Skip to main content
web-development

Why Your Business Emails Go to Spam in Kenya: SPF, DKIM and DMARC Explained

Clients finding your quotes in spam? Learn why business email from Kenyan domains lands in junk, what SPF, DKIM and DMARC do, what Gmail and Outlook now require, and a step by step fix.

Mocky Digital
September 26, 2026
11 min read

You send a quotation to a new client, follow up two days later, and hear "Sorry, it was in my spam folder." If that sounds familiar, you are not alone. Business email going to spam in Kenya is one of the most common problems we see with companies that use their own domain, whether the domain is a .co.ke, a .com or a .ke. The good news is that the cause is usually technical, it can be checked in minutes, and it can be fixed without changing your email address.

If you searched for "business email going to spam Kenya", this guide explains why it happens, what SPF, DKIM and DMARC actually do, how to check your own domain, and a step by step fix you can hand to whoever manages your DNS.

Why business emails land in spam

Gmail, Outlook and other mailbox providers decide where a message goes by asking a few questions. Is this sender who they say they are? Has this domain behaved well in the past? Do recipients want these messages? When the answers are unclear, the safe choice for the provider is the spam folder, or outright rejection.

The usual causes for Kenyan businesses fall into five groups:

1. Missing or broken authentication records. Your domain has no SPF, DKIM or DMARC record, or the records exist but contain errors. 2. Senders you forgot about. Your website contact form, accounting software, CRM, bulk email tool or a developer's server sends mail "from" your domain without being listed in your records. 3. A damaged sending reputation. A shared server that other customers abuse, a hacked mailbox that sent spam overnight, or a sudden burst of cold emails can all drag your reputation down. 4. Complaints and poor engagement. When recipients mark your messages as spam, providers notice. 5. Content and formatting issues. Image-only emails, link shorteners, misleading subject lines and attachments with unusual file types raise suspicion, although content is rarely the main problem once authentication is correct.

For most small and medium businesses, the first two groups explain the majority of spam complaints. That is why authentication is where you should start.

SPF, DKIM and DMARC explained in plain language

These three records live in your domain's DNS, the same place that tells the internet where your website and mailboxes are. Together they prove your mail is genuine.

SPF: who is allowed to send

SPF (Sender Policy Framework) is a TXT record that lists the servers allowed to send email for your domain. A simple record looks like this:

`v=spf1 include:_spf.yourmailprovider.com ~all`

Two rules trip up many businesses. First, a domain must have only one SPF record. The SPF standard, RFC 7208, says a domain must not publish multiple SPF records, and a receiver that finds more than one returns a "permerror", which means the check fails. This often happens when a new email provider is added and someone creates a second SPF record instead of editing the first.

Second, SPF evaluation is limited to 10 DNS lookups. Mechanisms such as include, a, mx, ptr, exists and the redirect modifier each count towards that limit, while ip4, ip6 and all do not. Add your email host, your bulk email tool, your CRM and your website host, and you can pass 10 without noticing. Once you do, the result is again a permerror.

DKIM: was the message changed

DKIM (DomainKeys Identified Mail) adds a digital signature to every message your mail server sends. The matching public key sits in your DNS. The receiving server checks the signature against that key, which proves the message came from an authorised system and was not altered along the way. Your email host generates the DKIM key, and you publish it as a TXT or CNAME record at a name such as `selector._domainkey.yourcompany.co.ke`.

DMARC: what to do when checks fail

DMARC ties SPF and DKIM to the address people actually see in the From line, and tells receivers what to do when a message fails. The record is published as a TXT record at `_dmarc.yourcompany.co.ke`. It has three policy options:

  • `p=none`: take no special action, just send me reports.

  • `p=quarantine`: treat failing mail as suspicious, usually by placing it in spam.

  • `p=reject`: refuse failing mail.

The key idea in DMARC is alignment. The domain in your From address must match the domain that passed SPF or the domain that signed with DKIM. A message can pass SPF on your email provider's domain and still fail DMARC because it is not aligned with yours.

DMARC was updated in May 2026, when RFC 9989 replaced the older RFC 7489 specification. The three policy values stay the same. The old "pct" tag was removed, and new tags were added, including "t" for test mode and "np" for non-existent subdomains. If an older guide tells you to roll out DMARC with pct=10, check with your provider before copying it.

What Gmail and Outlook now require

This is no longer optional good practice. According to Google's email sender guidelines, everyone sending to personal Gmail accounts must set up SPF or DKIM, have valid forward and reverse DNS for their sending servers, use a TLS connection, and keep the spam rate reported in Postmaster Tools below 0.3%.

Senders of more than 5,000 messages a day to Gmail personal accounts must do more. They need SPF and DKIM and DMARC, their From domain must align with SPF or DKIM, and marketing messages must support one-click unsubscribe. A DMARC policy of none is acceptable for this requirement.

Microsoft introduced similar rules for Outlook.com, Hotmail.com and Live.com. Since 5 May 2025, domains sending more than 5,000 emails a day to those addresses must pass SPF and DKIM and publish DMARC at least at p=none, aligned with SPF or DKIM. Non-compliant messages are rejected with the error "550; 5.7.515 Access denied, sending domain does not meet the required authentication level."

Most Kenyan SMEs send far fewer than 5,000 emails a day, so the bulk rules may not apply to you directly. But the same checks feed into how every message is filtered, and a newsletter sent through a bulk tool can easily cross the threshold on a busy day. Treat the high-volume rules as the standard to aim for.

How to check your domain in 10 minutes

You do not need to be technical to find out where you stand.

1. Send a test email to a Gmail address. Open it, click the three dots, then "Show original". Gmail shows SPF, DKIM and DMARC results at the top, each marked PASS, FAIL or NONE. 2. Look up your DNS records. Use your registrar's DNS panel or any public DNS lookup tool. Search for TXT records on your root domain (for SPF) and on `_dmarc.yourdomain` (for DMARC). 3. Count your SPF records. If you see two records starting with `v=spf1`, that is a problem to fix today. 4. List everything that sends as you. Think about your website forms, invoicing system, CRM, bulk email platform, point of sale receipts and any app a developer built for you. Each one needs to be covered by SPF or sign with DKIM for your domain. 5. Check blocklists and reputation. If your mail is authenticated but still lands in spam, check whether your sending IP address or domain appears on a public blocklist, and sign up for Google Postmaster Tools to see how Gmail rates your domain.

If a mailbox was recently hacked, change the password, turn on two-step verification and check forwarding rules before anything else. No DNS change will fix mail that an attacker is still sending.

Step by step fix for emails landing in spam

Here is the order we recommend for SPF DKIM DMARC setup on a typical Kenyan business domain:

1. Confirm who hosts your email. Your email provider publishes the exact SPF include and DKIM records you need. Do not guess them. 2. Merge into one SPF record. Combine every legitimate sender into a single record. If you are close to 10 lookups, remove services you no longer use, or ask your provider about alternatives. 3. Turn on DKIM for every sender. Enable signing in your mail host, and in each third-party tool that supports custom domain signing, then publish their keys. 4. Publish a DMARC record at p=none with reporting. A starter DMARC record Kenya businesses can adapt looks like this: `v=DMARC1; p=none; rua=mailto:dmarc@yourcompany.co.ke`. The rua address receives daily aggregate reports showing which servers send as your domain and whether they pass. 5. Read the reports for two to four weeks. Fix any legitimate sender that fails. As a rule of thumb, wait until your known senders pass consistently before tightening. 6. Move to p=quarantine, then p=reject. This is the step that actually stops criminals from sending invoices "from" your domain, which matters a lot given how common payment redirection fraud is. 7. Clean up sending habits. Send from a real address people can reply to, avoid buying lists, warm up new domains slowly, and include a clear unsubscribe option in marketing messages.

If your website contact form sends mail using the server's built-in mail function, route it through your authenticated mail server or a transactional email service instead. Unauthenticated form mail is one of the most common reasons an otherwise healthy domain gets flagged.

Email deliverability Kenya checklist: local points to watch

A few situations come up again and again with local businesses:

  • DNS managed in a different place from email. Many .co.ke domains are registered with one company, hosted with another, and use email from a third. Records must be added wherever the domain's nameservers point, not where you pay for email.

  • Cheap shared hosting mail. Free mailboxes bundled with a shared hosting plan often share IP addresses with hundreds of other sites. If one of them sends spam, everyone suffers.

  • Staff forwarding to personal Gmail. Automatic forwarding can break SPF and trigger DMARC failures. Give staff proper mailboxes on phones instead.

  • Changing providers without updating DNS. After an email migration, the old provider's SPF and DKIM records often stay behind while the new ones are never added. Our guide to setting up custom domain email in Kenya walks through a clean setup.

When to get help

If the steps above feel like a lot, you can hand the job over. Every mailbox on our business email hosting plans comes with spam and virus filtering, and SPF, DKIM, DMARC and MTA-STS set up for you. Your portal shows the DNS records to add and checks them live, and a done-for-you setup option is available if you would rather not touch DNS at all. Plans are billed per mailbox per year in KES and paid with M-Pesa.

If the problem is your website or server rather than your mailboxes, our website care plans cover ongoing maintenance, and our cloud infrastructure service handles server setup, hardening and migration. And if your newsletters are what keep landing in spam, our digital marketing team can help you rebuild a permission-based email list.

Frequently asked questions

Why do my emails go to spam even when SPF, DKIM and DMARC pass?

Authentication proves who you are, not that recipients want your mail. Check your reputation in Google Postmaster Tools, look for blocklist listings, review complaint rates and make sure your content and sending volume look normal.

Can I have two SPF records if I use two email services?

No. The SPF standard says a domain must not publish multiple SPF records, and receivers treat that as an error. Merge both services into one record.

Should I start DMARC at p=reject?

Not usually. Start at p=none with reports so you can find every legitimate sender first. Jumping straight to reject can block your own invoices, receipts or website forms.

Do the Gmail and Outlook bulk sender rules apply to small businesses?

The extra rules apply to senders of more than 5,000 messages a day to Gmail personal accounts or to Outlook.com, Hotmail.com and Live.com addresses. Smaller senders still need at least SPF or DKIM for Gmail, and meeting the full standard improves delivery for everyone.

How long does it take for DNS changes to fix spam problems?

DNS updates usually spread within hours, although it depends on the record's time to live setting. Authentication failures stop as soon as the new records are visible, but a damaged reputation can take longer to recover.

Will switching to a paid email host stop my emails landing in spam?

It helps when the host sets up authentication properly and runs well-managed servers, but you still need to cover every other system that sends as your domain.

The bottom line

Emails landing in spam are rarely bad luck. In most cases your domain is missing one of three DNS records, has two SPF records fighting each other, or has a forgotten system sending mail without permission. Check your headers, fix SPF, turn on DKIM, publish DMARC and tighten it over time. Your quotations, invoices and follow ups will start reaching the inbox again, and criminals will find it much harder to impersonate your business.

Share this article

Ready to Start Your Project?

Tell us what you need designed, built, or printed. We will reply with a clear price and timeline.