Email DNS fix
- SPF, DKIM and DMARC for one domain
- Reverse DNS and blacklist check
- Test messages to Gmail and Outlook
- A written list of every record
SPF, DKIM, DMARC, reverse DNS, relay and blacklist checks set up properly on your own server or provider, so order emails and enquiries arrive. Gmail, Yahoo and Microsoft expect it. From €290.
Authentication-Results: mx.receiver.example;
spf=pass smtp.mailfrom=example.fi;
dkim=pass header.d=example.fi header.s=default;
dmarc=pass (p=QUARANTINE) header.from=example.fiPick a situation or set each gate yourself. The records below change with your choices, and the DMARC policy is shared between both parts.
Authentication gets you through the door. Reputation keeps you there. Each item below exists because of a specific way mail goes wrong; set your volume to see what Gmail treats as required.
Why it exists: Receivers check the sending IP against SPF and the signature against DKIM before they look at the content. Set up both: DKIM survives forwarding, SPF does not.
Why it exists: It tells receivers what to do with mail that fails, and the reports show every service sending as your domain, including the ones nobody remembered.
Why it exists: Mail from an IP whose PTR record does not resolve back to the same host name is refused or filtered by many receivers.
$ dig +short -x 192.0.2.25 mail.example.fi. $ dig +short A mail.example.fi 192.0.2.25
Why it exists: Receivers flag mail delivered without encryption. Mail servers do this automatically once a valid certificate is installed.
Why it exists: People can leave with the mail app’s own button instead of pressing Report spam. Gmail and Yahoo require it for bulk marketing mail and expect requests honoured within two days.
List-Unsubscribe: <https://example.fi/unsubscribe/7f3a9c>, <mailto:[email protected]?subject=unsubscribe> List-Unsubscribe-Post: List-Unsubscribe=One-Click
Why it exists: Above 0.3% spam reports in Google Postmaster Tools, Gmail filters or refuses your mail. Aim for under 0.1%, and watch Microsoft SNDS and the Yahoo feedback loop too.
Why it exists: Confirmed opt-in, hard bounces removed at once and inactive contacts retired. Old addresses become spam traps and bounces, and both damage the reputation of the sending domain.
Why it exists: Send campaigns from a subdomain such as news.example.fi or a separate service, so a bad campaign cannot push order confirmations and password resets into spam.
Based on the sender guidelines Google and Yahoo published in 2024 and the rules Microsoft added for Outlook.com in 2025. They change; check each provider's current pages before a large send.
Jumping straight to reject blocks your own invoices and newsletters if one sender was missed. The safe route takes a few weeks and is driven by the reports.
A real message sent to Gmail and Outlook, opened with "Show original", so the Authentication-Results line tells us what actually fails.
Every sending service in SPF, DKIM keys on, a PTR record matching the mail host name, and the server IP checked against the main blacklists.
Two to four weeks of aggregate reports show every server that sends as your domain, including the ones nobody remembered.
Legitimate services get aligned SPF or DKIM; anything unknown is investigated before the policy tightens.
Quarantine first, then reject once the reports are clean, so spoofed mail stops and your own still lands.
Order emails going to spam? Send me one with its full headers.
Fix my email deliveryGood DNS is necessary, not magic.
Fixed prices in euros, excluding VAT 25.5%. You keep every DNS account, mailbox and password; I document every record I change.
If your records were already right and the problem lies elsewhere, you get that in writing and pay only for the check. owner to confirm
Usually because receivers cannot verify it: SPF missing a sending service, no DKIM signature, no DMARC, or a From domain that does not align. Next come reputation problems: a blacklisted server IP, missing reverse DNS, high complaint rates or a neglected list. I read the headers of a real message first, so the fix targets the actual cause.
DMARC is a DNS record at _dmarc.yourdomain that tells receiving servers what to do when a message using your domain fails SPF and DKIM alignment: deliver it anyway, put it in spam or reject it. It also asks them to send you daily reports, so you see every service that sends as you.
Yes: on cPanel/WHM with Exim and Dovecot, or a standalone Postfix server, with SPF, DKIM, DMARC, reverse DNS, TLS and spam filtering. For most small teams I recommend Microsoft 365 or Google Workspace for the mailboxes instead, and set up the DNS, the migration and your website or store sending around them.
Sending campaigns? Authentication also matters for paid ads landing flows that end in a confirmation email.