If your booking confirmations, invoices or review requests keep landing in spam — or customers say they "never got the email" — the cause is usually not your message. It's that your domain isn't proving the email really came from you. Three small records fix that: SPF, DKIM and DMARC.

These are the most-failed checks we see in audits, and they have nothing to do with how your website looks. They live in your domain's DNS settings. Get them right and two things happen: your email reliably reaches the inbox, and nobody can send scam email pretending to be your business.

You don't need to be technical

Think of these three records as an ID card, a tamper-proof seal, and a rulebook. You don't have to configure them by hand — your email provider (Google Workspace, Microsoft 365, your host) has a guide, and ranker.bot flags exactly which are missing.

Why email authentication decides who reaches the inbox

Inbox providers like Gmail and Outlook receive an enormous amount of spam and spoofed mail. To protect users, they now quietly demand proof of identity from the sending domain. If your domain can't provide it, your legitimate email is treated with suspicion — filtered, foldered, or dropped. For a local business, that's the difference between a confirmed appointment and a no-show.

1. SPF — who is allowed to send as you

SPF (Sender Policy Framework) is a public list of the mail servers permitted to send email using your domain. When Gmail receives a message claiming to be from you, it checks whether the sending server is on your list.

What it looks like

A single line in your DNS, e.g. v=spf1 include:_spf.google.com ~all. The include entries name your providers (Google, Microsoft, your booking tool, your newsletter service).

The common mistake

Businesses add a new tool — an email marketing service, a booking platform — but never add it to SPF. The tool's mail then fails the check and lands in spam. Every service that sends on your behalf must be listed.

2. DKIM — proof the message wasn't tampered with

DKIM (DomainKeys Identified Mail) adds an invisible cryptographic signature to every message you send. The receiving server uses a public key published in your DNS to confirm the email genuinely came from your domain and wasn't altered in transit.

If SPF is the ID card, DKIM is the tamper-proof seal. Together they make it very hard to forge mail from your domain.

3. DMARC — the rulebook that ties it together

DMARC (Domain-based Message Authentication) tells inbox providers what to do when a message fails SPF or DKIM: allow it, send it to spam, or reject it outright. It also emails you reports so you can see who is sending as your domain — including impersonators.

Without DMARC, anyone can send email that looks like it comes from your business. With it, you decide what happens to mail that fails the check — and you find out who's trying.

A gentle starting policy is p=none (monitor only), moving to p=quarantine and eventually p=reject once you've confirmed all your legitimate senders pass.

How to check yours in two minutes

  • Search for a free "DMARC checker", enter your domain, and read the three results
  • SPF present and listing every tool you send from
  • DKIM enabled in your email provider's admin settings
  • DMARC record present, starting at p=none while you monitor

Fixing the gaps

Each record is added in your DNS settings (where your domain is registered) or turned on inside your email provider's admin panel. Your provider has a step-by-step guide for each — search "[your provider] set up SPF DKIM DMARC". If you use a marketing or booking tool, it will have its own SPF include and DKIM setup instructions too.

Do it in order

Set up SPF and DKIM first and confirm they pass. Only then add DMARC at p=none, watch the reports for a couple of weeks, and tighten the policy once every legitimate sender is passing. Rushing to p=reject can block your own mail.

Common questions

Will fixing this stop my emails going to spam?

It removes the single biggest technical reason mail is filtered. Content and sending reputation also matter, but authentication is the foundation — without it, even perfect emails get suspected.

Is this the same as my website security?

No. These records live in your domain's DNS and govern email, not your website. A site can have a perfect SSL certificate and still fail email authentication completely.

How long do changes take to work?

DNS changes usually take effect within a few hours, though they can take up to 48 hours to fully propagate.

Want this handled for you? Run a free audit and ranker.bot will find the issues, prioritise them, and fix the ones you approve — in plain English, no agency retainer.