Why It Matters

You've probably never thought about this. That's exactly the problem.

Most business owners assume their email just works. And most of the time, it does. But underneath every email you send, there's an invisible layer of infrastructure that receiving servers check before your message ever reaches a human. If that layer isn't right, your email disappears — and nobody tells you.

Email feels simple. Under the hood, it isn't.

You write an email, you hit send. It goes. That's the experience. But what actually happens between the moment you click send and the moment it lands in someone's inbox involves a series of checks that most people — including most IT professionals — don't think about on a daily basis.

Before your email is evaluated for content, before spam filters look at a single word, the receiving mail server asks a more fundamental question: is this sender actually authorised to send email from this domain? That question is answered not by anything in the email itself — but by a set of technical records published on your domain.

If those records are missing, misconfigured, or out of date, the answer comes back wrong. And the server acts accordingly — quietly, without notice, without a bounce, without any signal to you or the person you were trying to reach.

What Actually Happens

The journey your email takes before anyone reads it.

In the seconds between you hitting send and your email arriving, the receiving server runs a series of checks. Here's what that looks like — and where things go wrong.

📤
You hit send Origin
Your email leaves your outbox and travels to your mail server — whether that's Google Workspace, Microsoft 365, or your hosting provider. So far, so normal.
🔍
The receiving server checks your SPF record Check 1
The receiving server looks up your domain's SPF record — a published list of servers authorised to send email on your behalf. If your sending server isn't on that list, or the list is misconfigured, the check fails.
If SPF fails: the email is flagged immediately. Depending on the receiving server's policy, it may be rejected outright or sent straight to spam.
🔏
DKIM signature is verified Check 2
DKIM adds a cryptographic signature to your outgoing email. The receiving server uses a key published on your domain to verify that the message hasn't been tampered with in transit and genuinely came from you.
If DKIM is missing or the key has expired: the signature check fails. Many businesses don't realise their DKIM keys need periodic rotation — or that every new tool they add needs its own key configured.
🛡️
DMARC policy is applied Check 3
DMARC ties SPF and DKIM together and tells the receiving server what to do if either check fails — ignore it, quarantine it, or reject it. It also generates reports that tell you who's sending email using your domain.
63% of domains with a DMARC record are set to "none" — monitor only. No action is taken when checks fail. It's the equivalent of having a security camera with no recording.
🚫
Email is silently rejected Failure
If the checks above fail and your DMARC policy is set to reject or quarantine, your email doesn't arrive. No bounce notification. No delivery failure. Nothing. Your sent folder shows it as delivered. Your client never received it.
This is the part that catches most business owners off guard. The failure is completely invisible from your end.
✓
Or — everything passes and it lands Success
When SPF, DKIM, and DMARC are correctly configured and aligned, all three checks pass. Your email clears the authentication layer, moves on to content filtering, and lands in the inbox. This is the outcome we build toward.

The problem isn't that email is broken. It's that you can't see when it fails.

Think about how you'd know if your email was failing. You'd expect a bounce. A delivery notification. Something in your sent folder to flag it. But that's not how silent rejection works. The failure happens at the infrastructure level, before the email ever reaches a spam filter — and nothing reports back to you when it happens.

The best way we've found to explain this is to think about how physical mail used to work — and what it would be like if your post office operated the same way.

Imagine you run a business and you send letters to clients every day. Your name is on the envelope, your address is on the back, and your letterhead is inside. But the post office has a new rule: before any letter is delivered, a clerk checks a register to confirm that your return address is legitimate and that you're authorised to send from that location.

If your address isn't on the register — or if the register has an old entry that doesn't match — the letter gets pulled from the pile. It doesn't come back to you marked "undeliverable." It doesn't get forwarded. It simply disappears. The clerk moves on. Your client waits for a letter that never comes. You assume they received it.

That register is your email authentication records. Most businesses have never checked whether theirs is accurate — or whether it's even there.

The stakes are higher than most people realise. It isn't just about deliverability — it's about what happens when your domain isn't protected. Without the right records in place, there's nothing stopping someone from sending an email that appears to come from your domain. Your clients could receive a message that looks exactly like it came from you — asking them to update a payment detail, click a link, or provide information. Your brand takes the hit regardless of whether you sent it.

This isn't a theoretical risk. Business email compromise is one of the most financially damaging forms of cybercrime — and weak email authentication is what makes it possible.

The Numbers

This isn't a niche problem. It's widespread, measurable, and largely ignored.

1 in 6
business emails never reach the inbox — lost to spam filters or dropped entirely
That's roughly 16% of every email you send. Proposals. Invoices. Follow-ups. Gone.
84%
of domains actively sending email have no DMARC record published at all
Most businesses are operating with no policy whatsoever — open to impersonation, and invisible to the receiving server.
2.7×
more likely to reach the inbox with full SPF, DKIM and DMARC vs unauthenticated sending
Proper authentication doesn't just protect you — it actively improves deliverability across the board.
63%
of businesses that have DMARC are still on "monitor only" — providing zero spoofing protection
Having a DMARC record set to p=none is like having a lock on the door and leaving it open. The record exists. The protection doesn't.
65%
drop in unauthenticated email reaching Gmail since February 2024 enforcement began
Google didn't ask. They enforced. Domains that weren't ready started failing — many without realising why.
6.4%
of emails are dropped entirely — no spam folder, no bounce, no notification
Not delayed. Not quarantined. Dropped. And the sender has no way of knowing it happened.
What's Actually at Stake

Three things that happen when email authentication fails.

None of these are edge cases. Each one is a documented, common outcome for businesses with misconfigured or missing email authentication.

Revenue walks out the door quietly

A proposal that doesn't arrive doesn't get rejected — it just never gets read. An invoice that disappears doesn't get disputed — it just doesn't get paid. The client assumes you didn't follow up. You assume they're ignoring you. The deal dies in silence.

"We sent the proposal on Tuesday. They said they never received it. By the time we resent it, they'd already gone with someone else."
Someone sends email pretending to be you

Without DMARC enforcement, anyone can send an email that appears to come from your domain. Your clients could receive a message that looks exactly like it came from you — asking them to update a payment detail, click a link, or provide information. Your brand takes the hit regardless of whether you sent it.

Business email compromise cost businesses over $10.5 billion in 2023. Most of it started with a spoofed domain and no DMARC protection.
Gmail and Microsoft now enforce this — not suggest it

In February 2024, Google and Yahoo introduced strict authentication requirements for senders. Domains without proper SPF, DKIM, and DMARC configuration started seeing their emails rejected at scale — not filtered, rejected. This wasn't a guideline. It was a policy change with immediate effect.

If your domain wasn't compliant in February 2024 and you haven't checked since, there's a reasonable chance some of your email is still failing these checks today.
Get Started

Not sure where you stand? Start with a conversation.

Book a free discovery call. We'll talk through your setup, answer your questions, and let you know whether there's anything worth looking at. No commitment, no pressure.