Why your order confirmations land in spam, and the three DNS records that fix most of it.
Your checkout works. The customer pays. Then the order confirmation lands in their spam folder, or never arrives at all. Since 2024, Gmail and Yahoo have required senders to authenticate their mail properly, and Microsoft has followed. If your app sends email (receipts, password resets, booking reminders), authentication is no longer optional.
This guide walks through the three records that matter, in the order you should set them up, with the mistakes we see most often.
1. SPF: who is allowed to send for your domain
What it does: SPF (Sender Policy Framework) is a TXT record that lists the servers allowed to send email using your domain in the envelope sender.
What it looks like:
yourdomain.com. TXT "v=spf1 include:_spf.google.com include:<your-smtp-provider> ~all"
Checklist
- [ ] Publish one SPF record per domain. Two
v=spf1records make SPF fail outright. - [ ] Include every service that sends as your domain: your mailbox provider, your SMTP relay, your helpdesk, your CRM.
- [ ] Stay under 10 DNS lookups. Each
include:counts, and nested includes count too. Too many and SPF returns a "permerror". - [ ] Start with
~all(softfail) while you audit, and move to-allonce you're sure the list is complete.
Common mistake: adding a new tool months later and forgetting to update SPF. The new tool's mail silently starts failing.
2. DKIM: proof the message wasn't changed
What it does: DKIM (DomainKeys Identified Mail) adds a cryptographic signature to every message. The receiving server looks up your public key in DNS and checks that the message wasn't altered in transit.
What it looks like:
selector1._domainkey.yourdomain.com. TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkqh..."
Checklist
- [ ] Use a 2048-bit key where your provider supports it.
- [ ] Sign with your own domain, not your provider's shared domain. This is what makes DMARC alignment work (see below).
- [ ] Give each sending service its own selector, so you can rotate or revoke one without touching the others.
- [ ] Rotate keys periodically and remove selectors for tools you no longer use.
Common mistake: DKIM "passes", but for the provider's domain instead of yours. Receivers see a valid signature that doesn't match your From address, which doesn't help your reputation.
3. DMARC: the policy that ties it together
What it does: DMARC tells receivers what to do when a message claims to be from your domain but fails SPF and DKIM alignment. It also sends you reports showing who is sending as your domain.
What it looks like:
_dmarc.yourdomain.com. TXT "v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com; fo=1"
Checklist
- [ ] Start with
p=noneand a reporting address (rua=). Read the reports for two to four weeks. - [ ] Confirm every legitimate sender passes with alignment. The domain in SPF or DKIM must match the domain in the visible From address.
- [ ] Move to
p=quarantine, thenp=reject, once the reports are clean. - [ ] Keep the reporting address monitored. DMARC reports are often the first sign that someone is spoofing your domain.
Common mistake: jumping straight to p=reject and blocking your own invoices because the billing tool was never added to SPF or DKIM.
4. Beyond DNS: what keeps you in the inbox
Authentication gets you through the door. Staying in the inbox depends on behaviour:
- Separate your streams. Send transactional email (receipts, resets) from a different IP or subdomain than marketing email, so a newsletter complaint spike can't hurt order confirmations.
- Warm up new IPs and domains. Ramp volume gradually over days or weeks instead of sending your full list on day one.
- Watch bounces and complaints. Gmail asks senders to keep spam complaints below 0.1% and never reach 0.3%. Remove hard bounces immediately.
- Monitor blocklists. A listing on a major blocklist can quietly cut your delivery rate. Check daily, not after customers complain.
- Use TLS. Send over port 587 with STARTTLS so messages are encrypted in transit.
Quick reference
-
SPF (TXT on
yourdomain.com): authorised senders. Start with~all, end with-all. -
DKIM (TXT on
selector._domainkey): message signature. 2048-bit key on your own domain, one selector per sender. -
DMARC (TXT on
_dmarc): policy and reporting. Start withp=noneplusrua, end withp=reject.
SMTPCart is a managed SMTP relay. We set up SPF, DKIM and DMARC for each customer, keep sending reputation isolated, manage warm-up and monitor blocklists daily, so your app's email reaches the inbox. If you'd like a second pair of eyes on your setup, we offer a free deliverability check at smtpcart.com.
Top comments (1)
You need to verify your account .
Link is in the profile.