This is a research guide based on cited documentation. It is not a report of firsthand testing. Our editorial method

Record the failing path before editing DNS

A business can send newsletters, invoices and person-to-person mail through different services. Start with the stream that failed, its visible sender address, the destination provider and the actual rejection or spam-folder observation. One successful office email does not settle the newsletter configuration. Save the message privately and remove recipient details from any shared incident notes.

Google's published guidelines distinguish requirements for all senders to personal Gmail accounts from additional requirements for bulk senders. They also describe domain alignment for direct mail. This article uses those guidelines as a specific destination's requirements, not a universal guarantee of delivery to every mailbox. [1]

Read authentication as separate results

Inspect the original message or full headers using the receiving mailbox's tools. Record SPF, DKIM and DMARC results separately, together with their associated domains. Do not paste the full header into a public forum: it can contain addresses and routing details. Ask the sending provider to explain a result that is absent or ambiguous.

Google describes DMARC alignment as relating the visible From domain to an authenticated SPF or DKIM domain. A message can authenticate infrastructure belonging to a sending service without authenticating the business identity shown to the reader. The FAQ provides additional context for sender compliance and alignment. [1] [2]

Worked example: two green checks are not the conclusion

Consider an invented newsletter using the mailbox hello at the domain news.example in its visible From header. Its inspection record shows SPF passing for delivery.example and DKIM passing for delivery.example, while DMARC fails. The domains here are fictional. The expected diagnostic question is whether the provider has configured authentication for the intended business domain; counting two pass labels misses that question.

Now imagine a second message shows DKIM passing for news.example and DMARC passing, while SPF still identifies delivery.example. That is a different result, not evidence that every DNS entry must be replaced. Keep the exact message date so you can distinguish old mail from a message sent after a configuration change.

Change only the configuration you can explain

Inventory every legitimate sender before altering shared DNS. Obtain the exact records from each provider's current setup page or support response. Have the domain administrator compare them with the current zone and preserve the existing values. Avoid copying a sample record from an unrelated company or removing a sender simply because it is unfamiliar.

Use the provider's domain-verification check, then send a new authorized test message through the same affected service. Record the new results. A dashboard showing verified is evidence about configuration; the received message supplies evidence about the actual sending path. If the two disagree, keep both observations for support.

Separate authentication repair from inbox placement

Once the intended message authenticates, inspect remaining symptoms separately: a rejection response, a spam placement or no visible receipt are different outcomes. Google also discusses reputation, unwanted mail and message formatting; authentication is one part of its guidance. Do not promise that changing a DNS record forces inbox placement. [1]

Use the worksheet for one row per sending stream and one dated recheck. Close the authentication issue only when the affected stream produces the expected result. Leave unrelated deliverability questions open with their own evidence. This is a documentation-based procedure, not a report of tests inside your account or a recommendation to send unsolicited mail.

Take it with you

SPF and DKIM pass, but email still fails worksheet

Download worksheet

Sources & verification

Product details and prices can change. Check the linked provider before buying.

  1. Google Gmail Help: Email sender guidelines Accessed 2026-09-14
  2. Google Gmail Help: Email sender guidelines FAQ Accessed 2026-09-14

Sources link directly to providers. Product buttons may use separately labeled affiliate links. Read our disclosure.

Your decision at a glance

Compare the options

Full comparison

Documentation-based guidance. No tested ranking or performance score.

Email

Kit

Consider it for
Evaluate for subscriber broadcasts; consider Creator when a specific sequence or automation earns its cost.
Starting cost
Free plan; audited Creator example $39/month for 1,000 subscribers
Before you choose
Subscriber count and billing interval change price. The paid workflow has not been tested.

Checked 2026-09-13 · Pricing source

View Kit plans

Ordinary provider link. No affiliate partnership claimed. Link disclosure

Automation

Make

Consider it for
A visual tool to investigate small workflow designs, beginning with synthetic data and human review.
Starting cost
Free plan includes 1,000 credits/month
Before you choose
Connected apps can cost extra. Free scheduled interval is at least 15 minutes; paid billing must be checked at checkout.

Checked 2026-09-13 · Pricing source

View Make plans

Affiliate link: we may earn a commission on an eligible purchase. Link disclosure

Email

MailerLite

Consider it for
Compare with Kit for a small list that needs limited automated follow-up.
Starting cost
Free: up to 250 subscribers, 2,500 emails/month, 3 automations
Before you choose
Paid prices require a live quote. Free sends lock above the subscriber limit; premium trial features may expire.

Checked 2026-09-13 · Pricing source

View MailerLite plans

Ordinary provider link. No affiliate partnership claimed. Link disclosure