Synthetic Industry

Job email-spf-dkim-dmarc-business-mail-in-spam · revised 9 October 2026

Set up SPF, DKIM and DMARC for business mail going to spam

Authenticate mail from your domain across your mailboxes and up to three other sending tools. Check headers and DMARC reports; inbox placement cannot be guaranteed.

You might be seeing

  • Customers find your quotes or invoices in their spam or junk folder
  • Bounce messages mentioning SPF, DKIM, DMARC or “not authenticated”
  • Gmail shows “Be careful with this message” on mail from your own domain
  • Mail sent by your invoicing or booking system arrives, but mail from your mailbox doesn't, or the other way round

No passwords, keys, card details or admin invites needed to start.

What usually happened

Your domain doesn't tell receiving mail servers which services may send on its behalf. Some senders have no SPF entry, DKIM signing was never switched on, or there are two clashing SPF records, so Gmail and Outlook can't verify that the mail is really yours and file it as junk or refuse it. Since 2024 the big providers have tightened these checks.

Who it’s for: Owner or office manager of a small business that sends quotes, invoices and replies from its own domain, with nobody technical looking after the domain.

Usually starts when: Customers say your emails went to spam or never arrived, Gmail or Outlook bounces a message with an authentication error, or you add an invoicing, booking or newsletter tool that sends as your domain.

The result: Mail from each agreed sender passes an aligned authentication check in a Gmail and Outlook.com test message; your domain publishes a monitoring DMARC policy and you receive a two-week report review. Inbox placement is not guaranteed.

Check whether this job fits

Five questions, about two minutes. Your answers stay on this page unless you choose to email them.

Do you send from your own domain, such as you@yourbusiness.co.uk?
Who can change your domain's DNS records?

DNS is managed wherever the domain's nameservers point: often your registrar, your web host or Cloudflare.

How many different tools send email as your domain?

Count your mailboxes as one, then add each invoicing, booking, shop, newsletter or website form that sends as your domain.

What kind of email is going missing?
Has anyone reported spam sent from your address that you didn't write, or has your host warned you about outgoing spam?

Answer the questions to see whether this job fits.

Nothing is sent anywhere until you choose to email us.

Email us your answers

Checks you can run yourself

  1. See whether your domain has SPF and DMARC records

    On a Mac or Linux terminal, run these two read-only lookups with your own domain. On Windows, use nslookup -type=TXT, or any public DNS lookup website.

    dig +short TXT yourbusiness.co.uk; dig +short TXT _dmarc.yourbusiness.co.uk

    Look for: One line starting v=spf1, and one starting v=DMARC1. No v=spf1 line means no SPF; two of them is an error; no v=DMARC1 line means no DMARC.

  2. Read the verdict on a message you sent

    Send an email from your business address to a personal Gmail account, open it, and choose Show original from the three-dot menu.

    Look for: SPF, DKIM and DMARC each marked PASS or FAIL near the top. A FAIL, or DKIM signed by a domain other than yours, is what this job fixes.

What you get

  • A table of every sending service found, with its SPF, DKIM and DMARC result before and after
  • The exact DNS records to add or change, written for whoever edits your domain
  • Header evidence from test messages to Gmail and Outlook.com for each agreed sender
  • A short note after two weeks of reports: anything still failing, and whether to move DMARC from monitoring to quarantine

Included

  • An owner-supplied inventory of every known service that sends as your domain, checked against DNS and available DMARC reports; reports alone do not list every legitimate sender
  • One correct SPF record within the 10-lookup limit
  • DKIM switched on and published for each agreed sender, signed with your own domain
  • A DMARC record that starts by monitoring, with reports sent to a mailbox you choose
  • One review of the first two weeks of DMARC reports, and a recommendation on tightening the policy

Not included

  • Mailing-list hygiene, bought lists or cold-email campaigns
  • Getting your server's IP address removed from a blocklist after a compromise
  • Moving mailboxes to a new email provider
  • Fixing the code of a website form that sends with PHP mail(): that is a separate job
  • Ongoing monitoring of DMARC reports after the two-week review

How we know it’s done

Agreed with you before work starts. Each check produces evidence you keep.

  1. Public DNS returns exactly one SPF record for the domain, with no more than 10 DNS lookups, and a DMARC record with reports addressed to your mailbox

    Evidence: Output of the DNS lookups before and after

    dig +short TXT yourbusiness.co.uk; dig +short TXT _dmarc.yourbusiness.co.uk
  2. A test message from each agreed sender to Gmail and Outlook.com shows DMARC pass through aligned SPF or DKIM, with DKIM also passing where the sender supports it

    Evidence: The Authentication-Results header from each message

  3. Each test message is accepted by Gmail and Outlook.com without an authentication bounce; we record its actual Inbox or Junk placement without promising it will always remain there

    Evidence: Screenshot of the inbox and the message headers

  4. After about two weeks, DMARC reports show each agreed sender passing, and any unknown sender is listed with a recommendation

    Evidence: Summary table of the reports for the period

Sign-off. You sign off after the sender tests and the included two-week report review are complete; we record anything that still fails rather than treating a monitoring policy as a deliverability guarantee.

If it fails. If authentication for an agreed, DKIM-capable sender still fails after the approved DNS records are entered, you do not pay. Provider reputation or filtering outside authentication is not an acceptance failure.

When it fits, and when we stop

It fits when

  • You send from your own domain, such as you@yourbusiness.co.uk, not a free Gmail or Outlook.com address
  • Someone can add or change DNS records for the domain, or can say who holds the domain account
  • The services that send as your domain are ones you use and can log in to, up to the agreed number
  • The problem is legitimate business mail being filtered, not marketing to people who didn't ask for it

We stop and tell you if

  • The domain is held by someone who won't make changes or hand it over
  • Mail is being rejected because your server or account was compromised and is sending spam
  • Messages are bulk marketing to bought or scraped lists
  • A sending service can't sign with your domain and can't be replaced: we tell you which one and why

What could go wrong

The handover lists every record and its previous value. Your domain holder can restore those values, but cached answers may persist until their TTL expires. The agreed DMARC policy is monitoring-only; moving to enforcement requires separate authorisation.

Scroll the table sideways to read it all.

RiskHow we handle it
A missed sending service starts failing once SPF or DMARC is tightenedDMARC starts in monitoring mode, which blocks nothing, and the two-week report review finds senders we didn't know about before any stricter policy.
An SPF record with too many lookups breaks SPF for everythingWe count lookups before handover and the independent reviewer re-checks the count.
A typing mistake when entering a recordWe give copy-and-paste values and re-check the live records from outside before signing off.
DMARC reports contain the addresses of mail servers and some message metadataReports go to a mailbox you own. We read only what's needed and keep no copies after sign-off.

A second reviewer checks the full record set against each sending provider's published instructions, and checks that nothing legitimate would fail, before your domain holder applies it.

How we deliver

We arrange the work and independent review, then show you the result against the agreed checks. You keep authority over your systems.

  • Read the domain's current public DNS records and the headers of a test message from each sender
  • List every sending service and record its SPF, DKIM and DMARC result
  • Write one SPF record within the lookup limit, the DKIM records each service gives, and a monitoring DMARC record
  • Independent review of the full record set against each provider's own instructions before anything is changed
  • Your domain holder enters the records; we re-test every sender to Gmail and Outlook.com
  • After two weeks, read the DMARC reports and recommend whether to tighten the policy

This is a one-off job, not emergency cover or a subscription. We confirm eligibility, the total price, a start window and a delivery date before you accept. Work starts only after agreed inputs, secure access, any licences and necessary permissions are in place. Hosting, platform and supplier charges are excluded unless the written quote includes them. No charge or booking is created by an enquiry.

Need to keep it working?

If you add senders regularly, discuss ongoing DMARC report review and checks before each new sending service is enabled.

Ongoing work is separately scoped and quoted: no monitoring, response-time guarantee or automatic subscription is included in this job.

Explore an ongoing engineering lane, or mention the responsibility you need in your enquiry.

What you can check

This is a new service. We have not delivered this job for a client yet.

Other ways to get this done

  • Google Workspace and Microsoft 365 publish step-by-step guides for their own SPF, DKIM and DMARC records. If your mailboxes are the only thing sending, you or your IT firm may manage with those. support.google.com
  • Some DMARC report services have free tiers that turn the daily reports into a readable dashboard, which helps if you want to keep watching after this job.

Questions

Do you need my email or domain password?

No. We work from public DNS and test messages. Whoever already manages your domain enters the records we give them.

Will this guarantee my emails never go to spam?

No. Providers also judge content, reputation and how recipients react. This job checks that your domain is authenticated and records inbox placement during the test; it does not promise future inbox delivery.

Will setting up DMARC block my own emails?

Not at first. We start with a monitoring policy that blocks nothing and only reports, then recommend tightening it once every real sender passes.

Our website's contact form emails don't arrive either. Is that included?

Only if the form already sends through a proper mail service. If it uses the server's built-in PHP mail function, it needs a code change, which is a separate job.

Start with an email

Send us

  • Your domain name
  • Who provides your mailboxes: Google Workspace, Microsoft 365, your web host or another provider
  • Every tool you know of that sends email as your domain, such as invoicing, booking, shop or newsletter software
  • A bounce message or a customer's description of where your mail landed, with personal details removed
  • Who can edit the domain's DNS: you, your web host, an IT firm or a former web designer

Later, once you agree

  • One test message from each agreed sender to test inboxes we give you
  • Screenshots or an export of the domain's current DNS records, if the provider allows it
  • A mailbox or alias for DMARC reports, such as dmarc@yourbusiness.co.uk
  • A company-controlled secure handoff agreed before access: no live passwords, keys, private code or customer records by ordinary email.

You keep the domain account, mailboxes and sending tools. AI agents prepare and test the record set; a separate reviewer checks it. Whoever holds your domain enters or removes the records. Synthetic Industry is owned by a person and remains accountable for the agreed work.

Enquire — £195 fixed price

Or write to hello@syntheticindustry.ai with “email-spf-dkim-dmarc-business-mail-in-spam” as the subject.