An email that lands in spam is an email that doesn’t exist. Your contact never sees it, never replies, and has no idea your message arrived. For UK businesses, this happens more than most realise. It’s often happening silently too, with no obvious warning until you notice a drop in replies or a client mentions they never received your invoice.
The causes range from simple technical configuration errors to legal compliance gaps. Here’s what’s most likely going wrong, and how to put it right.
Your Email Authentication Records Are Broken
SPF, DKIM, and DMARC are three technical records that prove your emails are genuinely coming from you. They live in your domain’s DNS settings and tell receiving mail servers whether to trust your emails or treat them as suspicious. The National Cyber Security Centre recommends all UK organisations set up these records to keep their emails deliverable and stop their domain being used by fraudsters.
SPF lists the servers that are authorised to send email on your behalf. DKIM adds a digital signature to each email so the receiving server can confirm it hasn’t been tampered with in transit. DMARC ties the two together and instructs receiving servers on what to do when either check fails: allow the email through, quarantine it, or reject it outright.
If these records are missing, incomplete, or haven’t been updated since you last changed email providers or added a new marketing platform, your emails are far more likely to be caught by filters. The NCSC provides a free email security check tool where you can test your domain’s authentication setup in minutes.
Your Domain Has Built Up a Poor Sending Reputation
Email providers score every domain and IP address that sends mail. Your score is your sender reputation, and it applies to every email you send, not just your marketing campaigns.
A few things damage it quickly. Sending to large lists that haven’t been cleaned in a while produces a high bounce rate from invalid addresses, which signals poor list hygiene to receiving servers. Getting marked as spam by recipients is worse. Sending from a free webmail address (Gmail, Hotmail, Outlook.com) rather than your own business domain also raises red flags, because free addresses can’t carry the authentication records a custom domain can.
Prevention is far easier than repair. Once your reputation is damaged, consistent good sending habits (valid authentication, clean lists, low complaint rates) will show improvement over time, but recovery typically takes four to eight weeks of doing things correctly before deliverability meaningfully improves.
The Content or Format of Your Emails Is Getting Them Caught
Modern spam filters don’t just scan for trigger words. They analyse the whole structure of your email: the ratio of text to images, the number of links, the formatting, and whether the technical markers of a legitimate email are present.
Some patterns that still cause problems: emails built almost entirely of images with very little actual text, because filters can’t read images the same way they read copy. Emails with excessive links. Subject lines written in ALL CAPITALS or heavy with punctuation. And emails that don’t include a physical business address or an unsubscribe option.
That last point matters beyond spam filtering. Certain requirements, like including a working unsubscribe mechanism in marketing emails, are not simply good practice. They’re legally required under UK law, which leads on to the next point.
You’re Emailing People Who Haven’t Consented
Sending emails to people who didn’t ask to hear from you doesn’t just damage your reputation with spam filters. It puts you in direct conflict with UK law.
Under the Privacy and Electronic Communications Regulations (PECR), you cannot send marketing emails to individuals without their consent, unless they are an existing customer being contacted about a similar product under the ‘soft opt-in’ rule. The Information Commissioner’s Office fined two companies a combined £225,000 in January 2026 for sending tens of millions of emails and texts without valid consent.
The connection to spam filtering is direct. When people receive emails they didn’t ask for, they hit the spam button. Enough spam complaints and your entire sending domain gets flagged, affecting your everyday business emails as well as your campaigns. The ICO’s guidance on electronic mail marketing explains what valid consent looks like under UK law and what the soft opt-in exemption does and doesn’t cover.
Getting your email marketing consent process right is the foundation everything else builds on.
How to Check Whether Your Setup Is the Cause
The NCSC’s free email security check is the quickest starting point. Enter your domain and it will show you whether your SPF, DKIM, and DMARC records are present and properly configured. If anything is missing or failing, that’s your first fix.
For content, most email platforms include a spam score tool that analyses your email before sending. Use it every time. Flags to look for: a missing unsubscribe link, poor text-to-image balance, too many links, or no physical address. Sort these before you send, not after complaints start arriving.
If your issue looks like sender reputation rather than a configuration error, recovery takes consistent effort over several weeks. Cleaning your contact list, removing bounced addresses, and gradually reducing send volume while engagement recovers are all part of the process. Your IT helpdesk can help if you need to dig into bounce logs or delivery reports and aren’t sure how to read them.
When the Problem Needs IT Support to Fix
Setting up or correcting SPF, DKIM, and DMARC records requires direct access to your domain’s DNS settings. Your IT provider manages these, and getting them wrong can break your email setup entirely. It’s not a place to guess.
If you’ve recently moved to a new email platform, changed hosting provider, or connected a third-party marketing tool, your authentication records may need updating. You might not notice until replies stop arriving. Managed IT support includes keeping your business email infrastructure working correctly: checking records after any changes, making sure new platforms are added to your SPF record, and catching configuration issues before they cause problems.
If you think your email issues are connected to something more serious (for example, clients receiving emails from your domain that you didn’t send), that’s a cyber security issue, not just a deliverability problem. Domain spoofing does happen, and DMARC is the primary technical defence against it. If you suspect it, your IT team needs to know immediately.
Getting your emails delivered reliably isn’t only a marketing task. Your underlying infrastructure has to support it first.
Frequently Asked Questions
Does having SPF, DKIM, and DMARC set up guarantee my emails won’t go to spam?
No. Authentication records prove your emails are coming from your domain, but spam filters also consider your sender reputation, email content, and how recipients engage with your messages. Getting authentication right is the most important technical step, but it needs to sit alongside clean lists, relevant content, and proper consent practices.
Can transactional emails (like invoices or booking confirmations) end up in spam too?
Yes. Authentication failures and a poor sender reputation affect all emails from your domain, not just marketing campaigns. If your DNS records are broken or your domain has been flagged, your invoices, account alerts, and order confirmations are just as likely to be caught as your newsletters. Any business that relies on email for day-to-day operations needs its infrastructure set up correctly.
How do I know if someone is spoofing my business email domain?
DMARC reports are the most direct way to find out. Once DMARC is set up in monitoring mode, you’ll receive data showing every source claiming to send email from your domain. The NCSC’s email security and anti-spoofing guidance explains how to set this up and what to do if you spot unauthorised sources in the reports.
Do I need consent before emailing other businesses?
It depends on the business type. You can email a limited company or LLP without consent under PECR. Sole traders and most partnerships are treated the same as individuals, so you do need consent or to meet the soft opt-in conditions. The ICO’s electronic mail marketing guidance explains clearly which rules apply to each business type.
What’s the difference between an email landing in spam and being rejected?
A spam-filtered email lands in the recipient’s junk folder and they might still see it if they check. A rejected email bounces and never reaches the recipient’s server at all. Rejections are typically caused by strict DMARC policies, IP blocklisting, or sending to invalid addresses. Both outcomes signal a problem, but the cause and the fix are usually different.
How long does it take to recover from a damaged sender reputation?
Most businesses see meaningful improvement within four to eight weeks of consistent good sending practices: valid authentication, a clean contact list, low complaint rates, and relevant content. More severe cases involving a compromised domain or large-scale spam complaints can take longer and may need professional support to resolve properly.
Sort It Before It Costs You
Email is one of the most dependable communication tools a UK business has. When it breaks quietly (messages going nowhere, important conversations never starting) the cost is real and often invisible until you start digging.
If you’re not sure whether your email setup is working correctly, UK IT Services can check your authentication records, review your domain configuration, and flag anything that needs attention. Contact us today for a free IT consultation.