Why your emails land in spam
When a WordPress site or business mailbox sends mail that gets filtered, the cause is almost always one of these:
- Missing authentication records — no SPF, DKIM, or DMARC
- Shared server reputation — noisy neighbors on the same IP
- Content signals — URLs, attachments, or wording that looks spammy
- Low engagement — recipients marking your mail as spam drags your reputation down
- Sending from PHP
mail()— your WordPress site's default, which fails modern spam checks
Email is trust. The three DNS records below are how your domain proves it's who it says it is. This guide walks through each — the same records you'd set when setting up domain email.
SPF: who may send for your domain
SPF (Sender Policy Framework) is a single DNS TXT record listing every server allowed to send mail for your domain.
yourdomain.com. TXT "v=spf1 include:_spf.yourhost.com ~all"
include:each service you use (your host, Google Workspace, Mailgun — combine multipleinclude:blocks)~allsoft-fails unknown senders;-allhard-fails (use~alluntil you're sure)- Keep it under 10 DNS lookups or the record is invalidated
Find your value in your provider's docs — Hostinger, SiteGround, Google Workspace, and Zoho all publish their SPF includes.
DKIM: cryptographically sign your mail
DKIM adds a public key to your DNS and your provider signs each message with the matching private key.
- In your email provider, generate a DKIM key for your domain
- You get a hostname like
default._domainkey.yourdomain.comand a TXT value - Publish it, wait for propagation, then enable signing in the provider
Without DKIM, receiving servers can't verify the mail truly came from you — and big inboxes increasingly treat unsigned mail as suspicious.
DMARC: tell receivers what to do
DMARC ties SPF and DKIM together and gives you reporting:
_dmarc.yourdomain.com. TXT "v=DMARC1; p=none; rua=mailto:you@yourdomain.com"
- Start with
p=none— collect reports without rejecting anything - Review reports (the
ruamailbox) for legitimate senders you forgot - Move to
p=quarantine, thenp=rejectonce everything's aligned
How to check your setup
Three free tools that test your records instantly:
- Google Postmaster Tools — spam rate, reputation, and delivery errors for your domain
- MXToolbox — SPF/DKIM/DMARC checks and DNS lookups
- Mail-tester.com — sends a test email and scores your configuration out of 10
Run the check, fix anything it flags, then re-test. The troubleshooting loop is usually 20 minutes.
WordPress transactional mail
If you've done all the DNS work and WordPress site mail (resets, orders, forms) still gets filtered, the problem is PHP mail(). Route it through a real SMTP service instead — our WordPress SMTP setup covers Mailgun, SendGrid, and Postmark in detail.
Frequently asked questions
How long does SPF/DKIM/DMARC take to work? DNS propagation is usually complete in minutes to a few hours. Mail-tester.com confirms when your records are live.
Do I need all three records? DMARC is most effective when SPF and DKIM both pass. You can run DMARC with one, but alignment checks require both for best results.
My host set up email — why is it still in spam? Your domain's records may be correct while the server's shared IP has a bad reputation. Move to Google Workspace or a dedicated email service to fix the IP problem. Compare options in WordPress hosting and email.
Can DMARC break my email?
Only if you set p=reject before all legitimate senders are aligned. Start at p=none, review reports, then escalate.
What is email warm-up? Gradually increasing send volume from a new domain/address so inboxes build a positive reputation. Relevant when you start cold outreach or newsletters.