iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
If mail still goes to spam after you set up SPF, DKIM, and DMARC, diagnose an actual delivered message before changing DNS: compare its Authentication-Results with the visible From domain, then trace any failure to the sending service, key, or alignment policy. If authentication passes, investigate sender reputation and the recipient provider’s other requirements. Passing authentication improves the chances of delivery; it does not guarantee inbox placement.
This guide focuses on personal Gmail and Google Workspace because the specific sender requirements below are Google’s. Other mailbox providers may apply different rules. Google’s bulk-sender requirements described here began February 1, 2024; their inclusion does not mean they were newly introduced in 2026.
How do you tell whether authentication or inbox placement is the problem?
Inspect one message that reached the affected inbox
- Send a controlled test to an account at the mailbox provider where delivery is a problem. Use the same sending service and message path as the mail that lands in spam.
- In Gmail, open the message, select the three-dot menu, then choose Show original. Record the visible
From,Return-Path,Authentication-Results, and the sending IP if shown. Also note whether the message was delivered, placed in spam, rejected, or deferred. - Read the receiving provider’s authentication results for that message. A DNS checker can show that a record exists, but it cannot establish whether this particular message passed or aligned.
| Result in the message headers | What it establishes | What to check next |
|---|---|---|
spf=pass |
The sender was authorized under the SPF policy evaluated for the envelope identity. | Compare that identity’s organizational domain with the visible From domain. An SPF pass alone does not prove alignment. |
dkim=pass |
The message’s DKIM signature verified for its signing domain. | Compare the signature’s d= domain with the visible From domain under the receiver’s alignment rules. |
dmarc=pass |
At least one passing SPF or DKIM identity aligned with the visible From domain under the applicable policy. |
If the message still lands in spam, continue to sender practices and other provider requirements. |
The envelope sender used for SPF is not necessarily the address shown in the visible From header. That distinction explains a common result: SPF passes, but DMARC fails because the passing identity is not aligned.
How do you fix SPF for every sending service?
Inventory the systems that send as your domain
List every active source: your mailbox provider, website forms, CRM, newsletter platform, billing system, support desk, and any application that sends mail using your domain. If a legitimate source is missing from SPF, mail from that source can fail even when mail from your primary mailbox provider passes.
#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Check the record and its lookup limit
- Confirm the SPF TXT record is published on the correct domain and that the domain has only one SPF record.
- Ensure the single record authorizes all active senders using the mechanisms each provider documents.
- Check for syntax errors, incorrect qualifiers, and mechanisms that trigger too many DNS lookups. Google Workspace Help says SPF permits a maximum of 10 DNS lookups, including nested lookups.
- Remove obsolete sender entries rather than adding broad, undocumented mechanisms. Multiple SPF records or omitted senders can cause failures.
Do not copy a generic SPF example without checking your senders. Google’s example, v=spf1 include:_spf.google.com ~all, is for a domain that uses Google Workspace alone; other sending services must be accounted for in the domain’s own record. Google Workspace Help says changes can take 24–48 hours to take global effect, so test again after that window.
How do you verify DKIM for each sending platform?
DKIM is configured per sending service, so a working signature from one provider does not establish that another provider’s mail is signed correctly.
Rank #2
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
- In the message headers, find the DKIM result and the signature’s
s=selector andd=signing domain. - In the sending provider’s settings, confirm that the selector and public key are published in DNS at the exact name the provider specifies. Compare that setup with the selector and signing domain on the affected message.
- If verification fails, check for a missing or incorrect key and ask whether an intermediary changed the signed message after it was signed. Google identifies incorrect published keys and message modification in transit as possible causes of DKIM failure.
For mail to personal Gmail, Google requires a DKIM key of at least 1024 bits and recommends 2048 bits where the sending provider supports it. This key guidance concerns Gmail authentication, not a promise of inbox delivery.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →How do you diagnose DMARC alignment without blocking legitimate mail?
DMARC passes when at least one mechanism—SPF or DKIM—both passes and aligns with the visible From domain. A raw SPF or DKIM pass that does not align is not enough. For direct mail to personal Gmail, Google’s stated bulk-sender alignment requirement is met when the visible From domain aligns with either SPF or DKIM’s organizational domain; Google recommends aligning both where practical.
Rank #3
- A FIDO security key with PUF technology provides a unique, hardware-rooted trust anchor that resists tampering and cyber attacks, offering stronger security than conventional designs.
- FIDO2 Certified Protection – Enjoy phishing-resistant security with FIDO2 certification, ensuring top-tier account safety across Windows, macOS, Linux, iOS iOS, Android and more.
- Easy to use & Portable – Designed with a compact USB-C interface, Clife key fits easily on your keychain for secure access anywhere. Simply plug in and authenticate with ease.
- Universal Compatibility – Works seamlessly with hundreds of FIDO2/U2F compliant services, including popular cloud, email, and social platforms.
- Backup recommended – To ensure continuous access, register a backup Clife security key as a spare in case your primary key is lost.
Compare relaxed and strict alignment
Check the DMARC alignment settings against the domains shown in the message headers. Strict alignment requires a closer domain match; legitimate mail can fail alignment if a provider signs or sends using a different subdomain. Google warns that strict alignment can make valid messages more likely to be rejected or sent to spam when identities differ.
Use reports before tightening enforcement
Review DMARC aggregate reports to identify which sending sources pass, fail, or use unaligned identities. Do not move to p=quarantine or p=reject until every legitimate mail stream is authenticated and aligned. Google’s troubleshooting guidance says SPF and DKIM should be enabled for at least 48 hours before DMARC is enabled.
Rank #4
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
A DMARC policy of p=none is not itself proof that DMARC caused spam placement. Google explicitly notes that messages can go to spam for another reason when the policy is set to none.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsWhat if SPF, DKIM, and DMARC all pass?
Passing authentication narrows the problem; it does not identify the cause of spam placement. Start with whether recipients expected and opted in to the mail, whether complaints have risen, whether sending volume changed sharply, and whether the sender identity and message categories are consistent. Google says unwanted mail and recipient spam reports can cause future messages to be marked as spam.
Best Value
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
For senders who send more than 5,000 messages per day to Gmail accounts, Google’s requirements also include valid forward and reverse DNS (PTR), TLS, and RFC 5322-compliant message formatting. Google’s sender guidelines say bulk senders should keep the spam rate reported in Postmaster Tools below 0.30%. That is Google guidance for Gmail—not a universal safe rate for all providers.
For relevant marketing and subscribed messages, Google requires one-click unsubscribe support and a visible unsubscribe link in the message body. Google’s stated direct-mail alignment requirement can be met with aligned SPF or aligned DKIM, but aligning both where practical provides a more robust setup. These requirements are specific to Google’s Gmail guidance and the relevant message types; they should not be presented as universal rules for every mailbox provider.
How do you confirm a fix and monitor Gmail delivery?
- Make the narrowest correction supported by the evidence: add an omitted sender to SPF, correct a DKIM key or selector, or address the specific DMARC alignment mismatch. A policy change is riskier than correcting a known authentication fault.
- Keep a copy of the original message headers and note the DNS-change and test times. Send another controlled message through the affected service and compare its authentication results.
- Allow for DNS propagation after SPF changes; Google Workspace Help gives a 24–48-hour global window. Then verify the affected message again.
- Use Google Postmaster Tools to review available compliance status, authentication, delivery errors, spam reports, and format indicators. Google notes that authentication dashboards may show no data for domains that do not send mail, so interpret an empty view alongside actual sending activity.
- For DMARC detail, review aggregate reports; Google points senders to third-party tools for report analysis. If the evidence points to a provider’s configuration, consult that provider’s authentication support.
Authentication is one layer of delivery. A header-based diagnosis tells you whether to repair SPF, DKIM, or alignment; when all three pass, the next useful evidence is about recipient response, sending behavior, and the receiving provider’s other sender requirements.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

