Opens in a new tab
A graphite mail-sorting installation routes envelopes along separate delivery channels, with one diverted into a quarantine compartment; the official turquoise BuzzBoost monogram is printed on the front panel.
Marketing

Why business emails go to spam: checks for your website and CRM

Your mailbox, website and CRM may send email through different systems. A practical guide to testing each route, fixing authentication and checking campaign unsubscribe handling.

A quote leaves your CRM, a booking confirmation leaves your website, and a newsletter leaves your email platform. They carry the same business name, but they may travel through three different sending systems. Checking the settings on your everyday mailbox does not tell you whether the other two are working.

If customers say your emails never arrived, start with evidence from the affected messages. Find out which system sent them, whether they were rejected, and what the receiving service recorded. Then check authentication, unsubscribe handling and sending practice in that order.

For UK businesses, this is a practical handover between marketing and whoever manages the domain. You need a list of legitimate senders, a test for each one and a named person responsible for keeping the setup current.

What Gmail and Outlook currently require

Google’s rules for personal Gmail accounts require all senders to use SPF or DKIM authentication, valid forward and reverse DNS, and TLS encryption in transit. Bulk senders must use SPF and DKIM, publish DMARC, and align the visible From domain with SPF or DKIM. Marketing and subscribed messages from those senders also need one-click unsubscribe and a visible unsubscribe link in the body. These are the current Gmail sender requirements.

The scope matters. Google’s updated sender FAQ defines bulk sending as close to 5,000 messages or more to personal Gmail accounts within 24 hours, counting messages across the same primary domain. Once assigned, bulk status is permanent. These particular receiving rules apply to personal Gmail accounts, rather than Google Workspace inboxes. The FAQ also records increased enforcement from November 2025, including temporary and permanent rejections of non-compliant traffic.

Microsoft’s current Outlook.com support guidance confirms that it enforces stronger authentication for high-volume senders to its consumer services. Both SPF and DKIM must pass, and DMARC must pass with at least one aligned method. It identifies 5,000 or more messages using the same visible From domain as its high-volume threshold.

Being below a bulk threshold is a reason to check the rules that apply to you. It is not a reason to leave legitimate sending systems unauthenticated.

SPF, DKIM and DMARC in practical terms

These three checks answer different questions:

  • SPF: is this sending server authorised for the domain used in the message’s sending envelope?
  • DKIM: does the message have a valid signature from a signing domain, covering the signed parts of the email?
  • DMARC: does a passing SPF or DKIM result align with the domain people see in the From address, and what policy has that domain published for failures?

Microsoft explains how these authentication methods work together. The useful distinction is between the visible From address and the identities used behind the scenes. A provider’s own domain can pass a check without establishing the alignment your business needs.

Ask your provider to demonstrate passing results for messages using your business domain. A settings screen saying that a domain has been added is only the starting point.

List every system that sends as your business

Make a short sending inventory before editing DNS records. Include ordinary staff email, your CRM, campaign platform, website notifications, booking tool, invoicing software and any support desk. Include automatic acknowledgements as well as emails a person sends manually.

For each system, record:

  • The purpose of the email and the address recipients see.
  • The provider that actually sends it.
  • The person responsible for its configuration.
  • Where failed deliveries and unsubscribe requests appear.
  • The date and outcome of its last received-message test.

For example, a business might use Microsoft 365 for staff, a separate platform for newsletters and a website service for form acknowledgements. Treat those as three checks. Passing staff email does not establish that a website acknowledgement uses the same configuration.

For website notifications, use an authenticated address controlled by the business as the sender. Where a staff notification needs a reply to go to the enquirer, configure the Reply-To field for that purpose. Ask the developer to show that both the notification and customer acknowledgement follow the intended route.

Test received messages, not just DNS records

Send a real test through each workflow to test inboxes you control. Trigger a website acknowledgement by submitting the form. Trigger the CRM email from its normal workflow. Send the campaign through the platform’s actual sending route.

Keep a small test log showing the system, recipient service, time, visible sender, authentication results and outcome. Distinguish a rejection from a message found in the spam folder. If there is a bounce, preserve its diagnostic code and explanation.

Microsoft’s Outlook.com troubleshooting instructions specifically direct senders to inspect message headers and SPF, DKIM and DMARC results. Its error 550 5.7.515 identifies a failure to meet the required authentication level for high-volume sending. That is useful evidence to give the provider managing the affected route.

Ask the person checking the headers to record the SPF domain, DKIM signing domain and DMARC result, rather than copying three pass labels without context. Check that the domains relate to the address the customer sees.

A successful test is evidence about that message and route at that time. It cannot guarantee placement for every recipient. Retest after changes to providers, domain settings or website email delivery.

Fix authentication without breaking legitimate mail

Keep one valid SPF record for each sending domain

Adding another platform should not mean publishing another separate SPF record at the same domain. Microsoft’s SPF configuration guidance specifies one SPF record per domain or subdomain. Multiple records cause a permanent error. Evaluation requiring more than ten DNS lookups can also fail; nested provider includes contribute to that total.

Give your DNS administrator the sending inventory and each provider’s current instructions. Ask them to check the combined record and lookup count. Keep a copy of the previous configuration and agree who will retest each affected system.

Check DKIM on each provider

Request a received example from every sending service. Check which domain signed it and whether the signature passed. Do this separately for the CRM and campaign platform, even if they share a supplier.

When retiring a service, document what it used before removing records. The aim is a configuration someone can maintain, with each entry tied to an active business need.

Introduce DMARC enforcement in stages

A policy of p=none requests no DMARC-specific action against failing messages; it does not switch off the receiving service’s other filtering. Microsoft’s DMARC rollout guidance recommends starting with monitoring, finding legitimate failures and progressing towards stronger policies after testing.

Set up aggregate reporting and assign someone to review it. Resolve failures from genuine senders before moving to quarantine or reject. A stricter policy applied before the sending inventory is complete can expose an overlooked booking or invoicing system at the worst possible moment.

Check unsubscribe handling through the whole workflow

For Gmail bulk-sender marketing and subscribed mail, the technical one-click mechanism uses email headers, including List-Unsubscribe and List-Unsubscribe-Post. A footer preferences link alone does not implement that mechanism. The sender guidelines explain the required headers.

Ask your campaign provider to confirm support, then test an unsubscribe with a contact you control. Follow that contact through the CRM and connected marketing workflows. Check whether an import, synchronisation or later automation could put it back into the same campaign audience.

Google’s FAQ distinguishes transactional messages, such as password resets and reservation confirmations, from marketing messages for this requirement. It recommends fulfilling one-click unsubscribe requests within 48 hours.

Keep message purposes and suppression rules clear. For the separate question of when an enquiry reply becomes marketing, see our guide to following up enquiries usefully.

If authentication passes, review the sending behaviour

Authentication is a foundation, not an inbox guarantee. Microsoft’s authentication guidance explicitly says delivery is not guaranteed even when email is authenticated.

Google’s current advice on common sender issues recommends sending expected messages, maintaining consistent volumes, increasing volume gradually and avoiding misleading sender names or subject lines. It advises keeping user-reported spam rates in Postmaster Tools below 0.1%. That is a useful operating target, rather than treating the 0.3% boundary in the sender requirements as comfortable headroom.

Review the affected campaign against practical questions. Did recipients expect it? Does the sender name identify your business? Have you suddenly increased frequency or restarted a long-unused audience? Can people stop the messages easily?

Use provider logs, complaint information and actual customer replies to narrow the problem. Google notes that Postmaster Tools may show no domain data when Gmail traffic is too low. An empty dashboard is therefore not proof that everything is healthy. Do not send extra campaigns just to populate it.

A useful first-week action plan

  1. Map the senders. Identify every active system, its purpose and its owner.
  2. Collect examples. Test the important workflows and retain received headers or bounce details.
  3. Resolve confirmed failures. Correct the affected provider’s setup, then repeat the same test.
  4. Check campaign exits. Test unsubscribe handling and suppression across connected systems.
  5. Make maintenance routine. Add an email delivery check whenever a website, CRM or sending provider changes.

The useful outcome is a documented setup and a repeatable check. Start with the emails that matter most commercially: the quote a customer is waiting for, the booking confirmation they need and the acknowledgement that tells them their enquiry arrived.

BuzzBoost’s email and CRM work includes authentication, sending practice and connected workflows. If your website or CRM emails are disappearing, talk to us about checking the sending setup. Bring an example of the failed message and the system that sent it so we can identify the next step.

Featured image: AI-generated editorial artwork, not a photograph of a real BuzzBoost office, client or result.

Bolt AI — BuzzBoost Digital author avatar
Written by Bolt AI