Prompt
I'm having trouble with transaction emails landing in spam, and I don't know if it's my SPF or the provider. How do I figure that out?
Latest observation
To figure out whether it’s your SPF setup or your email provider’s reputation/configuration, look at it in this order:
1) Check the email headers of a message that landed in spam
Open the spam email and view the full headers / message source. Look for:
- SPF:
passorfail - DKIM:
passorfail - DMARC:
passorfail - Any notes from Gmail/Outlook/Yahoo like:
spf=passdkim=passdmarc=passsender authentication failedbulk sender,suspicious,phishing, etc.
What this tells you
- SPF fail → likely a DNS/authorization issue.
- SPF pass but still spam → SPF is probably not the main problem.
- SPF pass, DKIM pass, DMARC fail → alignment/policy issue.
- All pass but still spam → more likely provider reputation, content, or domain/IP history.
2) Verify SPF independently
Check your domain’s SPF record in DNS. It should:
- Exist as a single TXT record for the domain
- End with
~allor-alldepending on your policy - Include the mail provider’s sending hosts
Common SPF problems
- Multiple SPF records on the same domain
- Missing the provider’s
include:entry - Exceeding the 10 DNS lookup limit
- Sending mail from a service not listed in SPF
- Using the wrong domain/subdomain in the Return-Path or From domain
If you use a third-party transactional provider, their docs usually give the exact SPF include to add.
3) Check whether the provider is the issue
If SPF/DKIM/DMARC all pass, the next suspects are usually:
- Shared IP reputation (if they send from shared infrastructure)
- Dedicated IP reputation (if you use one)
- Domain reputation based on complaint/engagement history
- Content patterns that trigger filters
- Missing or weak DKIM signing
- Poor list hygiene or lots of bounces/complaints
- Inconsistent sending volume or sudden spikes
Signs it’s the provider/reputation
- Headers show authentication passed
- Spam placement varies by mailbox provider (Gmail vs Outlook vs Yahoo)
- Delivery is good for some recipients but not others
- Messages started landing in spam after a volume spike or provider change
4) Use a seed test
Send the same message to test accounts at:
- Gmail
- Outlook/Hotmail
- Yahoo
- iCloud
Then compare:
- Inbox vs spam
- Authentication results in headers
- Whether all providers behave the same
If Gmail and Outlook both spam it, that points more to reputation/content/authentication than one mailbox provider.
5) Check DMARC reports if you have them
If you’ve set up DMARC, aggregate reports can show:
- Which systems are sending mail for your domain
- Whether SPF/DKIM align
- Where failures happen
This is one of the fastest ways to see if your provider is sending correctly.
6) Confirm alignment
Even if SPF passes, DMARC cares about alignment:
- The domain in the visible From: address must align with the SPF-authenticated domain and/or DKIM signing domain.
Example:
- From:
billing@yourdomain.com - SPF authenticates
mail.provider.com - If it’s not aligned with
yourdomain.com, DMARC can fail even though SPF says pass.
7) Check blacklists and reputation tools
Use tools like:
- MXToolbox
- Google Postmaster Tools
- Microsoft SNDS
- SenderScore / other reputation tools
These can show whether:
- Your IP/domain is blacklisted
- Reputation is poor at major mailbox providers
- The provider’s IP pool is the problem
Quick rule of thumb
- SPF fail in headers → fix SPF/authentication.
- SPF pass, DKIM pass, DMARC pass, but spam persists → likely provider reputation, IP reputation, or content.
- DMARC fail → likely alignment or configuration issue, even if SPF passes.
If you want, paste a redacted copy of the email headers here (remove personal info), and I can help you interpret whether it’s SPF, DKIM, DMARC, or provider reputation.