Skip to content
Harbor Tree

Why your quote emails end up in spam

You sent the quote. It never arrived, and nobody told either of you. Three public records decide whether a receiving server trusts mail from your domain.

7 min read
  • email deliverability
  • SPF
  • DMARC

You quoted a job on Tuesday. By Friday you'd heard nothing, and you filed it under went with someone cheaper — the way you file most of them, because that's usually what happened.

Sometimes it isn't. Sometimes the message was sorted into a spam folder before anyone read the subject line, and the silence is identical either way. The customer thinks you never replied. You think they went quiet. Nobody is told, which is the whole problem: an email that fails this way fails without an error, without a bounce, and without a single clue on your end that anything went wrong.

Three records decide whether you're believed#

When a message arrives claiming to be from your business, the receiving server has to make a judgement in a fraction of a second about whether it really is. It does that by looking up three public records attached to your domain. They're not secret, they're not technical trophies, and anyone can read yours right now — including your customers' mail providers, which is exactly what they do.

  1. SPF — who is allowed to send as you

    A list of the servers permitted to put your name on a message. If your mail goes out through Google and your website's contact form goes out through your host, both need to be on that list. A server that isn't listed is a message the receiver has to decide about with no help from you.

  2. DKIM — a signature that survives the journey

    A cryptographic signature added to the message itself. Unlike SPF, it travels with the mail, so it still proves the message is yours after it's been forwarded — which matters more than it sounds, because a customer forwarding your quote to their partner is the normal path a quote takes.

  3. DMARC — what to do when the first two fail

    The instruction you give receivers about messages that fail the checks above: let them through, set them aside, or refuse them. Without it, the other two are advice rather than a rule, and each receiving company falls back on its own judgement about your mail.

Why this is so often the website's fault#

Your day-to-day email is probably fine. It was set up once, it goes out through a mailbox provider that got the records right, and you'd have noticed years ago if it weren't working.

The mail that breaks is the mail your website sends: the notification when somebody fills in your contact form, the copy of the quote your booking page sends, the password reset from your customer area. That mail leaves from a different machine than your normal email does — your web host's, or a sending service the site was wired up to — and unless somebody deliberately added that machine to your SPF record, it's a stranger claiming to be you.

This is why the failure is so lopsided. The mail you'd notice works. The mail nobody watches is the mail carrying your leads.

What changedWhat it does to your mail
The website was rebuilt or moved hostForm notifications now leave from a machine your SPF record has never heard of
You added a newsletter or booking serviceA second sender, often with its own setup steps that got skipped at the end of a busy week
Someone added a second SPF recordThe worst outcome of the lot — see below
You switched mailbox providerThe old provider's servers usually stay in the record, and the new one's sometimes never make it in
The changes that quietly break it

What to actually do#

Find out what yours say before changing anything. These records are public, so this costs nothing and takes seconds. Our free email check reads all three for your domain and tells you plainly what it found — no account, and no email needed to see the result.

Then send the result to whoever holds your domain. That might be your web person, your IT support, or you with a login you haven't used since you bought the name. These changes happen in the DNS settings at your registrar, they take minutes for someone who has done it before, and they are the sort of thing that is genuinely easy to get subtly wrong — a stray character in an SPF record is not a syntax error, it's a silently weaker one.

Test the path that actually matters. Fill in your own contact form from a phone, using an address at a different provider from your own — a Gmail address if your business runs on Microsoft, or the reverse. That's the journey your leads take, and it's the one nobody ever tries.

Related: a contact form people actually finish, which is the step before this one, and why your website isn't getting you leads, which covers the ones that never reached the form at all.

Questions people ask

How would I know if this is happening to me?

Mostly you wouldn't, which is the point — that's why it's worth checking rather than waiting for a symptom. The soft signals are worth knowing though: customers who say they never got your quote, replies that arrive days late because someone found the message in a spam folder, or a noticeable gap between how many enquiries your website reports and how many you remember answering. Any of those is worth a look. None of them is proof, and the absence of them isn't proof either.

Isn't this my email provider's job?

They do half of it. Google Workspace or Microsoft 365 will set up records for their own sending when you first configure the domain, and they generally get that part right. What they can't know about is everything else that sends as you — your website's contact form, a booking tool, a newsletter service — because those were added later by someone else. The gap is never the provider's setup; it's everything added after it.

I use a Gmail or Yahoo address for my business. Does any of this apply?

Not in the same way, because those records belong to Google or Yahoo rather than to you, and they're already correct. The thing worth thinking about instead is that the address on your own website is one you don't own — you can't move it, you can't add people to it, and it reads as less established to some customers. If your website is at your own domain, having the email there too is usually a small job with a long payoff.

Can I fix this myself?

The reading part, yes, definitely — it's public and it takes seconds. The changing part depends on whether you're comfortable in your registrar's DNS settings, and honestly on how much is wrong. Adding a missing DMARC record set to watch-only is close to risk-free. Editing an SPF record that several services already depend on is the one to be careful with, because getting it wrong affects mail that currently works. If you're unsure, that's the point to hand it to somebody.

Will fixing these records stop my mail being filtered?

It removes the most common reason for it, and it's the part you control. It isn't the whole story: what's in the message, how your address has behaved in the past, and each receiving company's own rules all get a say, and none of that is visible from outside your mailbox. Think of it as the groundwork — necessary, not sufficient. It's also the only part of the picture you can settle in an afternoon.

Start a project

Ready for a site
that wins the job?

Tell us what you're working with. You'll get a plain-language reply — and if we're not the right fit, we'll say so and point you somewhere good.

Don't like the first design? Take your money back. What it covers

Want the number first? Build an estimate — a minute, and no email needed.

Not ready? Check your Google listing — free, about ten seconds.

Prefer email? contact@theharbortree.com

Tell us what you need

Three fields. Takes about thirty seconds.

No newsletters, no spam — your details go straight to us and nowhere else.