weeks and is driven by the reports.

  1. 1

    Read the headers

    A real message sent to Gmail and Outlook, opened with "Show original", so the Authentication-Results line tells us what actually fails.

  2. 2

    Fix SPF, DKIM and reverse DNS

    Every sending service in SPF, DKIM keys on, a PTR record matching the mail host name, and the server IP checked against the main blacklists.

  3. 3

    Monitor p=none

    Two to four weeks of aggregate reports show every server that sends as your domain, including the ones nobody remembered.

  4. 4

    Authorise or stop each sender

    Legitimate services get aligned SPF or DKIM; anything unknown is investigated before the policy tightens.

  5. 5

    Tighten p=quarantine p=reject

    Quarantine first, then reject once the reports are clean, so spoofed mail stops and your own still lands.

Order emails going to spam? Send me one with its full headers.

Fix my email delivery

When I would not recommend this

Good DNS is necessary, not magic.

  • 01You want your own mail server for a handful of mailboxes. Microsoft 365 or Google Workspace costs less to keep running; I set up the DNS and move the mail instead.
  • 02The list was bought or scraped. No record fixes complaints from people who never asked for the mail, and I will not help send it.
  • 03One message went to spam once and your provider already publishes SPF, DKIM and DMARC. Forward me the headers; that is often a short email answer, not a package.

Email packages

Fixed prices in euros, excluding VAT 25.5%. You keep every DNS account, mailbox and password; I document every record I change.

Recommended

Email DNS fix

€290from proposed
  • SPF, DKIM and DMARC for one domain
  • Reverse DNS and blacklist check
  • Test messages to Gmail and Outlook
  • A written list of every record
Fix my email delivery

DMARC to enforcement

€490from owner to confirm
  • Everything in the DNS fix
  • Four to six weeks of reports read for you
  • Every legitimate sender aligned
  • Policy moved to quarantine, then reject
Ask about DMARC enforcement

Mail server set-up

€690from owner to confirm
  • cPanel/WHM with Exim and Dovecot, or Postfix
  • TLS certificates and spam filtering
  • Outgoing rate limits per account
  • All DNS records, tested end to end
Ask about a mail server

If your records were already right and the problem lies elsewhere, you get that in writing and pay only for the check. owner to confirm

Questions about email delivery

Why does my email go to spam?

Usually because receivers cannot verify it: SPF missing a sending service, no DKIM signature, no DMARC, or a From domain that does not align. Next come reputation problems: a blacklisted server IP, missing reverse DNS, high complaint rates or a neglected list. I read the headers of a real message first, so the fix targets the actual cause.

What is DMARC?

DMARC is a DNS record at _dmarc.yourdomain that tells receiving servers what to do when a message using your domain fails SPF and DKIM alignment: deliver it anyway, put it in spam or reject it. It also asks them to send you daily reports, so you see every service that sends as you.

Can you set up a mail server for my company?

Yes: on cPanel/WHM with Exim and Dovecot, or a standalone Postfix server, with SPF, DKIM, DMARC, reverse DNS, TLS and spam filtering. For most small teams I recommend Microsoft 365 or Google Workspace for the mailboxes instead, and set up the DNS, the migration and your website or store sending around them.

Made in Tampere. The path ends here.61.4978° N, 23.7610° E

Tell me what you need. I reply within one working day.

About these landmarks
  • Näsinneula tower, Tampere, 1971. Opened in 1971, with an observation deck and a revolving restaurant at the top.
  • Finlayson mill, Tampere, 1820. Cotton mill founded in 1820 by James Finlayson; the red-brick mill and chimney still stand by the Tammerkoski rapids.
  • Tampere Cathedral, 1907. National Romantic granite church by Lars Sonck, with frescoes by Hugo Simberg.
  • Helsinki Cathedral, 1852. White neoclassical church with green domes above the Senate Square steps, designed by Carl Ludvig Engel.
  • Parliament House, Helsinki, 1931. Eduskuntatalo, built of red granite behind a front row of tall columns.
  • Temppeliaukio Church, Helsinki, 1969. The Rock Church: cut into solid bedrock and roofed with a copper dome.
  • Suomenlinna sea fortress, Helsinki, 1748. Island fortress begun in 1748 at the entrance to Helsinki harbour; a UNESCO World Heritage Site.
  • Olavinlinna castle, Savonlinna, 1475. Medieval castle with three round towers, built on a rock island between two lakes.
  • Sauna by a frozen lake, UNESCO 2020. Finnish sauna culture is on UNESCO’s list of the intangible cultural heritage of humanity.
  • Lapland: spruce, reindeer and a fell, North. The northern end of the journey: spruce forest, a reindeer and a snow-capped fell.
© 2026 Pikselipolku, Tampere, FinlandBusiness ID [Y-tunnus]Built to WCAG 2.2 AABack to top