Why Mail From Your Own Domain Gets Refused

A white envelope with a crimson wax seal resting on a closed steel mail slot

A business sends a quote. It never arrives. The customer says nothing came, and when they check the junk folder there it is, marked as suspicious.

The instinct is to blame the wording, or the attachment, or the customer's provider. Usually it is none of those. Usually the published records that say who is allowed to send mail using the business's domain name are missing, incomplete, or contradict each other.

Marque & Heir treats this as a records question with a specific order of work. What follows is that method for local businesses across the United States.

Understand the problem in plain terms

Anyone can write any address on an envelope. Email works the same way: a sender can put a business's address in the From line whether or not they have anything to do with it.

Because of that, receiving providers look for published statements from the domain itself, saying which services are permitted to send on its behalf and how a message can be shown not to have been altered. Where those statements are missing or inconsistent, the receiving provider has to guess, and guessing tends toward the junk folder.

There are three of these statements in common use. What they are called matters less than what they do: one lists the services allowed to send, one attaches a verifiable signature to outgoing mail, and one tells receiving providers what to do when a message fails the first two — and can send reports back.

Find out what is published now

Before changing anything, read what the domain currently publishes and save a dated copy in plain text.

This is where most of the surprises are. Common findings: nothing published at all; a list naming a mail provider the business stopped using two years ago; two conflicting entries; a list so long it has stopped being valid; or a strict instruction published without the other pieces in place, which causes legitimate mail to be rejected outright.

Do not tidy anything yet. Record it first.

List everything that sends as the business

This is the step that decides whether the work succeeds, and it is the one that gets rushed.

Write down every service that sends mail using the business's address:

  • The main mail provider.
  • The website's enquiry form.
  • Invoicing or accounting software.
  • Booking or scheduling tools.
  • Any mailing or newsletter service.
  • Review request tools.
  • Anything a supplier sends on the business's behalf.

Ask around, because nobody knows all of these from memory. A missed service is a service whose mail starts failing the moment the records are tightened, and the failure is usually noticed weeks later by a customer.

Do it in the right order, and slowly

The order matters, because a strict instruction published too early breaks working mail.

  1. Get the list complete. Everything that sends.
  2. Publish the list of permitted senders, covering all of them.
  3. Set up signing with each provider that supports it.
  4. Publish the third record in its most permissive form, asking only for reports.
  5. Read the reports for several weeks. They will name senders nobody remembered.
  6. Correct what they reveal.
  7. Only then tighten, in stages, watching after each.

Rushing to step seven is the single most damaging thing that can be done here, and it is what happens when somebody follows a checklist without the list from step one.

Expect the reports to be confusing at first

The reports are machine-readable and they include everything, including legitimate services that were forgotten and unrelated noise.

Read them, but do not act on a single report. Look for patterns over weeks. A service appearing consistently and sending mail the business recognises is one to authorise. A single unrecognised entry is usually noise.

Watch the limits

The record listing permitted senders has technical limits — on how many lookups it can require, and on its length. Businesses with several services hit them, and when they do the record silently stops working.

This matters when adding a new service. It is not a case of appending indefinitely. Check that the record is still valid after any change, and remove entries for services no longer used.

That last part is ordinary housekeeping that never gets done. Every service ever added tends to stay listed forever, which both crowds the limit and leaves old services authorised to send as the business long after the relationship ended.

Remember what it does and does not fix

These records address whether the sender is who they claim to be. They do not make mail interesting, and they do not stop a receiving provider filtering mail for other reasons — the way it is written, the links in it, whether people mark it as unwanted, or the reputation of the sending service.

So this work removes a specific and common cause of non-delivery. It does not guarantee delivery, and nobody can. Any provider claiming otherwise is claiming control over decisions made by other companies.

Check it after anything changes

These records go stale silently. Changing mail provider, adding a mailing tool, rebuilding the website's form, or taking on a service that sends on the business's behalf all affect them.

Name the person who checks, and make it part of adding any new service. Then check on a schedule anyway, because things get added without anyone thinking of it.

What this work does not include

It does not include guaranteeing delivery to any inbox, controlling how any receiving provider treats a message, or improving mail that is filtered on its contents. Where mail is being refused for reasons beyond sender authorisation, that is a separate question.

If mail from a business has started going quiet, the free business check can read what the domain currently publishes about who may send on its behalf and report what is there — which, more often than not, is either nothing or something out of date.

Watch what happens after a big send

The records matter most at the moment the business sends more mail than usual — a set of invoices, a seasonal note to past customers, a batch of quotes.

That is when a receiving provider is most likely to look closely, and when a gap in the published records turns from a background risk into a visible failure. So do this work before any planned send, not after somebody reports that the batch did not arrive.

Afterwards, check the reports for that period specifically. A send that went out through a service not covered by the published list will show there, and it is easier to spot against a spike than in ordinary traffic.

Where a business sends anything in volume, it is worth checking the records before every such send as a matter of routine. It takes a minute and it catches the change nobody mentioned.

← All posts