# Emails going to spam? Fix SPF, DKIM, DMARC and reverse DNS

> Find out why your mail lands in spam or bounces: check SPF, DKIM, DMARC and reverse DNS, read message headers and meet the Gmail and Yahoo sender requirements.

Difficulty: Intermediate\
Tested on: Ubuntu 24.04 LTS, Debian 13, Windows 11

Whether your mail reaches the inbox depends on a few checks that every receiving server runs: is the sender allowed (SPF), is the message signed (DKIM), what does the domain owner want done with failures (DMARC), and does the sending IP address have matching reverse DNS. This guide checks each one and fixes the usual gaps. Replace `example.com` and `203.0.113.10` with your domain and your mail server's IP address.

## Before you start

- Know **which server sends your mail**: your VPS, your hosting plan's mail server, or an external email service.
- Have access to the **DNS of your domain** (your DNS host or hosting control panel).
- Send a test message to a Gmail or Outlook address you control, so you can read the headers.
- On a HyperDC VPS, outbound port 25 is closed by default; see the troubleshooting section below for how it is opened.

## Step 1: Read what the receiver saw

Open the test message's headers (Gmail: **Show original**; Outlook: **View message source**). Find the `Authentication-Results` line:

```text
Authentication-Results: mx.example.net;
       spf=pass smtp.mailfrom=example.com;
       dkim=pass header.d=example.com;
       dmarc=pass header.from=example.com
```

Each check that does not say `pass` points you to one of the steps below.

## Step 2: SPF

SPF is a TXT record listing the servers allowed to send for your domain:

```bash
dig TXT example.com +short
```

You should see exactly **one** record that starts with `v=spf1`, for example:

```text
"v=spf1 ip4:203.0.113.10 include:_spf.mailprovider.example -all"
```

- Add every system that sends for you: your server's IP (`ip4:`), your email provider (`include:`).
- **Only one** SPF record per name; merge them if there are two.
- At most **ten DNS lookups** (each `include`, `a`, `mx` counts).
- End with `-all` (reject others) or `~all` (soft fail) once the list is complete.

## Step 3: DKIM

DKIM signs each message; receivers check the signature with a public key in DNS. Your mail server or provider gives you the record and its **selector**. Check that it is published:

```bash
dig TXT default._domainkey.example.com +short
```

Replace `default` with your selector (the `s=` value in the `DKIM-Signature` header of a sent message). An empty answer means the key is missing; a `dkim=fail` result means the key and the signature do not match, often after a key change.

## Step 4: DMARC

DMARC tells receivers what to do when SPF and DKIM do not align with the visible From domain, and where to send reports:

```bash
dig TXT _dmarc.example.com +short
```

Start with monitoring and tighten step by step:

```text
"v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com"
```

When the reports show that all your legitimate mail passes, move to `p=quarantine` and later `p=reject`. For a domain that never sends mail, publish `v=spf1 -all` and a DMARC policy of `p=reject` to stop others from using it.

## Step 5: Reverse DNS and HELO

The sending IP address needs a PTR record, and that name should resolve back to the same IP:

```bash
dig -x 203.0.113.10 +short
dig mail.example.com A +short
```

Set your mail server's host name (the name it announces in HELO/EHLO) to that same name. See [reverse DNS (PTR)](/guides/reverse-dns-ptr) to request the PTR record for a HyperDC IP address.

## Step 6: Meet the large providers' rules

Gmail and Yahoo require from every sender SPF or DKIM, valid forward and reverse DNS for the sending IP and TLS for the connection. Senders of large volumes (Gmail names more than 5,000 messages a day to its users) also need SPF, DKIM and DMARC, alignment of the From domain, easy one-click unsubscribe for marketing mail and a low spam complaint rate. Their sender guidelines list the details.

## Step 7: Check reputation and blocklists

If authentication passes and mail still lands in spam or bounces with a message naming a blocklist:

- Read the bounce text; it usually names the list or the reason.
- Look up your IP address and domain on the list it names and follow that list's removal process.
- Find the cause before you request removal: a compromised mailbox, a contact form abused for spam or a script sending in bulk. Check your mail queue and logs.

## Hosting accounts

On cPanel hosting, open **Email › Email Deliverability**. It checks the SPF, DKIM and PTR records for each domain and can install the suggested records when the domain uses the hosting nameservers.

## Troubleshooting

**`spf=permerror`.** Two SPF records or more than ten lookups. Merge records and remove unused includes.

**`dkim=fail (body hash did not verify)`.** Something changed the message after signing, such as a footer added by a mailing list or a forwarding service.

**`dmarc=fail` while SPF passes.** SPF passed for a different domain than the one in From (for example a provider's bounce domain). Sign with DKIM for your own domain so DMARC aligns.

**Outgoing connections on port 25 time out.** Outbound port 25 is closed by default on HyperDC VPS. For services bought for a term of 3 months or longer, it is opened on request: open a support ticket and choose the server under **Related Service**. Until then, send through a relay on port 587. You can test the port from the server with `nc -vz gmail-smtp-in.l.google.com 25`.

## Next steps

- Set the PTR record: [reverse DNS (PTR)](/guides/reverse-dns-ptr).
- Records explained: [DNS basics for a new domain](/guides/dns-basics-for-a-new-domain).
- Received an abuse complaint about spam? See [abuse FAQ](/guides/abuse-faq).

## Frequently asked questions

### Do I need all of SPF, DKIM and DMARC?

Yes. Large mailbox providers expect SPF or DKIM from every sender, and SPF, DKIM and a DMARC record from bulk senders. Together they prove that your mail really comes from you and stop others from sending in your name.

### Can I have two SPF records?

No. A name may have only one SPF record; two of them make SPF fail. Merge all your senders into one record, and stay within the limit of ten DNS lookups.

### Why does reverse DNS matter for email?

Receiving servers check that the sending IP address has a PTR name that points back to the same address. Mail from IP addresses without matching reverse DNS is often rejected or marked as spam.

### My IP address is on a blocklist. What now?

Find and stop the cause first, for example a compromised account or a form that sends spam. Then request removal through the blocklist's own process. Removal without fixing the cause does not last.

### Should I run my own mail server?

Only if you are prepared to maintain it. A mail server needs correct DNS, reverse DNS, TLS, spam filtering and constant monitoring of its reputation. Many teams use the mail of a hosting plan or a dedicated email service instead.

---

Source: <https://hyperdc.com/guides/troubleshooting/email-deliverability>\
Updated: 2026-10-09
