If emails you send are landing in people's spam folders or being rejected, the most common cause is missing or incorrect SPF, DKIM or DMARC records. Gmail, Outlook and Yahoo now expect all three, so setting them up is one of the best things you can do for deliverability.

What they do

  • SPF lists the servers allowed to send email for your domain.
  • DKIM adds a digital signature to every email so the receiver can check it really came from you and wasn't changed.
  • DMARC tells receivers what to do with email that fails SPF or DKIM, and can send you reports.

1. Check and fix SPF and DKIM in cPanel

  1. Log in to cPanel from your service page under Services → My Services (https://www.hooplahosting.co.nz/client/clientarea.php?action=services).
  2. Open Email Deliverability (type it in the cPanel search bar).
  3. Each domain is listed with its status. If a domain shows a problem, click Manage.
  4. If your DNS is hosted with us (you use our nameservers), click Repair next to SPF and DKIM and cPanel will fix the records for you.
  5. If your DNS is managed somewhere else, such as your domain registrar or Cloudflare, cPanel shows the exact records you need. Copy them into your DNS provider. Not sure where your DNS is? See Where is my DNS managed?

Only one SPF record. A domain must have a single SPF record. If you also send email through another service, such as Microsoft 365, Google Workspace, Mailchimp or your accounting software, it needs to be included in that same record, not added as a second one. Each service publishes the include: value to add.

2. Add a DMARC record

If your DNS is with us:

  1. In cPanel, open Zone Editor and click Manage next to your domain.
  2. Click Add Record and choose TXT.
  3. Name: _dmarc.yourdomain.co.nz
  4. Value: v=DMARC1; p=none; rua=mailto:you@yourdomain.co.nz (replace the email address with one you check).
  5. Save the record.

If your DNS is elsewhere, add the same TXT record with your DNS provider.

p=none is the safe place to start. It doesn't block anything, it just lets you receive reports so you can confirm all your legitimate email passes. Once you're confident everything is set up correctly, you can change it to p=quarantine (send failures to spam) or p=reject (refuse them).

3. Test it

DNS changes can take a few hours to take effect. After that, send a test email to a Gmail account, open it, and choose Show original. SPF, DKIM and DMARC should all show PASS.

Still landing in spam?

  • If you send from a website contact form, set it up to send through your email account with SMTP. Emails sent directly by PHP are more likely to be flagged.
  • Avoid sending bulk newsletters from your hosting account. Use a dedicated service such as Mailchimp or Brevo, and include it in your SPF record. See How many emails can I send per hour?
  • If your account has been sending spam because of a compromised form or password, see Outgoing spam detected on my account.

If you'd like us to check your records, open a support ticket with the domain name and an example of an email that went to spam.

Was this answer helpful? 0 Users Found This Useful (0 Votes)