Teaser only. This is not the full article. Complete guide with Authentication-Results and alignment fixes: SPF Passes but Mail Lands in Spam
MXToolbox shows SPF pass. Gmail Postmaster shows spam anyway. The team keeps editing TXT records that were never the problem.
SPF pass only means the sending IP is authorized for the envelope domain. Inbox placement in 2026 still depends on DKIM, DMARC alignment, complaint rates, and engagement. We've seen teams chase SPF includes for weeks while DMARC failed on every campaign.
In Gmail, open Show original and read Authentication-Results before changing DNS again.
In the full post on zerohook.org:
- SPF vs. DKIM vs. DMARC responsibilities
- Alignment failures when ESPs sign their own domain
- Bulk sender complaint rate thresholds
- List hygiene signals beyond DNS
Read the full guide: SPF Passes but Mail Lands in Spam
Top comments (1)
This trips up a lot of people. SPF authenticates the envelope
MAIL FROM(return-path), but DMARC checks whether that domain aligns with the headerFrom:domain. If your ESP sends via their own return-path, SPF passes for their domain, not yours, so DMARC still fails. DKIM alignment is usually the more reliable path to a DMARC pass when third-party senders are involved.