Skip to content

TroubleshootingEmail delivery

Emails going to spam? Fix SPF, DKIM, DMARC and reverse DNS

Find out why your mail lands in spam or bounces: check SPF, DKIM, DMARC and reverse DNS, read message headers and meet the Gmail and Yahoo sender requirements.

  • Intermediate
  • 15 min read
  • Updated

Tested on: Ubuntu 24.04 LTS, Debian 13, Windows 11

This guide is not available in your language yet, so it is shown in English.

On this page
  1. Before you start
  2. Step 1: Read what the receiver saw
  3. Step 2: SPF
  4. Step 3: DKIM
  5. Step 4: DMARC
  6. Step 5: Reverse DNS and HELO
  7. Step 6: Meet the large providers' rules
  8. Step 7: Check reputation and blocklists
  9. Hosting accounts
  10. Troubleshooting
  11. Next steps

Whether your mail reaches the inbox depends on a few checks that every receiving server runs: is the sender allowed (SPF), is the message signed (DKIM), what does the domain owner want done with failures (DMARC), and does the sending IP address have matching reverse DNS. This guide checks each one and fixes the usual gaps. Replace example.com and 203.0.113.10 with your domain and your mail server's IP address.

Before you start

  • Know which server sends your mail: your VPS, your hosting plan's mail server, or an external email service.
  • Have access to the DNS of your domain (your DNS host or hosting control panel).
  • Send a test message to a Gmail or Outlook address you control, so you can read the headers.
  • On a HyperDC VPS, outbound port 25 is closed by default; see the troubleshooting section below for how it is opened.

Step 1: Read what the receiver saw

Open the test message's headers (Gmail: Show original; Outlook: View message source). Find the Authentication-Results line:

Text
Authentication-Results: mx.example.net;
       spf=pass smtp.mailfrom=example.com;
       dkim=pass header.d=example.com;
       dmarc=pass header.from=example.com

Each check that does not say pass points you to one of the steps below.

Step 2: SPF

SPF is a TXT record listing the servers allowed to send for your domain:

Bash
dig TXT example.com +short

You should see exactly one record that starts with v=spf1, for example:

Text
"v=spf1 ip4:203.0.113.10 include:_spf.mailprovider.example -all"
  • Add every system that sends for you: your server's IP (ip4:), your email provider (include:).
  • Only one SPF record per name; merge them if there are two.
  • At most ten DNS lookups (each include, a, mx counts).
  • End with -all (reject others) or ~all (soft fail) once the list is complete.

Step 3: DKIM

DKIM signs each message; receivers check the signature with a public key in DNS. Your mail server or provider gives you the record and its selector. Check that it is published:

Bash
dig TXT default._domainkey.example.com +short

Replace default with your selector (the s= value in the DKIM-Signature header of a sent message). An empty answer means the key is missing; a dkim=fail result means the key and the signature do not match, often after a key change.

Step 4: DMARC

DMARC tells receivers what to do when SPF and DKIM do not align with the visible From domain, and where to send reports:

Bash
dig TXT _dmarc.example.com +short

Start with monitoring and tighten step by step:

Text
"v=DMARC1; p=none; rua=mailto:[email protected]"

When the reports show that all your legitimate mail passes, move to p=quarantine and later p=reject. For a domain that never sends mail, publish v=spf1 -all and a DMARC policy of p=reject to stop others from using it.

Step 5: Reverse DNS and HELO

The sending IP address needs a PTR record, and that name should resolve back to the same IP:

Bash
dig -x 203.0.113.10 +short
dig mail.example.com A +short

Set your mail server's host name (the name it announces in HELO/EHLO) to that same name. See reverse DNS (PTR) to request the PTR record for a HyperDC IP address.

Step 6: Meet the large providers' rules

Gmail and Yahoo require from every sender SPF or DKIM, valid forward and reverse DNS for the sending IP and TLS for the connection. Senders of large volumes (Gmail names more than 5,000 messages a day to its users) also need SPF, DKIM and DMARC, alignment of the From domain, easy one-click unsubscribe for marketing mail and a low spam complaint rate. Their sender guidelines list the details.

Step 7: Check reputation and blocklists

If authentication passes and mail still lands in spam or bounces with a message naming a blocklist:

  • Read the bounce text; it usually names the list or the reason.
  • Look up your IP address and domain on the list it names and follow that list's removal process.
  • Find the cause before you request removal: a compromised mailbox, a contact form abused for spam or a script sending in bulk. Check your mail queue and logs.

Hosting accounts

On cPanel hosting, open Email › Email Deliverability. It checks the SPF, DKIM and PTR records for each domain and can install the suggested records when the domain uses the hosting nameservers.

Troubleshooting

spf=permerror. Two SPF records or more than ten lookups. Merge records and remove unused includes.

dkim=fail (body hash did not verify). Something changed the message after signing, such as a footer added by a mailing list or a forwarding service.

dmarc=fail while SPF passes. SPF passed for a different domain than the one in From (for example a provider's bounce domain). Sign with DKIM for your own domain so DMARC aligns.

Outgoing connections on port 25 time out. Outbound port 25 is closed by default on HyperDC VPS. For services bought for a term of 3 months or longer, it is opened on request: open a support ticket and choose the server under Related Service. Until then, send through a relay on port 587. You can test the port from the server with nc -vz gmail-smtp-in.l.google.com 25.

Next steps

Frequently asked questions

Do I need all of SPF, DKIM and DMARC?

Yes. Large mailbox providers expect SPF or DKIM from every sender, and SPF, DKIM and a DMARC record from bulk senders. Together they prove that your mail really comes from you and stop others from sending in your name.

Can I have two SPF records?

No. A name may have only one SPF record; two of them make SPF fail. Merge all your senders into one record, and stay within the limit of ten DNS lookups.

Why does reverse DNS matter for email?

Receiving servers check that the sending IP address has a PTR name that points back to the same address. Mail from IP addresses without matching reverse DNS is often rejected or marked as spam.

My IP address is on a blocklist. What now?

Find and stop the cause first, for example a compromised account or a form that sends spam. Then request removal through the blocklist's own process. Removal without fixing the cause does not last.

Should I run my own mail server?

Only if you are prepared to maintain it. A mail server needs correct DNS, reverse DNS, TLS, spam filtering and constant monitoring of its reputation. Many teams use the mail of a hosting plan or a dedicated email service instead.

Sources

Gerar Senha

Please confirm