Is the message delayed, rejected or in junk mail?

These are different situations. A delivery failure notice indicates a rejected or unsuccessful delivery; its error code is useful evidence. A message in the spam folder has arrived but has been classified differently. A missing reply alone proves neither.

Record the sending time, sender address, recipient domain and any failure notice. Ask a known recipient to check their junk folder. Repeatedly sending the same message does not identify the cause.

  • If only one recipient is affected, their organisation also needs to be considered.
  • If messages from a workstation arrive but invoices sent by an application do not, compare the sending systems.
  • If several users and recipients are affected, prioritise the domain and email service.

What do SPF, DKIM and DMARC actually do?

These checks help receiving systems verify a message's origin. SPF identifies permitted servers for the domain used in the sending transaction. DKIM adds a digital signature. DMARC checks alignment between the visible From domain and a domain authenticated by SPF or DKIM, and publishes a handling policy.

A company may send from Microsoft 365, a website form, CRM, newsletter platform and invoicing software. Configuring one service does not automatically cover the others. An MX record routes incoming mail; it does not establish that every outgoing message is correctly configured.

Why this remains a practical business issue

Google distinguishes general requirements for sending to personal Gmail accounts from stricter requirements for bulk senders. The basic authentication requirement is SPF or DKIM; bulk senders need SPF, DKIM and DMARC. Consult the Google sender guidelines for the precise scope and additional conditions.

A small business still benefits from checking its domain. A few missed quotes can disrupt the sales process. Correct authentication does not guarantee inbox placement: sending reputation, content and recipient policies also matter.

A diagnostic sequence before changing DNS

  1. List every service sending from your domain, including your website and business applications.
  2. Collect examples from each source and review the authentication results in their headers.
  3. Compare DNS records with the actual provider's documentation. Do not copy another company's SPF record.
  4. Agree changes, preserve previous values and test each sending source.
  5. Monitor reports and delivery before enforcing a stricter DMARC policy.

Microsoft recommends a gradual DMARC rollout that verifies legitimate mail. Enforcing rejection before accounting for your senders can block messages the business needs to deliver.

Avoid fixes that hide the problem

Do not ask a client to permanently disable spam protection. A personal email address is not a sustainable replacement for a misconfigured business account. Changing a display name or adding more signature text is also no substitute for diagnosis.

If colleagues report messages you never sent, account security must be reviewed as well. If the problem is with the application itself, see our Outlook and business email support.

NBG TEAM support for business email delivery

If quotes, invoices or staff messages are not arriving reliably, NBG TEAM can review your business email setup, domain configuration and application sending paths. For businesses in Belgrade and New Belgrade, we agree the scope of the review and next steps around the system you already use.

Explore our business IT support or request an email delivery review. Tell us which service you use, when the problem started and whether all users are affected. Do not send passwords; we will agree how to share example messages during support.

Request IT support →

Related guide: MFA protection for business accounts.