You sent the quote on a Friday afternoon. No reply came. On Monday you sent it again, added a polite line, and again nothing came back.
Three weeks later a phone call clears it up: the other side was waiting for your message exactly the way you were waiting for their answer. Both messages exist. They are sitting in a spam folder nobody opens.
This failure eats exactly the messages that were going to earn money: quotes, invoices, replies to enquiries. And it gives you no sign at all that it is happening.
A silence that is not an answer
When a message cannot be delivered because the address does not exist, you get a notice back. The notice is ugly, it is in English and it is full of numbers, but it exists. You know something went wrong, and usually you can work out what.
A message filed as spam does none of that. It was accepted. Technically everything went fine. The only thing that happened is that the receiving mail program decided to put it in a different folder. In your sent items there is a line that looks exactly like every other line.
That is why "I sent it again and it still did not arrive" is such an ordinary sentence. The second message travels the same road, from the same server, with the same settings. If the first one was filtered, the second and the third almost certainly will be too. Sending again is not a new attempt, it is the same attempt several times in a row. And the other side is not ignoring you, they never saw it.
Why the receiving side is suspicious at all
To understand why your message gets checked, you have to know one uncomfortable thing about email: the sender line is not evidence.
Email was built when the network was mostly universities and everybody knew everybody. The sender address is just a field inside the message, rather like a name written on the back of an envelope. Anybody at all can put your company's address there and send a message you did not send.
They need neither your password nor access to your mailbox.
And people do it every day, because it works. A message that appears to come from a company you know gets opened. An invoice that appears to come from your own accountant gets paid. That is why receiving servers started asking for proof.
So these checks are not aimed at you. They exist because your domain's good name is worth stealing, and the only defence is for you to say out loud who is allowed to write in that name. Say nothing, and the receiving side has to guess - and it errs on the side of caution.
The three settings, in plain words

There are three of them and they are the same three for everybody. Nothing here is bespoke, and nothing here is something anybody should be selling you separately. Think of them as three things that belong with your company's post.
A list of who may write in your name
The first setting (SPF) is simply a list: these servers are allowed to send mail in your domain's name. Your mail service is on the list. Your website is on the list, if it sends notifications from forms. Your newsletter tool is on the list, if you have one. The rest of the world is not.
The receiving server looks at where the message actually came from and compares that against the list. If the sender is not on it, that is the first sign that something is out of place.
The mistake we see most often here is not a missing list but an out-of-date one. You moved your mailboxes from one service to another, but the list still names the old service. Or a newsletter tool was added and nobody added it to the list.
A seal showing the message has not been touched
The second setting (DKIM) puts a seal on every message that goes out. The seal is made by your mail server, and it can only be checked using information published alongside your domain.
The receiving side gets two things from it at once. It can see that the message really came from where it claims to have come from, and it can see that nobody rewrote the message on the way. If the seal does not match, the message was either forged or altered in transit, and the receiver cannot tell which of the two.
A note to the receiving post office
The third setting (DMARC) checks nothing itself. It tells the receiving side what to do when the first two checks fail: let the message through, put it in the spam folder, or refuse to accept it at all.
Without that instruction, every receiver falls back on its own guess about a message that failed the first two checks. One lets it through, the next puts it aside, and you hear about neither.
It can also report back. Put an address into that third setting and the big mail services start sending summaries of who has been sending in your domain's name, including whoever is doing it without asking you. One honest warning: those summaries arrive in a machine-readable form, not as a report a person reads. Put your domain manager's address there, or a service that reads them for you.
All three live in the domain's settings, not on the website and not in the mailbox. They are added by whoever manages your domain: your host, the company that sold you the name, or your IT person. This is one of those places where it pays to know whose name your domain is in, because without access this work cannot be done at all.
The form that mails in the visitor's name
Now for the one thing we see most often on small Estonian sites. It is also the sneakiest, because it does not break the mail you send. It breaks the mail your customers send you.
The contact form on your site sends you a message every time somebody fills it in. A great many forms are set up to put the visitor's own address on the sender line. The intention is good: that way you can just press "Reply" and the message goes to the right person.
The result, though, is that your server sends a message claiming to come from a stranger's address. Catching exactly that is what those three settings are for, and the message fails them in the clearest possible way.
It is nobody's mistake: the form behaves like a forger, because it is doing the same thing.
And your own settings do not fix it. All three can be flawless on your domain: this message is judged against the visitor's domain, not yours.
The correct setup is simple. The message is sent from an address on your own domain, something like form@yourcompany.ee, and the visitor's address goes on the reply line instead. You still press "Reply" and the message still goes to the visitor. The only difference is whose name your server presents itself under.
If you have the feeling that fewer enquiries arrive than your visitor numbers would suggest, check this before anything else. There is a separate article about the other places enquiries go missing.
Habits that get you filtered

A domain with its settings in order can still have a message filed as spam, if the message itself looks like spam. Filters also look at what you write and at how you send it.
The clearest example goes like this. Somebody sends a newsletter from an ordinary mailbox to two hundred addresses at once. There is no unsubscribe link, because ordinary letters do not have one. Some of the recipients press "spam" instead, and every one of those presses goes onto your domain's record.
The rest are smaller, and they work the same way.
- A free mailbox address, or one from your old internet provider. No filter forbids it and millions of people use one every day. But you have no domain whose good name you can build up: the reputation you accumulate over the years belongs to the mail provider rather than to you.
- A subject line in capitals. Capitals used to read as attention-grabbing. Now they are how attention-grabbing mail gets spotted.
- A message that is one big image. A nice layout, turned into a picture and sent as a picture. The filter sees no words in it at all, only a file, and a file with no text is an old trick for hiding text from exactly that filter.
- Shortened links. A short link hides where it goes. You have an innocent reason for using one, but to a filter it is the same thing everybody else is doing with it.
- A first message to a stranger carrying an attachment. An attachment from a sender the filter does not know is one of the strongest warning signs it has. A first message can be text and a link; the price list can follow once the other side has replied.
- A bought list. Nothing gets a domain filtered faster. The addresses are old. Some of them are addresses the mail providers plant on purpose, so that anyone writing to them is a buyer of lists and nothing else. And people who have never heard of you mark the message as spam. It is also a legal question in its own right, and this article does not settle that one.
A small warning: this article is not legal advice. We are not lawyers and we do not know your company's situation. If you are planning to send mail to people who are not your customers, the right person to ask is a lawyer, not an article.
Reputation belongs to a name, not to a message
Filters do not only judge the message that has just arrived. They judge two names: your domain, and the server the message left from. Both of them have a history.
Two things follow from that. First, a new domain is treated cautiously. You registered the name last week and started sending quotes immediately, but to a receiver it is a name with no story yet. Time and ordinary day-to-day correspondence fix that on their own; sending harder does not speed it up.
Second, cheap shared hosting often means a shared sending reputation as well. If your site and your mail both go through the same machine as several hundred other customers, your message carries their history too. You do nothing wrong and the result is still worse, which is one thing worth asking your host about.
How to check it yourself, today

You do not have to buy anything or meet anybody to do this. Three steps, about a quarter of an hour.
- From the address you actually write to customers from, send a message to yourself at an account you own with one of the big free providers. Do this on a computer, not a phone: the phone apps mostly do not offer the option you need. Open the message that arrives and look in the menu for the item usually called "Show original". At the top of the page that opens are three lines, each of them saying either "pass" or "fail". Those three lines are the three settings from earlier in this article.
- From the same address, send a message to a colleague whose mail is somewhere else. Same message, different service. If one mailbox takes it calmly and the other files it as spam, you already know something you did not know before: the problem is not what the message says.
- Ask whoever manages your domain one sentence. "Does our domain have its mail settings in place, and are they up to date?" That is the whole conversation. If the answer is "I do not know", that is the first thing to come back to.
Then do the same with your own website's form, from end to end. Fill it in the way a customer would, with a real address, and see whether the message reaches your inbox.
If it does, open the original of that message the same way you did in the first step, and see whose name it was sent under. Plenty of the enquiries you thought were lost are not lost at all, they are simply in another folder.
The honest limit
Now the part we cannot promise either. Nobody can promise that a message reaches the inbox.
The rules the filters use are secret, they change, and every service decides in its own way. The same message can reach one person's inbox and another person's spam folder on the same day, with nothing having changed at your end. Anyone promising you delivery is promising something that is not theirs to give.
What you do control is how suspicious you look. Three settings in order, an address on your own domain, a form that sends in your own name, and messages that read as though a person wrote them. That moves you from suspicious to ordinary. Ordinary is all any sender gets, including the largest ones.
These settings are also not a one-off job. The mail service changes, a newsletter tool gets added, somebody sets up a new form. Any of those can fall outside the list, and nobody notices until the replies stop coming. Which is why it is worth going over once a year: who is currently sending mail in your domain's name. The same logic runs through the rest of web management - things do not break all at once, they break one at a time and quietly.
And if you have lost enquiries and have no idea where to start, write to us and say which address you send from and where the message did not arrive. Those two things are enough to start checking from. "Our mail goes to spam" is not.
So if you read this far and do only one thing, send yourself a message from the address you write to customers from, and look at whether those three lines say pass.
Frequently asked questions
We see two causes most often. The first is that the receiving server cannot tell your message apart from a forgery: the sender line is not evidence, anybody can put your company's address there without your password or your mailbox, and people do it every day. If your domain does not say who is allowed to write in its name, the receiving side has to guess, and it errs on the side of caution. The second is the message itself: a subject in capitals, one big image instead of text, or an attachment in a first message to a stranger.
They are three settings that live alongside your domain, and they are the same three for everybody. The first is a list of which servers may send mail in your domain's name. The second puts a seal on every outgoing message, so the receiving side can see it really came from you and that nobody altered it on the way. The third tells the receiving side what to do when the first two fail, and it can also report back to you on who is sending mail in your name. Whoever manages your domain adds them.
What we see most often is a form that puts the visitor's own address on the sender line, so that you can just press Reply. Your server then sends a message claiming to come from a stranger's address, which is exactly what the mail checks were built to catch, and it fails them in the clearest possible way. The correct setup is to send from an address on your own domain and put the visitor's address on the reply line instead: you still press Reply, but your server presents itself under its own name.
From the address you actually write to customers from, send a message to yourself at an account you own with one of the big free providers, open it on a computer, and look in the menu for the item called "Show original". At the top of the page that opens are three lines, each saying either "pass" or "fail". Then send the same message from the same address to a colleague whose mail is elsewhere: if one accepts it and the other files it as spam, the problem is not what the message says. Third, ask whoever manages your domain whether the mail settings exist and are up to date. Finally, fill in your own website form with a real address and see whether it arrives.
No. The rules the filters use are secret, they change, and every mail service decides in its own way: the same message can reach one person's inbox and another person's spam folder on the same day, with nothing having changed at your end. Anyone promising delivery is promising something that is not theirs to give. What is yours is how suspicious you look: the three mail settings in order, an address on your own domain, a form that sends in your own name, and messages that read as though a person wrote them. That moves you from suspicious to ordinary, and ordinary is all any sender gets.
Read next

Friday afternoon, a customer says your site is not working, and on your own computer it works fine. What you actually do in the next ten minutes: how to check, what the error message tells you, and which of the three doors to knock on.