Emails from your website usually go to junk because your web host sends them using your address, such as bookings@yourbusiness.com.au, from a server your SPF record doesn't list and without a DKIM signature. To Outlook and Microsoft 365, that looks the same as someone forging your address, so the email fails its checks and lands in the Junk Email folder.
Why website email is different
When you send email from Microsoft 365, Microsoft's servers send it, and your domain's records say those servers are allowed. Your website is different. A contact form, an online shop or a booking plugin sends email from the web server your site runs on. That server usually belongs to your hosting company, and on shared hosting it sends for many other websites too.
WordPress shows how this happens. Out of the box, it sends email using PHP's built-in mail function on your web server. If nothing else sets a From address, it uses wordpress@ followed by your site's domain. Many form and booking plugins send the same way.
The result is an email that:
- claims to be from yourbusiness.com.au,
- comes from a server your SPF record doesn't list, so SPF fails, and
- carries no DKIM signature for your domain, so DKIM fails too.
With both failing, DMARC fails, and Microsoft's checks treat the email as a likely forgery. This is also why form notifications sent to your own Microsoft 365 inbox can land in your own junk folder.
A second trap: forms that send "from" the visitor
Some contact forms put the visitor's address in the From line, so the enquiry looks like it came from jane@gmail.com. Your web server isn't allowed to send for gmail.com. The big free email providers publish DMARC records, and some tell receivers to reject anything that fails.
Fix this in your form's notification settings:
- From: an address on your own domain, such as website@yourbusiness.com.au.
- Reply-To: the visitor's address, so you can still click Reply.
The fix: send through a proper email service
Option 1: Send through Microsoft 365
If your email is on Microsoft 365, the simplest fix is to send your website's email through it. Use an SMTP plugin (a plugin that sends WordPress email through a real email service). Choose one that connects to Microsoft 365 with a Microsoft sign-in (OAuth). Microsoft recommends this over typing a mailbox password into the plugin, and it is retiring password-only sending.
For example, WP Mail SMTP has a "Microsoft 365 / Outlook.com" mailer. Its documentation says you need the Pro licence or higher, an HTTPS website and an app registration in Microsoft Azure. The From address must be the same mailbox you signed in with, so use a real mailbox, such as website@yourbusiness.com.au. Microsoft limits how much one mailbox can send, at around 10,000 recipients a day. That's plenty for enquiries and booking confirmations, but not for newsletters.
Your email then passes SPF through Microsoft's include, as long as your SPF record has it:
| Type | Name | Value |
|---|---|---|
| TXT | yourbusiness.com.au | v=spf1 include:spf.protection.outlook.com ~all |
Then switch on DKIM for your domain. In the Microsoft Defender portal go to Email & collaboration → Policies & rules → Threat policies → Email authentication settings → DKIM. Select yourbusiness.com.au, add the two CNAME records it shows (selector1 and selector2), then switch on "Sign messages for this domain with DKIM signatures".
Option 2: Use an email sending service
A transactional email service is a company that sends automatic emails for websites and apps. Most SMTP plugins can connect to one. Set it up for your domain:
- Turn on DKIM signing for yourbusiness.com.au in the service, and add the DKIM record it gives you to your DNS. Most services call this "domain authentication".
- Add the service to your SPF record with the include: value from its help pages. Keep one SPF record and add it alongside Microsoft's, like this:
v=spf1 include:spf.protection.outlook.com include:<your service> ~all. - If the service offers a custom bounce or return-path domain, set that up too, so SPF also passes for your own domain.
Option 3: Online booking and hosted form services
If bookings or forms run on another company's platform, look in its settings for "domain authentication" or a "custom sending domain". If it offers one, add the records it gives you. If it doesn't, let it send from its own address with yours as the reply-to. Then your records don't come into it, and the email can't fail them.
What not to do
Don't add your shared web server's IP address to your SPF record. That server sends for other websites too, so you would be letting them all pass SPF as you, and it still wouldn't add DKIM. Only authorise a server directly if you're sure it's yours alone.
Check it worked
Most SMTP plugins have a "send test email" button. Send one to your private test address. To check a form, temporarily set its notification address to your test address, or make a test booking with it. The report shows whether SPF, DKIM, DMARC and alignment pass for yourbusiness.com.au. It also gives a verdict for Outlook.com, Microsoft 365, Gmail, Google Workspace and Yahoo, and the exact record to fix if anything fails.
Checked against: WordPress Developer Resources, wp_mail() · Microsoft Learn, How to set up a multifunction device or application to send email using Microsoft 365 or Office 365 · WP Mail SMTP, How to Set Up the Microsoft 365 / Outlook.com Mailer · Microsoft Learn, How email authentication works in Microsoft 365 · Microsoft Learn, Set up SPF to identify valid email sources for your Microsoft 365 domain.
