Data leak, intrusion, or suspected security incident? Report a security incident immediately.

Report security incident
EBH Security

Guide

Why Your Business Emails Keep Landing in Spam (And How to Check in 30 Seconds)

EBH Security TeamAugust 4, 20266 min read

The symptom: important emails that never seem to arrive

You send an invoice, a business proposal, or a simple follow-up to a client, and nothing happens. No reply, no bounce message, nothing unusual in your Sent folder. A few days later the client calls to say they never received it — or worse, they saw it land straight in their spam folder and never opened it. This scenario plays out quietly in many Moroccan businesses, without anyone connecting it to a specific technical issue. You assume the client didn't look carefully enough, or you shrug it off as one of those things that just happens sometimes, when in reality the cause is usually the same: your sending domain isn't properly authenticated in the eyes of major email providers like Gmail, Outlook, or Yahoo. These providers apply increasingly strict rules to fight spam and impersonation, and a domain that doesn't meet them sees its sending reputation quietly erode over time, until a growing share of its emails gets filtered automatically. What makes this especially insidious is that it comes with no warning sign — no notification tells you your emails are being filtered. You keep sending, assuming everything is fine, while business opportunities and client relationships deteriorate in the background.

SPF: who is allowed to send email on behalf of your domain

SPF (Sender Policy Framework) is a record in your domain's DNS configuration that explicitly lists which servers are authorized to send email on your behalf. When an email arrives at its destination, the receiving mail server checks whether the sender appears on that list. If your invoicing software, your CRM, or your email marketing platform sends messages from your business address without being declared in your SPF record, those messages look like impersonation to the recipient's mail server — even though they're completely legitimate. This is one of the most common causes of poor deliverability: a business adds a new tool that sends email on its behalf (online invoicing, a newsletter platform, sales software) without ever updating its SPF record, which has stayed frozen since it was first set up, sometimes by a provider that no longer even exists. SPF isn't complicated to check once you know where to look, but it's almost always ignored after the initial setup, even as the list of tools a growing business uses keeps changing. An outdated or overly restrictive SPF record blocks your own emails; a missing one protects no one.

DKIM: the signature that proves a message wasn't tampered with

DKIM (DomainKeys Identified Mail) works differently: it attaches an encrypted digital signature to every outgoing email, generated from a private key tied to your domain. The recipient's server retrieves the matching public key, also published in your DNS, and checks that the signature is valid and that the message content wasn't altered in transit. It's a guarantee of integrity and authenticity that complements SPF, which only verifies the sending server. Without properly configured DKIM — or with expired keys, records copied incorrectly into DNS, or keys belonging to a former email provider — messages lose an important trust signal. Major providers like Gmail combine several signals (SPF, DKIM, domain reputation, recipient behavior) to decide where to place a message, and missing even one of these signals mechanically increases the odds that a legitimate email ends up in spam, especially for newer domains or ones that send low volumes. Setting up DKIM correctly usually just means enabling an option with your email provider and copying a couple of DNS records — a simple technical step, but one that's frequently overlooked when a domain is first created or when switching providers.

DMARC: the policy that tells inboxes what to do when checks fail

DMARC (Domain-based Message Authentication, Reporting and Conformance) sits on top of SPF and DKIM. It doesn't replace either one, but tells receiving mail servers what policy to apply when an email fails SPF or DKIM checks: do nothing, quarantine it (spam folder), or reject it outright. Without a DMARC record, every mail provider applies its own internal logic, inconsistently and unpredictably from one recipient to the next. DMARC also plays a role that's often underestimated: protecting your own domain from impersonation. Without DMARC set to a strict policy, nothing stops an attacker from sending an email that appears to come from your company — a fake invoice, an urgent wire transfer request signed with your CEO's name — to trick your clients or partners. This is a common fraud vector, and DMARC significantly reduces the risk by giving recipient inboxes a clear instruction: reject any message claiming to come from your domain that fails authentication checks. DMARC also provides regular reports showing exactly who is sending email on your behalf, which helps you spot both legitimate tools that were never properly declared and genuine impersonation attempts.

Why this is so often misconfigured (and how to check for free)

In the vast majority of cases we see among Moroccan SMEs, SPF, DKIM, and DMARC were never intentionally configured — or were set up once, when the website or mailbox was first created, and never revisited since. Switching email providers (moving to Gmail Workspace or Microsoft 365, for instance), adding an invoicing tool, a CRM, or a marketing platform like Mailchimp or SendGrid, or simply changing technical providers, is enough to break a configuration that used to work — often without anyone noticing for months. The real-world consequences are costly: invoices that never arrive and delay payment, proposals that go unanswered simply because they were never read, eroding trust as clients start to question the business's professionalism, and greater exposure to phishing attacks that impersonate your domain. The good news is that diagnosing all three takes only seconds. EBH Security built a free tool, available at emailcheck.ebh.ma as part of its EBH Defender suite, that checks the status of your SPF, DKIM, and DMARC records in 30 seconds and explains, in plain language, what needs fixing.

FAQ

Frequently asked questions on this topic

Not always — message content and overall domain reputation play a role too. But in most cases we see among SMEs, missing or misconfigured SPF, DKIM, or DMARC is the main cause, and it's also the easiest one to fix. It's the first thing worth checking before looking anywhere else.

Next step

A question about your specific context?

Let's discuss your challenges and the security scope that makes sense for your company.