You send a quote to a new client. Two weeks later they tell you they never heard back. You check your sent folder, and there it is — delivered, apparently. It just never reached a human being. It went to spam, or worse, it was silently dropped before it ever got that far.
This is one of the most expensive problems a small business can have, precisely because it is invisible. Nobody complains about an email they never saw. You simply lose the job and never learn why.
Why inboxes got so much stricter
Gmail, Outlook and the mail providers used by most Cyprus companies have spent the last few years tightening the rules on who is allowed to send email in your name. The reason is straightforward: impersonation. It is trivially easy to write any address you like into the "From" field of an email, which is why fake invoices and payment-redirect scams work so well.
To fight that, mail providers stopped trusting the "From" field on its own. Instead, they check whether the server that actually sent the message has permission to send on behalf of your domain. If there is no proof, your email is treated as suspicious — even when it is completely genuine.
The practical result is that businesses which never set up that proof have slowly slid from the inbox, to the promotions tab, to spam, to nowhere at all.
The three records that vouch for you
The proof lives in your domain's DNS settings — the same place your website address is configured. There are three records involved. You do not need to understand them technically, but you should know what each one is for, so you can ask the right questions of whoever manages your domain.
SPF — the guest list
SPF is a list of the mail services allowed to send email using your domain. Your business mailbox provider is usually on it. Problems start when you add other senders over time — a newsletter tool, an accounting system that emails invoices, a website contact form — and nobody updates the list. Those messages then arrive with nothing vouching for them.
DKIM — the signature
DKIM adds an invisible cryptographic signature to every message you send. The receiving server checks that signature against your domain and confirms two things: the email really came from you, and nobody altered it in transit. Without DKIM, you have no way to prove either.
DMARC — the instructions
DMARC ties the first two together and tells receiving servers what to do when a message fails the checks: let it through, send it to spam, or reject it outright. It also sends you reports showing who is sending email in your name. That last part is genuinely useful — it is how you discover both the legitimate tools you forgot about and the people impersonating your brand.
Five other things that quietly hurt delivery
- Sending from a free address. A quote from a gmail.com or hotmail.com address cannot be verified against your business domain, and it looks less credible to clients as well.
- Buying or scraping contact lists. Recipients who never asked to hear from you mark you as spam, and that reputation follows your domain everywhere.
- No unsubscribe link on marketing email. Without an easy way out, people use the spam button instead — which is far more damaging, and it also puts you offside with GDPR.
- Sending a large campaign from a brand-new domain. New domains have no track record, so volume needs to build gradually over a few weeks rather than all at once.
- Stale lists. Addresses that have gone dead bounce, and a high bounce rate reads as a sign that you are not maintaining your list properly.
How to check where you stand
You can get a reasonable picture in about ten minutes. Send an email from your normal business address to a free Gmail account you control. When it arrives, open it, choose "Show original" from the message menu, and look for SPF, DKIM and DMARC. Each should say "PASS". Anything reading "FAIL", "NONE" or "SOFTFAIL" is a gap worth closing.
Then repeat the test for every system that emails on your behalf — your website's contact form, your invoicing software, your booking system. These are the ones most often forgotten, and they tend to send the messages that matter most commercially.
What to do this week
Start by writing down every tool that sends email using your domain. Most businesses are surprised by the length of that list. Then have your SPF record updated to cover all of them, switch on DKIM with your mail provider, and add a DMARC record in monitoring mode so you receive reports without putting legitimate mail at risk. Once those reports look clean for a few weeks, you can tighten DMARC so impersonation attempts are rejected outright.
None of this is expensive, and for whoever looks after your domain it is usually an afternoon of work. Set against the cost of a single lost contract because a proposal never arrived, it is one of the better returns available in digital marketing — and unlike most of what we do, it keeps paying quietly in the background.
- email marketing
- deliverability
- dmarc
- small business
- cyprus