Let us imagine a small renovation company. The owner sends a quote on Monday and waits. By Thursday nothing has come back, so he calls the customer, who says she never received anything. They look together while on the phone, and there it is: in the spam folder, between a parcel that does not exist and a prize nobody won.
This can happen to careful, honest businesses, and the first place to look is somewhere easy to overlook: the settings attached to the domain name. So let us look at what Gmail and Yahoo now ask of every sender, what the three settings do, how you can check yours today, and who in your life should change them.
Why do real business emails end up in spam?
Your customer's email service receives millions of messages every day, and anyone in the world can type your business name in the "From" line of an email. So the service asks a simple question of each message: can this domain prove that the email came from the business whose name is on it?
Google publishes its answer in the Gmail email sender guidelines. Since 1 February 2024, all senders to personal Gmail accounts must "Set up SPF or DKIM email authentication for your sending domains". Yahoo writes the same rule on its Sender Hub: "Implement SPF or DKIM at a minimum". Both services also watch how often people mark your emails as spam. Google asks senders to "Keep spam rates reported in Postmaster Tools below 0.3%", and Yahoo asks you to "Keep your spam rate below 0.3%".
When a message arrives without that proof, the receiving service has nothing that separates your real quote from a fake one written in your name. And naturally, a service that exists to protect its users treats both the same way.
What are the three settings that prove an email is yours?
First, a word on where these settings live. Every domain has a small public list of settings, stored with the company that manages your domain. This list tells the internet where your website is and where your email should go. The technical name is DNS records, and you need the name only because your domain host will use it. The three email settings are extra lines on that same list.
| What it does | Its name | Who gives you the value | |---|---|---| | Lists the services allowed to send email for your domain | SPF | Your email provider, plus each outside service that sends for you | | Adds a checkable signature to every message | DKIM | Your email provider | | Tells receivers what to do when a message fails both checks | DMARC | You decide the policy, your provider shows the format |
The first setting is a guest list. Google's setup page explains that receiving servers "check the SPF record to verify that the messages came from authorized servers." There is one rule that matters here: "Each domain must have its own SPF record", meaning one list per domain. If a second list gets added by mistake, the two conflict. Google also notes that one SPF record "can have up to 10 include: tags", where each tag names an outside service.
The second setting is a signature. Your email service keeps a secret key and uses it to sign each message you send. It publishes the matching public half in your domain settings. Google describes what happens at the other end: the "Receiver's email server gets the public key from the DKIM TXT record and uses the key to read the DKIM signature and authenticate the email." Google says DKIM "helps protect your domain against spoofing", which means strangers sending fake emails that carry your business name.
The third setting is a set of instructions. In Google's words, DMARC "tells receiving email servers what action to take on messages sent from your domain that don't pass SPF or DKIM authentication." You choose one of three policies. With "none", the receiver will "Take no action on the message and deliver it to the intended recipient" and log it in a daily report. With "quarantine", it will "Mark the messages as spam". With "reject", it will "Reject the message."
Which of these rules apply to a small business?
The rules come in two levels. Every sender must have SPF or DKIM. Senders of more than 5,000 messages a day to Gmail must have all three: Google's guidelines ask them to "Set up SPF and DKIM email authentication for your domain" and to "Set up DMARC email authentication for your sending domain. Your DMARC enforcement policy can be set to none." Yahoo asks bulk senders to "Implement both SPF & DKIM" and to "Publish a valid DMARC policy with at least p=none".
If your business sends fewer than 5,000 emails a day, then strictly speaking one of the first two settings satisfies the rule. My advice, the truth is, would be to set all three. They cost nothing, they take a short visit to your domain settings, and the day your newsletter grows or your booking tool starts sending reminders, you are already in order.
There is one more detail in Google's rules for large senders: "the domain in the sender's From: header must be aligned with either the SPF domain or the DKIM domain." Put simply, the domain your customer sees on the email should be the same domain that passed the check.
How can I check my own emails in two minutes?
You do not need any special tool. Gmail shows the result of these checks to anyone who looks. Google's help page on checking authentication gives the steps, and here they are in order.
- Send an ordinary email from your business address to a personal Gmail address you control.
- On a computer, open Gmail and open that email.
- Below the sender's name, click the Down arrow.
- Look for a line that says "Mailed by" and a line that says "Signed by", each followed by a domain.
If both lines show your domain, the signature and the sender check are working. If you see a question mark next to your name instead, Google says it means "Gmail doesn't know if the message is coming from the person who appears to be sending it." That is precisely what your customer's inbox sees, too.
Then repeat the test from every tool that sends email in your name: send yourself an invoice from your accounting software, submit your own website's contact form, book a test appointment. Each one may travel through a different service, and each one needs to pass.
Who sets these up, and what should I ask them?
Two parties are involved. The email provider (Google Workspace, Microsoft 365 or another service) gives you the values. The domain host is where you enter them, and Google describes it as "typically where you purchased your domain name". For Google Workspace, the signature is created in the Google Admin console and then added as a line in your domain settings.
This is the step that is easy to forget. Google warns: "If you start using a new mail server or third-party sender, make sure to update your SPF record. Otherwise, messages sent by the new senders could be marked as spam." Google also names "Services that send automatic email, for example 'Contact us' forms" as senders that belong on the list. So the invoicing tool added last spring, the booking app, the website form: each one must be named.
If someone else manages your domain, whether a web designer, an agency or a relative who once helped, send them these questions in writing:
- Does our domain have one SPF record, and does it include every service that sends email for us, including invoicing, booking and website forms?
- Is DKIM switched on for our email provider and for each of those services?
- Do we have a DMARC record, which policy does it use, and where do the reports go?
- Who has the login to our domain settings, and is it an account our business controls?
The last question matters more than it seems. If you do not know who can reach these settings, read our guide on who owns your website, domain and Google accounts before anything else.
What if the settings are right and emails still go to spam?
Then look at how people react to your emails. Gmail's guidelines recommend keeping the spam rate below 0.1% and to "avoid ever reaching a spam rate of 0.30% or higher". A spam rate is the share of your messages that recipients mark as spam. Sending newsletters to people who never asked for them pushes that number up, and it affects your quotes and invoices as well, because they come from the same domain.
For marketing emails, both services also ask for an easy way out. Google asks that "Marketing messages and subscribed messages must support one-click unsubscribe", and Yahoo asks senders to "Honor unsubscribes within 2 days". An unsubscribe link costs you a reader. A spam complaint adds to the spam rate that Gmail and Yahoo measure for your domain.
These settings are part of the ordinary care of a business website, alongside renewals, backups and the security certificate. We describe that routine in website maintenance at the big-company standard.
How does Licheo look at this?
Licheo does the website, search and AI work that big companies pay whole teams for, done for your small business, and email settings sit on the same domain as everything else. If you would like a first look, the free Get Found Check reads your homepage, your domain's DNS records and your security certificate, and returns a grade in under 60 seconds.
Sources
- Email sender guidelines, Gmail Help, Google, accessed 29 September 2026.
- Sender Best Practices, Yahoo Sender Hub, Yahoo, accessed 29 September 2026.
- Set up SPF, Google Workspace Help, Google, accessed 29 September 2026.
- Set up DKIM, Google Workspace Help, Google, accessed 29 September 2026.
- Set up DMARC, Google Workspace Help, Google, accessed 29 September 2026.
- Check if your Gmail message is authenticated, Gmail Help, Google, accessed 29 September 2026.