Business Emails Going to Spam? The Real Cause Is Your Domain

A customer rings on Thursday asking where the quote got to. You sent it Tuesday morning, PDF attached, polite note about lead times. It is sitting in their junk folder, unread, filed under discount printer cartridges. Business emails going to spam almost always gets blamed on the writing, so the usual response is to rewrite the subject line, delete the word "free" and send again. The copy was rarely the problem.
Why are my business emails going to spam when nothing about them looks spammy?
Because Gmail and Outlook decide before they read a word. They check your sending domain first. If your DNS carries no SPF, DKIM or DMARC records, nothing proves the message came from you rather than from someone impersonating you, and an unverified sender gets filtered no matter how the message reads.
Three records do the work. SPF lists the mail servers allowed to send on behalf of your domain, so a receiving server can check whether the message arrived from an authorised source. DKIM attaches a cryptographic signature to every message, confirming your domain signed it and the contents were not altered on the way through. DMARC ties the two together, telling receiving servers what to do with mail that fails those checks and sending you reports on who is using your domain name to send email. The ASD's Australian Cyber Security Centre is blunt about the order of operations, advising organisations to implement DMARC now irrespective of existing controls, and its advice on how to combat fake emails includes example DNS records you can hand straight to whoever manages your domain.
Plenty of Australian businesses have none of this in place. They bought a domain from a reseller a decade ago, pointed it at a website, added Microsoft 365, then bolted on Xero invoicing, a booking tool, a newsletter platform and a contact form plugin. Every one of those systems sends mail as you. None of them was ever declared in DNS.
What changed at Gmail and Outlook?
Both turned authentication from a recommendation into an entry requirement. Google's sender guidelines, in force since 1 February 2024, require senders of 5,000 or more messages a day to Gmail accounts to have SPF and DKIM passing plus a DMARC record of at least p=none, aligned to the From domain. Every sender, at any volume, needs at least one of SPF or DKIM.
Microsoft followed. Since 5 May 2025, domains sending more than 5,000 messages a day to outlook.com, hotmail.com and live.com addresses have had to pass SPF, DKIM and DMARC. Microsoft's enforcement notice confirmed that failing mail is rejected outright rather than quietly junked, returning a 550 5.7.515 access denied error, and that sitting on a recipient's safe senders list will not get you past it.
Five thousand messages a day sounds like someone else's problem. Here is the catch. The baseline rule, that all senders need SPF or DKIM, carries no volume threshold at all, and the same authentication signals feed the filtering decisions applied to every message, including the one-to-one quote you sent at 9:42 on Tuesday. Large senders get a hard rejection and at least know something broke. Small senders get the junk folder, silently, with no bounce notice to tell them.
How do I stop business emails going to spam without breaking my email?
Work in order and change one thing at a time. Rushing straight to a strict DMARC policy is the one mistake that will stop legitimate mail cold.
Check what you already have. Run your domain through a free SPF and DMARC lookup tool and note what comes back. A half-finished SPF record left behind by an old web host is a common find.
List every system that sends mail using your domain. Mail provider, accounting software, CRM, booking system, online store, website forms, e-newsletter platform. Anything you miss will start failing once you tighten the policy.
Publish one SPF record covering all of them. One record per domain, never two. Keep it under 10 DNS lookups, a limit Microsoft singles out as a frequent cause of SPF failures.
Turn DKIM on inside each sending platform and add the CNAME records it gives you.
Publish DMARC at p=none with a reporting address, read the reports for a few weeks, fix whatever is failing, then step up to quarantine and eventually reject.
None of that touches your copy, which is why the whole exercise feels counterintuitive to most owners. We treat it as step one of any email work at Searchline, because testing subject lines against a domain the receiving server does not trust tells you nothing useful.
Once authentication passes, content signals start mattering again. Clean your list, keep a genuine unsubscribe path in place (the unsubscribe obligations under Australian law apply regardless of deliverability), and only then compare your results against open rate benchmarks to judge whether the writing needs work.
Common questions
I send about 50 emails a day. Do these rules apply to me?
The 5,000-a-day thresholds at Google and Microsoft define bulk senders, so the hard rejections are not aimed at you. The baseline still is: Google requires every sender, at any volume, to have at least SPF or DKIM. Unauthenticated low-volume domains get filtered rather than rejected, which hurts more in practice because nothing tells you it happened.
I'm on Microsoft 365 or Google Workspace. Isn't this handled for me?
Partly. Both platforms handle SPF and DKIM for mail sent through their own servers, although DKIM often needs switching on manually rather than arriving enabled. Neither covers the invoicing software, booking system or newsletter tool sending under your domain, and neither publishes a DMARC record on your behalf.
How long until delivery improves?
DNS changes propagate within hours and authentication results change immediately for anything sent afterwards. Domain reputation recovers more slowly, across weeks, especially if spoofed mail has been going out in your name. Your DMARC reports will show the trend before your reply rate does.
Before you rewrite another subject line, spend two minutes running your domain through a lookup tool. It will tell you whether you have a copywriting problem or a DNS problem. For most Australian small businesses, it is DNS, and it has been quietly costing them jobs they never knew they quoted on.




