Why are emails from my website going to junk?

Updated 9 October 2026 · 4 min read

A small-business owner checking enquiries on her laptop in her studio

Emails from your website usually go to junk because your web host sends them using your address, such as bookings@yourbusiness.com.au, from a server your SPF record doesn't list and without a DKIM signature. To Outlook and Microsoft 365, that looks the same as someone forging your address, so the email fails its checks and lands in the Junk Email folder.

Why website email is different

When you send email from Microsoft 365, Microsoft's servers send it, and your domain's records say those servers are allowed. Your website is different. A contact form, an online shop or a booking plugin sends email from the web server your site runs on. That server usually belongs to your hosting company, and on shared hosting it sends for many other websites too.

WordPress shows how this happens. Out of the box, it sends email using PHP's built-in mail function on your web server. If nothing else sets a From address, it uses wordpress@ followed by your site's domain. Many form and booking plugins send the same way.

The result is an email that:

  • claims to be from yourbusiness.com.au,
  • comes from a server your SPF record doesn't list, so SPF fails, and
  • carries no DKIM signature for your domain, so DKIM fails too.

With both failing, DMARC fails, and Microsoft's checks treat the email as a likely forgery. This is also why form notifications sent to your own Microsoft 365 inbox can land in your own junk folder.

A second trap: forms that send "from" the visitor

Some contact forms put the visitor's address in the From line, so the enquiry looks like it came from jane@gmail.com. Your web server isn't allowed to send for gmail.com. The big free email providers publish DMARC records, and some tell receivers to reject anything that fails.

Fix this in your form's notification settings:

  • From: an address on your own domain, such as website@yourbusiness.com.au.
  • Reply-To: the visitor's address, so you can still click Reply.

The fix: send through a proper email service

Option 1: Send through Microsoft 365

If your email is on Microsoft 365, the simplest fix is to send your website's email through it. Use an SMTP plugin (a plugin that sends WordPress email through a real email service). Choose one that connects to Microsoft 365 with a Microsoft sign-in (OAuth). Microsoft recommends this over typing a mailbox password into the plugin, and it is retiring password-only sending.

For example, WP Mail SMTP has a "Microsoft 365 / Outlook.com" mailer. Its documentation says you need the Pro licence or higher, an HTTPS website and an app registration in Microsoft Azure. The From address must be the same mailbox you signed in with, so use a real mailbox, such as website@yourbusiness.com.au. Microsoft limits how much one mailbox can send, at around 10,000 recipients a day. That's plenty for enquiries and booking confirmations, but not for newsletters.

Your email then passes SPF through Microsoft's include, as long as your SPF record has it:

TypeNameValue
TXTyourbusiness.com.auv=spf1 include:spf.protection.outlook.com ~all

Then switch on DKIM for your domain. In the Microsoft Defender portal go to Email & collaboration → Policies & rules → Threat policies → Email authentication settings → DKIM. Select yourbusiness.com.au, add the two CNAME records it shows (selector1 and selector2), then switch on "Sign messages for this domain with DKIM signatures".

Option 2: Use an email sending service

A transactional email service is a company that sends automatic emails for websites and apps. Most SMTP plugins can connect to one. Set it up for your domain:

  1. Turn on DKIM signing for yourbusiness.com.au in the service, and add the DKIM record it gives you to your DNS. Most services call this "domain authentication".
  2. Add the service to your SPF record with the include: value from its help pages. Keep one SPF record and add it alongside Microsoft's, like this: v=spf1 include:spf.protection.outlook.com include:<your service> ~all.
  3. If the service offers a custom bounce or return-path domain, set that up too, so SPF also passes for your own domain.

Option 3: Online booking and hosted form services

If bookings or forms run on another company's platform, look in its settings for "domain authentication" or a "custom sending domain". If it offers one, add the records it gives you. If it doesn't, let it send from its own address with yours as the reply-to. Then your records don't come into it, and the email can't fail them.

What not to do

Don't add your shared web server's IP address to your SPF record. That server sends for other websites too, so you would be letting them all pass SPF as you, and it still wouldn't add DKIM. Only authorise a server directly if you're sure it's yours alone.

Check it worked

Most SMTP plugins have a "send test email" button. Send one to your private test address. To check a form, temporarily set its notification address to your test address, or make a test booking with it. The report shows whether SPF, DKIM, DMARC and alignment pass for yourbusiness.com.au. It also gives a verdict for Outlook.com, Microsoft 365, Gmail, Google Workspace and Yahoo, and the exact record to fix if anything fails.

Checked against: WordPress Developer Resources, wp_mail() · Microsoft Learn, How to set up a multifunction device or application to send email using Microsoft 365 or Office 365 · WP Mail SMTP, How to Set Up the Microsoft 365 / Outlook.com Mailer · Microsoft Learn, How email authentication works in Microsoft 365 · Microsoft Learn, Set up SPF to identify valid email sources for your Microsoft 365 domain.

Questions people ask

Why do my form emails reach Gmail but go to junk in Outlook?

Each provider weighs things differently. Microsoft leans heavily on whether an email can be matched to the domain in its From address. Unsigned email from a shared web server that claims to be from your domain often fails that check, even when another provider lets it through.

Can my web host fix this for me?

Some hosts offer an authenticated mail service with DKIM for your domain. Ask them for the SPF include and DKIM record to add. If your email is already on Microsoft 365, sending your website's email through Microsoft 365 is usually simpler.

Should I just add my web server to my SPF record?

Only if the server is yours alone. On shared hosting, the same server sends for many other websites, and adding it lets all of them pass SPF as you. It also doesn't add a DKIM signature, so you're better off sending through a proper email service.

Do I need a paid plugin?

Not always. Many SMTP plugins are free for basic use, but connecting to Microsoft 365 with a Microsoft sign-in is a paid feature in some of them. Check the plugin's documentation before you buy.