top of page
it support sheffield

Microsoft 365

Why are my business emails going to spam?

By Steve Harper  |  8 min read  | Last updated:

7 August 2026 at 10:00:27

Business Emails Going to Spam

TL;DR

Business emails may go to spam because the sending domain is not properly authenticated, the domain or sending service has developed a poor reputation, the message resembles bulk marketing or an account has been compromised.


The first checks should normally include SPF, DKIM and DMARC, followed by the email headers, sending history, recipient pattern and any third-party platforms sending email from the company domain.


Asking recipients to mark messages as safe may provide temporary relief, but it does not correct the underlying deliverability problem.


Key Takeaways

  • Configure SPF, DKIM and DMARC correctly for the business domain.

  • Check every legitimate platform that sends email using the domain.

  • Sudden deliverability problems can indicate a compromised account.

  • Large or unusual increases in sending volume can trigger spam controls.

  • Message content is only one part of email deliverability.

  • Email headers can help identify why a message was classified as spam.

  • Avoid attempting random DNS changes without checking the complete email setup.

Are important business emails disappearing into customers’ spam folders?


IT Desk can investigate Microsoft 365 email delivery, check SPF, DKIM and DMARC, review sending services and identify possible account or configuration problems. We can help improve the reliability and security of your business email environment.



Why do legitimate business emails go to spam?

Receiving email systems assess many different signals before deciding whether a message should reach the inbox, enter the junk folder or be rejected.


These signals can include:

  • Whether the sender is authenticated

  • The reputation of the sending domain or service

  • The history and volume of messages

  • Whether recipients interact with or report the messages

  • The links, attachments and formatting in the email

  • Whether the sending behaviour resembles a compromised account

  • The recipient organisation’s own filtering policies

  • Whether the sender has previously delivered unwanted bulk email


A message can therefore be legitimate from the sender’s perspective but still appear risky to the recipient’s email system.

What are SPF, DKIM and DMARC?

SPF, DKIM and DMARC are email-authentication technologies used to help receiving systems confirm that a message is genuinely associated with the domain displayed to the recipient.


SPF

Sender Policy Framework, or SPF, identifies which mail systems are authorised to send email for a domain.


The SPF record is published in the domain’s DNS settings. If the business starts using a new email platform but does not update the SPF configuration correctly, messages from that platform may fail authentication.


DKIM

DomainKeys Identified Mail, or DKIM, adds a digital signature to outgoing messages.


The receiving email system can use this signature to check that the message was associated with the claimed domain and was not altered in a way that invalidates the signature.


Microsoft advises organisations using custom domains in Microsoft 365 to configure DKIM signing for stronger protection.


DMARC

Domain-based Message Authentication, Reporting and Conformance, or DMARC, builds on SPF and DKIM.


It allows the domain owner to define how receiving systems should handle messages that fail authentication. DMARC reporting can also help identify legitimate and unauthorised services sending email using the domain.


Microsoft recommends configuring SPF, DKIM and DMARC for custom Microsoft 365 domains. SPF alone does not provide complete protection.


Can an incorrect SPF record send emails to spam?

Yes.


An incomplete or incorrect SPF record can prevent receiving systems from confirming that a sending service is authorised.


This often happens when a business uses several platforms to send email, such as:

  • Microsoft 365

  • A CRM platform

  • An email-marketing service

  • An invoicing system

  • A website contact form

  • A customer-support platform

  • A recruitment system

  • A line-of-business application


Each legitimate sender must be considered as part of the domain’s authentication setup.


A business should not create several separate SPF records for the same domain or repeatedly add services without checking the finished record. SPF has technical limits, and an excessively complicated configuration may fail even if the individual entries appear correct.


Why did our emails suddenly start going to spam?

A sudden change may indicate that something in the sending environment or recipient filtering has changed.


Possible causes include:

  • A recent DNS or email-authentication change

  • A new third-party sending platform

  • A large increase in sending volume

  • A compromised mailbox sending spam

  • A new email signature containing problematic links

  • A domain or sending service developing a reputation problem

  • Messages being sent to an old or poor-quality mailing list

  • A recipient changing its filtering rules

  • A misconfigured connector or relay

  • Authentication failing after email is forwarded


The business should establish whether the issue affects:

  • One employee or everyone

  • One recipient or multiple organisations

  • Ordinary messages, marketing campaigns or both

  • One domain or all company domains

  • Messages sent directly from Outlook or through another application


This helps narrow the investigation considerably.


Could a hacked email account cause the problem?

Yes.


If an attacker gains access to a business mailbox and uses it to send spam or phishing emails, Microsoft or other providers may restrict the account. The sending domain’s reputation may also be affected.


Warning signs include:

  • A sudden rise in sent messages

  • Messages in Sent Items that the user does not recognise

  • Unexpected forwarding or inbox rules

  • Unfamiliar sign-in activity

  • Non-delivery reports for messages the user did not send

  • The account appearing as a restricted sender

  • Unexpected multi-factor authentication requests


If compromise is suspected, the priority is to secure the account—not merely improve the wording of outgoing emails.


The business may need to reset credentials, revoke active sessions, remove malicious rules, investigate sign-in activity and identify what the attacker accessed.


Does the wording of an email make it go to spam?

It can contribute, but there is rarely one forbidden word that automatically sends a message to spam.


Filtering systems consider the email as a whole. Potential issues include:

  • Misleading subject lines

  • Excessive capital letters or punctuation

  • Link text that does not match the destination

  • Links to suspicious or newly created domains

  • Unexpected attachments

  • Messages made almost entirely from images

  • Hidden or misleading content

  • Poor HTML formatting

  • Missing information in commercial email

  • Repeated messages sent to disengaged recipients


A normal business email can still enter spam even if its wording is perfectly reasonable, particularly when authentication or sender reputation is poor.


Changing individual words without diagnosing the technical cause is unlikely to provide a lasting fix.


Can email signatures affect deliverability?

Potentially.


A signature may include images, tracking links, social-media icons and links to external services. If one of those linked domains has a poor reputation or the signature creates unusual message formatting, it may contribute to filtering decisions.


This does not mean businesses must remove every image or link. However, when deliverability changes immediately after a new company-wide signature is introduced, testing a simple text-only message can help identify whether the signature is involved.


Can sending too many emails cause a problem?

Yes.


Microsoft 365 and receiving email platforms use sending limits and anti-abuse controls to protect their services. A sudden or unusual volume of messages can resemble spam or indicate that an account has been compromised.


Microsoft 365 is intended for business communication rather than unrestricted bulk marketing.


Businesses sending newsletters or large campaigns should use an appropriate email-marketing platform configured to authenticate the company domain. Lists should be permission-based, maintained and cleaned of invalid or disengaged addresses.


Dividing a large mailing across employees’ normal Microsoft 365 mailboxes is not a good workaround and may create further deliverability or account-security problems.


Why do emails only go to spam for one customer?

The issue may relate to the customer’s own security system, policies or previous interactions with the sender.


Their email environment may:

  • Apply stricter filtering

  • Block a sending domain or service

  • Quarantine particular attachment types

  • Use a custom mail-flow rule

  • Have received previous user complaints

  • Treat the message as impersonation

  • Reject mail that fails a particular authentication check


The recipient’s IT administrator may need to examine the message trace or quarantine reason. However, the sender should still verify its own authentication before assuming the problem belongs entirely to the customer.


How can I find out why an email went to spam?

Start by examining the message headers and authentication results.


Headers can show whether the message passed or failed checks such as:

  • SPF

  • DKIM

  • DMARC

  • Microsoft composite authentication

  • Spam confidence assessment


Microsoft 365 administrators can also use message tracing, security reports, quarantine information and Defender tools to investigate delivery.


Useful evidence includes:

  • A copy of the affected message

  • The complete message headers

  • The sender and recipient addresses

  • The exact date and time

  • Whether the message reached junk, quarantine or was rejected

  • Any non-delivery report or error code

  • Whether other recipients were affected


Sending repeated test emails without collecting this information can make diagnosis harder.


Should I ask customers to add us to their safe-sender list?

This can help individual recipients, but it should not be treated as the primary solution.


Safe-listing does not correct:

  • Failed email authentication

  • A compromised mailbox

  • Poor sending practices

  • Domain-reputation problems

  • Incorrect DNS records

  • Issues affecting other recipients


It is appropriate when a recipient’s legitimate custom policy is causing a false positive, but the sender’s wider configuration should still be checked.


How do we stop business emails going to spam?

A structured investigation should include:

  1. Confirm which senders, recipients and message types are affected.

  2. Review the complete email headers.

  3. Check SPF, DKIM and DMARC.

  4. Identify every system authorised to send from the domain.

  5. Review recent DNS, connector and mail-flow changes.

  6. Check for compromised accounts or unusual sending.

  7. Review domain and sending reputation.

  8. Test without complex signatures, links or attachments.

  9. Check Microsoft 365 message traces and restrictions.

  10. Monitor delivery after the correction.


Avoid making several DNS and security changes at once. If deliverability improves, it may otherwise be difficult to identify which change corrected the problem.


For employees who are receiving excessive unwanted email rather than having their own messages filtered, see our guide to stopping spam and junk email in Outlook.

Related Insights

So, why IT Desk?

deceleration.png

Proactive & Reactive Support

In 2024, we achieved an average response time of 13 seconds. Most IT support providers respond anywhere between 30 seconds and 1 minute.

Not only this, 99.5% of our feedback we received was rated 4 out of 4, making this one of our best years yet!

trophy.png

Award Winning

Recognised by Three Best Rated as one of the 'Three Best Rated' IT Service Providers in the Rotherham area. Our feedback definitely reflects this!

Acknowledged by Barnsley & Rotherham Chamber of Commerce over the years for Excellence in Customer Service and Commitment to People Development.

certified.png

Experienced & Certified

Awarded the 'Investors in People' certification, which is an industry standard that shows IT Desk as being actively committed to developing and supporting it's employees.

 

From apprentices to managers to solution engineers, our team of people is truly unique - often described by them as a 'family'!

Reliable & Consistent

Founded in Rotherham in 2006, we started out offering IT support to local businesses. Over the years, we've expanded to serve clients throughout the UK.

With over a decade of experience, we offer exceptional localised IT support, particularly in South Yorkshire, and specialise in assisting SMEs.

Innovative Solutions for Businesses

20+

Years of Experience

A legacy of excellence in digital solutions.

100%

Zero Carbon

Doing our part for the environment.

Certified by British Gas.

99.9%

Client Satisfaction Rate

Trusted by businesses across all sectors for superior service.

1200+

Projects Completed

Delivering cutting-edge solutions for a seamless digital future.

Chris W.png
Steve Harper.png
BG---Name---Chloe-Day.png
BG---Name---Morgan-C.png

Experts in the field. Driven by success.

Speak to our team today.

IT Desk are a leader in business growth through consultancy. Contact us today for a no-obligation chat. Your Success, We’re Part of IT.

Book a meeting with our team.

Click below to see our live calendar and book a meeting with our team of experts.

bottom of page