Your emails usually go to junk because Outlook, Hotmail or Microsoft 365 can't confirm they really came from your business. In most cases one of three DNS records (SPF, DKIM or DMARC) is missing, broken, or set up for a different service from the one that actually sends your email.
How Outlook decides what goes to junk
Every email has a From address, such as accounts@yourbusiness.com.au. Anyone can type any From address, so receivers look for proof. They check records your domain publishes in DNS (the settings that tell the internet where your website and email live).
- SPF is a list of the servers allowed to send email for your domain.
- DKIM is a digital signature that proves an email came from your domain and wasn't changed on the way.
- DMARC tells receivers what to do with email that claims to be from your domain but fails SPF and DKIM, and sends you reports about it.
Microsoft combines these results with other signals, such as your sending history, into one verdict it calls composite authentication. If the proof is missing, or it points to someone else's domain instead of yours, your email can fail that check and land in the Junk Email folder, even when there is nothing wrong with what you wrote.
The most common causes
1. No SPF record, or a broken one
Without an SPF record, receivers can't tell whether the server that sent your email was allowed to. A broken record is just as bad: receivers stop reading it and treat SPF as failed. The usual faults are two SPF records instead of one, a typo in an include:, or a record that needs more than 10 DNS lookups.
If you only send email from Microsoft 365, your record looks like this:
| Type | Name | Value |
|---|---|---|
| TXT | yourbusiness.com.au | v=spf1 include:spf.protection.outlook.com ~all |
Keep only one SPF record. If you already have one, add the new include: to it rather than creating a second record.
2. DKIM isn't switched on
Microsoft 365 doesn't sign your email with your own domain until you switch DKIM on. Until then, your email is either unsigned or signed with your ...onmicrosoft.com address, and neither counts for yourbusiness.com.au.
To fix it: in the Microsoft Defender portal go to Email & collaboration → Policies & rules → Threat policies → Email authentication settings → DKIM. Select yourbusiness.com.au, add the two CNAME records it shows (selector1 and selector2), then switch on "Sign messages for this domain with DKIM signatures".
3. No DMARC record
Without DMARC, receivers have no instructions from you, and Microsoft's rules for high-volume senders treat a missing record as a failure. Add this record. It starts in monitoring mode (p=none), so nothing changes for your email yet. Change the rua address to a mailbox you read; once reports show all your genuine email passing, move to p=quarantine.
| Type | Name | Value |
|---|---|---|
| TXT | _dmarc.yourbusiness.com.au | v=DMARC1; p=none; rua=mailto:dmarc-reports@yourbusiness.com.au |
4. A service sends for you in its own name
This is the cause people miss most often. Your invoices, newsletters, website forms and booking confirmations are often sent by other companies' servers, using your address. Each one has to be set up for your domain.
DMARC needs SPF or DKIM to pass for your own domain, not just the service's. That match is called alignment. A service can pass SPF for its own bounce address and sign DKIM with its own domain. Both checks say "pass", but neither one is for yourbusiness.com.au, so DMARC still fails.
The fix is in the service's settings. Turn on DKIM signing for yourbusiness.com.au in the service that sends the email, and add the DKIM record it gives you to your DNS. Most services call this "domain authentication". Some services, such as Xero and MYOB, send from their own address instead, with yours as the reply-to. In that case your records aren't checked at all. Our Xero and MYOB guides explain what you can do.
5. Your domain is new
Microsoft also looks at sender history. A domain registered last month has none, so filters are more cautious with it. Get SPF, DKIM and DMARC right before you start sending, and build up with normal one-to-one email before you send to a long list.
6. Content and links (less often)
For most small businesses, content isn't the main cause. It can tip a borderline email over, though. Watch for shortened links, links to a site that has been used for spam, and emails that are just one big image or an attachment with no text.
What your customers can do in the meantime
Ask anyone who finds your email in junk to mark it as not junk. That teaches their mailbox to trust you. It doesn't fix the cause, so your next new customer will have the same problem.
How to find out which cause is yours
Send one email to your private test address from the mailbox or service that's landing in junk. We check SPF, DKIM, DMARC, alignment and each provider's sender rules. Then we give you a verdict for Outlook.com, Microsoft 365, Gmail, Google Workspace and Yahoo, with the exact record to add or change for yourbusiness.com.au.
Test each way you send separately: your Microsoft 365 mailbox, an invoice from your accounting software, and a message from your website form. Each one sends differently, and each can fail for a different reason.
The free test covers one domain every 30 days. Your report stays online for 7 days, and we email you a copy.
Checked against: Microsoft Learn, How email authentication works in Microsoft 365 · Microsoft Learn, Set up SPF to identify valid email sources for your Microsoft 365 domain · Microsoft Learn, How to use DKIM for email in your custom domain · Microsoft Learn, Set up DMARC to validate email in Microsoft 365.
