Email deliverability remains one of the most frustrating issues for site owners and administrators. Your server is running, your application sends mail successfully, but messages consistently land in spam folders or disappear entirely. This guide walks through the most common real-world errors, their symptoms, root causes, and exact fixes—whether you're troubleshooting yourself or evaluating when to switch to a managed service.
Understanding the Core Problem
Email delivery depends on trust signals. Recipient mail servers evaluate your domain's reputation, authentication records, sending patterns, and content before deciding inbox placement. A single misconfiguration can trigger spam filters, and multiple issues compound the problem.
The choice between self-managed troubleshooting and managed services often comes down to technical capacity, volume, and business criticality. Both approaches solve the same underlying issues, but the implementation effort and ongoing maintenance differ significantly.
Common Error 1: Missing or Broken SPF Records
Symptoms
- Emails marked as spam or rejected outright
- Recipient mail logs show "SPF check: fail" or "SPF: none"
- Inconsistent delivery across different providers
Root Cause
Sender Policy Framework (SPF) records tell receiving servers which IP addresses are authorized to send mail for your domain. Missing or incorrect SPF records fail authentication, immediately lowering trust scores.
The Fix
Check your current SPF record:
dig TXT yourdomain.com +short | grep spf
A proper SPF record looks like:
v=spf1 ip4:203.0.113.10 include:_spf.google.com ~all
Common mistakes:
- Multiple SPF records: Only one TXT record starting with
v=spf1is allowed per domain. Combine all authorized sources into a single record. - Missing include directives: If you send through third-party services (Google Workspace, SendGrid, Mailchimp), add their
include:mechanism. - Wrong mechanism order: Place
ip4:andinclude:before theallqualifier. - Hard fail vs soft fail: Use
~all(soft fail) during testing,-all(hard fail) once validated.
Create or update your SPF record in your DNS control panel:
- Log into your DNS provider or cPanel
- Navigate to DNS Zone Editor
- Add or edit the TXT record for your root domain
- Set value to your complete SPF policy
- Save and wait 5-30 minutes for propagation
Verify after changes:
dig TXT yourdomain.com +short
Managed Service Advantage: Services like Google Workspace, Microsoft 365, or dedicated providers like SendGrid handle SPF automatically. Their IP ranges are already trusted, and you simply add their include: directive once.
Common Error 2: No DKIM Signature
Symptoms
- Mail headers show "DKIM: none" or missing signature
- Deliverability is poor despite correct SPF
- Gmail and Outlook show warning indicators
Root Cause
DomainKeys Identified Mail (DKIM) adds a cryptographic signature to outgoing messages. Without it, receiving servers cannot verify message integrity or authenticate the sender's domain ownership.
The Fix
Generate DKIM keys on your mail server. For cPanel:
- Navigate to Email Deliverability in cPanel
- Find your domain and click Manage
- Enable DKIM and copy the generated public key
- Add the DKIM TXT record to your DNS
For command-line mail servers using OpenDKIM:
# Generate key pair
opendkim-genkey -s default -d yourdomain.com
# View public key
cat default.txt
The DNS record format:
default._domainkey.yourdomain.com. IN TXT "v=DKIM1; k=rsa; p=MIGfMA0GCS..."
Add this TXT record to your DNS, then configure your mail server to sign outgoing messages with the private key.
Common DKIM mistakes:
- Key length: Use 2048-bit keys minimum
- Selector mismatch: The selector in DNS (e.g.,
default._domainkey) must match your mail server configuration - Quotes and formatting: Long keys often require splitting across multiple quoted strings in DNS
- Permissions: The private key file must be readable only by the mail server user
Test DKIM signing by sending mail to a test address and checking headers:
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yourdomain.com;
s=default; t=1720675000;
Managed Service Advantage: DKIM signing is enabled by default and managed automatically. Key rotation, selector management, and signing configuration require no manual intervention.
Common Error 3: DMARC Policy Not Set
Symptoms
- Sporadic deliverability issues
- No visibility into authentication failures
- Phishing attempts using your domain succeed
Root Cause
DMARC (Domain-based Message Authentication, Reporting, and Conformance) builds on SPF and DKIM, instructing receiving servers how to handle authentication failures and where to send reports.
The Fix
Start with a monitoring-only policy:
_dmarc.yourdomain.com. IN TXT "v=DMARC1; p=none; rua=mailto:[email protected]; fo=1"
Breakdown:
p=none: Monitor only, no enforcementrua=mailto:: Aggregate reports destinationfo=1: Generate reports for any authentication failure
Once you confirm SPF and DKIM pass consistently, escalate the policy:
v=DMARC1; p=quarantine; pct=10; rua=mailto:[email protected]
Then eventually:
v=DMARC1; p=reject; rua=mailto:[email protected]; ruf=mailto:[email protected]
Common DMARC mistakes:
- Jumping straight to p=reject: Start with
p=none, analyze reports, then tighten - Ignoring subdomains: Add
sp=quarantineto set a subdomain policy - No report monitoring: DMARC reports reveal unauthorized senders and misconfigurations
- Invalid email format: The
rua=andruf=must usemailto:URIs
Managed Service Advantage: Managed providers publish strict DMARC policies by default and provide dashboard-based report analysis rather than raw XML emails.
Common Error 4: Reverse DNS Mismatch
Symptoms
- Mail rejected with "reverse DNS lookup failed"
- Logs show PTR record errors
- Deliverability issues specific to corporate mail servers
Root Cause
Receiving servers perform reverse DNS lookups (PTR records) to verify your sending IP resolves to a hostname that matches your domain. Mismatches suggest compromised or suspicious infrastructure.
The Fix
Check your current PTR record:
dig -x 203.0.113.10 +short
This should return a hostname like mail.yourdomain.com. Then verify forward resolution:
dig mail.yourdomain.com +short
This must return the same IP address.
To fix:
- Contact your hosting provider or VPS provider: PTR records are managed by whoever owns the IP block, not in your DNS zone
- Request the PTR record point to your mail server hostname (e.g.,
mail.yourdomain.com) - Ensure the forward A record for that hostname points to the sending IP
- Wait for propagation and re-test
Common PTR mistakes:
- Generic hostnames: Avoid provider defaults like
vps12345.provider.com; use your own subdomain - IP mismatch: Forward and reverse lookups must match exactly
- Shared hosting: Shared servers often use the host's PTR; you may need a dedicated IP
Managed Service Advantage: Managed email services use their own IP infrastructure with correct PTR records already configured and maintained.
Common Error 5: Blacklisted IP Address
Symptoms
- Hard bounces with "blocked" or "blacklisted" messages
- Sudden delivery failure to multiple providers
- Specific error codes referencing RBLs (Realtime Blackhole Lists)
Root Cause
Your sending IP has been added to one or more spam blacklists, usually due to previous abuse, compromised accounts, or shared IP reputation issues.
The Fix
Check major blacklists:
# Using MXToolbox or similar
curl -s "https://mxtoolbox.com/api/v1/Lookup/blacklist/203.0.113.10"
Or check manually:
- Spamhaus (zen.spamhaus.org)
- Barracuda (b.barracudacentral.org)
- SpamCop (bl.spamcop.net)
- SORBS (dnsbl.sorbs.net)
For each blacklist where you appear:
- Identify the root cause: Check your logs for compromised accounts, malware, or bulk sending patterns
- Fix the underlying issue: Reset passwords, patch vulnerabilities, remove malware
- Request delisting: Each blacklist has its own removal process, usually requiring you to confirm remediation
- Implement rate limiting: Prevent future mass sending from single accounts
Preventive measures:
# Monitor outgoing mail queue
mailq | tail -n 1
# Check authentication failures in logs
grep "authentication failed" /var/log/maillog
Common blacklisting triggers:
- Compromised WordPress installations: Regularly update and harden
- Weak passwords: Enforce strong mail account passwords
- Contact form spam: Add CAPTCHA or rate limiting
- Shared IP pollution: Previous tenant abuse affects you
Managed Service Advantage: Managed providers maintain IP reputation actively, rotate IPs, use dedicated pools for high-volume senders, and handle delisting requests as part of service.
Common Error 6: Poor Email Content and Sending Patterns
Symptoms
- Authentication passes but messages still land in spam
- Inconsistent results across recipient domains
- Worse deliverability for bulk sends
Root Cause
Content filters and behavioral analysis flag suspicious patterns: spammy keywords, HTML/text ratio issues, attachment types, sudden volume spikes, or lack of engagement history.
The Fix
Content best practices:
- Avoid spam trigger words: "Free," "Click here," "Act now," excessive punctuation
- Balance HTML and plain text: Include both versions in multipart messages
- Proper HTML structure: Valid markup, no broken tags, reasonable image-to-text ratio
- Legitimate links: No URL shorteners, no suspicious domains
- Unsubscribe mechanism: Include a clear, functional unsubscribe link
- From name consistency: Use recognizable sender names and addresses
Sending pattern improvements:
- Warm up new IPs: Gradually increase volume over 2-4 weeks
- Maintain consistent volume: Sudden spikes trigger filters
- Authenticate all streams: Transactional and marketing mail both need proper setup
- Clean your list: Remove bounces and inactive recipients regularly
- Monitor engagement: High complaint rates damage reputation quickly
Test before sending:
# Send test to mail-tester.com
echo "Test message body" | mail -s "Test Subject" [email protected]
Review the score and recommendations.
Managed Service Advantage: Enterprise email services provide deliverability analytics, content scanning, A/B testing, engagement tracking, and automatic list hygiene. They maintain warm IP pools and manage sending reputation as a core service.
DIY Checklist vs Managed Services: When to Switch
Use the DIY Checklist When:
- You send low to moderate volumes (under a few thousand per day)
- You have technical staff comfortable with DNS and mail server administration
- You need full control over infrastructure and data
- Your budget is constrained
- You send primarily transactional or internal mail
Consider Managed Services When:
- You send high volumes or time-sensitive mail
- Deliverability directly impacts revenue
- You lack in-house email expertise
- You need detailed analytics and reporting
- You require guaranteed SLAs and uptime
- Your IP reputation is difficult to repair
- Compliance and auditing are critical (SOC 2, HIPAA)
Managed service providers abstract away the troubleshooting checklist by:
- Maintaining pre-warmed, monitored IP pools
- Automatically configuring and rotating DKIM keys
- Publishing and enforcing strict authentication policies
- Handling blacklist monitoring and delisting
- Providing deliverability dashboards and expert support
- Managing infrastructure at scale
The tradeoff is cost and reduced control, but for mission-critical email, the operational burden reduction is often worth it.
Ongoing Monitoring
Whether self-managed or using a service, continuous monitoring prevents recurrence:
# Daily checks
- Review mail queue length: mailq
- Check authentication pass rates in logs
- Monitor bounce and complaint rates
- Verify DNS records remain intact
- Check blacklist status weekly
Set up alerts for:
- Queue length exceeding normal baseline
- Authentication failures above threshold
- Sudden bounce rate increases
- Blacklist appearances
Regularly audit:
- User account security (password strength, 2FA)
- Application security (WordPress, forms)
- DNS record integrity
- Certificate expiration (for SMTP TLS)
Conclusion
Email deliverability troubleshooting follows a systematic process: verify authentication records, ensure proper DNS configuration, monitor IP reputation, and maintain clean sending practices. Most issues stem from missing SPF/DKIM/DMARC records, reverse DNS mismatches, or blacklisted IPs—all fixable with the right diagnostic approach.
The choice between self-managed troubleshooting and managed services depends on your technical capacity, volume, and business requirements. Small to mid-volume senders with technical expertise can manage deliverability using the checklist approach. High-volume senders or those where email is mission-critical benefit from the infrastructure, reputation management, and support that managed services provide.
Regardless of approach, consistent monitoring and quick response to issues maintain long-term deliverability. Set up alerts, review logs regularly, and stay current on authentication best practices as standards evolve.
