Start with one specific message and what happened to it. A rejected email, a message in spam and a missing notification call for different investigations.
Imagine this: you send a proposal after a meeting, then your prospect says they received nothing. You check the address, resend the quote and hope everything goes well this time. To move forward, you need to answer a more useful question: how far did the first message get?
This guide helps you prepare that investigation, even if you do not manage the technical side yourself. We suggest an order of checks, an interactive diagram and a worksheet to share with your provider. The technical rules refer to sources from Google, Microsoft and the IETF, accessed on 13 September 2026.
01 / The symptomWhat happens to your message?
The Sent folder is a starting point. To document what follows, the administrator can look for transport events: delivery, pending, failure or quarantine. Even a delivered status does not prove that a person read the email.3
- RejectedA bounce is available
- A non-delivery report explains the rejection. In enhanced status codes, 4.x.x indicates a temporary error and 5.x.x a permanent error for the message concerned. Keep the full text too: the address, routing or receiving policy may be involved.2
- In spamThe message has been found
- Authentication deserves a check, but sender reputation and user reports also count in Gmail’s rules. Correcting a DNS record therefore does not, on its own, guarantee different classification.1
- MissingThe route still needs to be established
- Message tracing helps identify a failure, a pending message or quarantine.3 Our advice: start with the time, exact address and sending channel. Then request an investigation on both sides of the exchange.
Where should you start in your situation?
Choose what you observe. The result suggests an investigation order to share with your administrator.
These steps guide the investigation. The cause still needs to be confirmed from your messages and email logs.
Prepare the useful evidenceEditorial guidance based on your answers and the sources cited. No analysis of your emails, domain or DNS is performed.
Treat the result as a checklist. A phrase such as “my emails aren’t getting through” becomes actionable when it can be tied to an example: the quote sent on Tuesday from the sales inbox to a specific recipient, with any bounce received.
“A specific message, its time and its route provide a starting point for the investigation.”
Our advice for preparing an email diagnosis.
02 / IdentitySPF, DKIM, DMARC: what does each check?
These names refer to complementary mechanisms. To understand them, distinguish between the domain shown to the reader, the server that sends the message and the signature added to it.
SPF: is this server authorised to send?
SPF publishes in DNS the servers authorised to send for a domain. The inventory must include the third-party services used: team email, website or platform.4 For your business, the practical question is: who actually sends on our behalf?
DKIM: can the signature be verified?
The sending service signs the message with a private key. The recipient verifies this signature using the public key published in DNS. DKIM must also be activated on the service and a real message checked: the public key’s presence alone does not document that activation.5
DMARC: does it match the displayed domain?
DMARC links authentication to the domain in the visible From field. It passes if SPF is valid and aligned, or DKIM is valid and aligned. Alignment compares domains according to the mode defined by the standard.7 The diagram uses identical or entirely different domains to make this principle clear.
Two paths. One identity to verify.
Change the scenario and follow the checks through to the DMARC result.
Sending from the domain
Both mechanisms are valid and aligned with atelier.example.
Return domain (MAIL FROM)atelier.example
- Verification
- Valid
- Aligned domain
- Yes
This path is sufficient
Signing domain (d=)atelier.example
- Verification
- Valid
- Aligned domain
- Yes
This path is sufficient
Both paths meet the condition. Either one alone would have been enough for DMARC to pass.
External platform
The platform authenticates with its own domain. The From field shows the workshop’s domain.
Return domain (MAIL FROM)plateforme.example
- Verification
- Valid
- Aligned domain
- No
This path is not sufficient
Signing domain (d=)plateforme.example
- Verification
- Valid
- Aligned domain
- No
This path is not sufficient
SPF and DKIM pass, but neither is aligned with atelier.example. DMARC fails in this example.
Forwarded message
In this forwarding scenario, SPF fails. The DKIM signature remains valid and aligned.
Return domain (MAIL FROM)atelier.example
- Verification
- Failed
- Aligned domain
- Yes
This path is not sufficient
Signing domain (d=)atelier.example
- Verification
- Valid
- Aligned domain
- Yes
This path is sufficient
The DKIM path is sufficient. An SPF failure does not automatically cause DMARC to fail.
Failed checks
The domain matches, but neither SPF nor DKIM passes verification.
Return domain (MAIL FROM)atelier.example
- Verification
- Failed
- Aligned domain
- Yes
This path is not sufficient
Signing domain (d=)atelier.example
- Verification
- Failed
- Aligned domain
- Yes
This path is not sufficient
The domain name alone is not enough: a valid check is also required. Neither path meets both conditions.
Fictional educational examples. One valid, aligned check is sufficient. A successful DMARC result does not guarantee placement in the primary inbox.7 The forwarding scenario assumes the signature is preserved.9
This is why a screen that simply says “SPF: valid” may leave part of the question unanswered. Microsoft cites a lack of alignment among the reasons DMARC can fail despite valid SPF.9 Ask for an explanation of the complete result, applied to the channel causing the problem.
03 / The journeyCheck every service that sends emails.
We recommend drawing up a simple inventory with your team. One line per channel, an identified owner and a recent example to retrieve. Open the rows below to prepare yours.
01Your team’s email inbox
Record the provider, addresses used, aliases and the people who administer the service. Agree on a test message with a recipient, then record its date and what they observe.
02Your website form
Ask who generates the notification, which provider sends it and where its log can be viewed. Have each step described, from the website enquiry to the intended inbox. Keep the reference for the agreed test.
03The tools working for you
List the CRM, appointment booking, invoicing and campaign tools, if you use them. For each, record the visible sender and technical contact. Add this check to your procedure whenever you change tools.
Preparation worksheet proposed by Kanexio. Fill in only the channels used in your business.
Correct the configuration with an overall view.
Google recommends preparing SPF and DKIM, then rolling out DMARC gradually. The none policy starts the observation phase; available reports help examine sending sources before strengthening the policy.6
The quarantine and reject policies express the requested treatment for messages that fail DMARC. The recipient retains its own decision-making. Likewise, none does not disable its spam filtering.7
Our proposed approach: associate each change with a reason, a scope and a planned check. Keep the previous configuration with the administrator. Then verify the listed channels, starting with the one that had the problem.
Also check what happens to the message along the way.
Forwarding can disrupt SPF. A change to the message can affect DKIM.9 Gateways that add a footer are among the points to examine for signatures.5 Specify whether the example was forwarded or processed by an intermediary service.
To compare tests, we recommend recording what changes: sending account, recipient, tool, attachment or content. Repeat an agreed case with just one variation at a time where possible. This gives you a more useful record than a succession of different resends.
04 / The methodPrepare a short, documented investigation.
Give the provider a concrete starting point and ask for an equally precise report. Here is the sequence we suggest for organising the work.
- Observe
Describe a real case.
Record the date, time with its time zone, sending channel, recipient and observed behaviour. Keep the complete error response if there is one. Separate what you saw from what you assume.
- Gather
- Verify
Connect a cause to a correction.
Ask which finding justifies the intervention, which channels it affects and how it will be checked. The report should distinguish the change made, the observed result and the points still to examine.
- Follow up
Run another test and keep a record.
Repeat the initial case with a recipient who has been informed. Record this result and the other channels checked. Agree with your administrator which checks to repeat during a migration or when adding a tool.
Editable text · No registration
To complete with your team or provider.
For your business, the goal is an email setup that is understood and manageable: identified services, explained settings and retained examples of operation. It is also a useful basis when preparing a business email migration.
FAQ: common questions.
Is a valid SPF result enough to pass DMARC?
The authenticated domain must also align with the domain in the visible From field. A valid, aligned DKIM result can also be sufficient. Two valid but unaligned checks do not pass DMARC.9
Do SPF, DKIM and DMARC guarantee delivery to the primary inbox?
No. Google also considers spam reports, reputation and other sending requirements. Authentication is part of the diagnosis; it does not guarantee how a message will be classified.1
Is DMARC mandatory for all emails sent to Gmail?
Gmail rules distinguish ordinary senders from those sending more than 5,000 messages per day to personal Gmail accounts. SPF or DKIM is the ordinary minimum; bulk sender requirements include SPF, DKIM and DMARC.1
Should you immediately change the DMARC policy to reject?
Start by checking your legitimate sending sources. Google recommends a gradual approach with observation and report review before strengthening the policy. The setting must take account of the services that actually use your domain.6
Where can I find headers in Gmail?
On a computer, open the message concerned, then its More menu, next to Reply. Choose Show original. Keep this original for checks with your administrator.8
Sources and method.
The documents below were accessed on 13 September 2026. Providers’ rules concern their own environments. The diagnostic journey, fictional examples and preparation worksheet are Kanexio’s editorial proposals.
- Google · Gmail Help
Authentication, reputation and requirements specific to sending to personal Gmail accounts. Accessed on 13 September 2026.
Email sender guidelines - Microsoft Learn · Exchange Online
Reading bounce messages and distinguishing temporary and permanent enhanced status codes. Accessed on 13 September 2026.
Non-delivery reports and delivery errors - Microsoft Learn · Exchange Online
Events and statuses for tracing a message. Accessed on 13 September 2026.
Message tracing in the admin centre - Google Workspace · Administrator documentation
Authorised servers and inventory of sending services. Accessed on 13 September 2026.
Set up SPF - Google Workspace · Administrator documentation
Signing, publishing the public key and activation on the sending service. Accessed on 13 September 2026.
Set up DKIM - Google Workspace · Administrator documentation
Preparation and gradual policy rollout. Accessed on 13 September 2026.
Set up DMARC - IETF · RFC Editor
Alignment, authentication result and the recipient’s role. Standard published in 2026, replacing RFCs 7489 and 9091. Accessed on 13 September 2026.
RFC 9989: DMARC standard - Google · Gmail Help
Accessing the original message in Gmail on a computer. Accessed on 13 September 2026.
View an email’s full headers - Microsoft Learn · Defender for Office 365
Alignment, forwarding and SPF, DKIM and DMARC checks. Accessed on 13 September 2026.
Troubleshoot email authentication - Kanexio · Case study
Scope of our intervention and distinction from the firm’s website. Accessed on 13 September 2026.
G-LAW: business email migration
What this article establishes.
The guide explains mechanisms and an investigation method. The interactive tool does not connect to any email service. The diagram illustrates fictional identities; it displays neither a client measurement nor a delivery probability.
An intervention is verified against your configuration and messages. Receiving decisions remain specific to each recipient and their provider.7