Skip to main content
CentraPoint

Invoice emails going to spam? SPF, DKIM and DMARC explained

Why invoice and receipt emails land in spam or vanish, how SPF, DKIM and DMARC work in plain language, and a checklist to get billing emails delivered reliably.

Published
Reading time
6 min read
By
CentraPoint Team
On this page
  1. Why billing emails are treated with suspicion
  2. SPF, DKIM and DMARC in plain language
  3. Other reasons invoice emails don't arrive
  4. What "sent" really means
  5. A deliverability checklist for billing emails
  6. How CentraPoint helps
  7. Frequently asked questions

If your invoice emails are going to spam, your customers aren't ignoring you: they never saw the invoice. Late payments, "I never got it" and duplicate reminders often start with an email problem, not a customer problem. The cause is usually technical and fixable: the mail server sending your invoices isn't properly authorised to send on behalf of your domain, so mailbox providers treat the message with suspicion.

This guide explains the three records that matter (SPF, DKIM and DMARC) without jargon, the other common causes, and a checklist you can work through with whoever manages your domain.

Why billing emails are treated with suspicion

Invoice emails look exactly like the emails fraudsters send: a company name, an amount due, a link or attachment, and a request to pay. Mailbox providers such as Gmail and Microsoft 365 have become strict about messages that claim to come from a domain but can't prove it, and they have tightened their requirements for senders in recent years.

So the question every receiving server asks is: is this server allowed to send email for this domain? SPF, DKIM and DMARC are how your domain answers.

SPF, DKIM and DMARC in plain language

SPF: who may send for your domain

SPF (Sender Policy Framework) is a DNS record on your domain listing the servers allowed to send email for it. If your invoices claim to come from [email protected] but are sent by a server that isn't on the list, SPF fails.

Common mistakes:

  • No SPF record at all.
  • Two SPF records on the same domain (only one is allowed, so both are effectively ignored).
  • A new service sending on your behalf (billing software, a CRM, a newsletter tool) that was never added to the record.

DKIM: a signature that proves the email wasn't altered

DKIM (DomainKeys Identified Mail) adds a digital signature to each email. The receiving server checks it against a public key published in your DNS. A valid signature proves the message was sent by a server holding your key and wasn't changed in transit. Each sending service needs its own DKIM key set up for your domain.

DMARC: your instructions when checks fail

DMARC tells receiving servers what to do with an email that fails SPF and DKIM alignment for your domain: nothing (monitor), quarantine (send to spam) or reject. It also lets you receive reports on who is sending email using your domain name, which is how many businesses discover spoofing attempts.

A sensible path is to start with a monitoring policy, read the reports for a few weeks to make sure every legitimate sender passes, and then tighten the policy. Tightening too early can block your own invoices.

DMARC also protects your customers: with a strict policy, it becomes much harder for a fraudster to send fake invoices that appear to come from your domain. See invoice fraud and banking detail scams for why that matters.

Other reasons invoice emails don't arrive

Authentication fixes most problems, but not all:

  • Sending from a free webmail address. Invoices from a free mailbox look less trustworthy and you can't control the authentication. Use your own domain, or a service that sends on your behalf correctly.
  • A bounced or full mailbox. Customers change jobs and email addresses. Keep a separate billing contact on each customer record.
  • Attachments only. An email that contains only an attachment and no text looks suspicious. Include a short summary in the body.
  • Link shorteners and mismatched links. Links whose visible text doesn't match where they go are a phishing signal.
  • Shouty subjects. "URGENT!!! PAYMENT DUE" reads like spam. "Invoice INV-1042 from Your Business" doesn't.
  • Reputation. If the server you send through is also used by spammers, your messages suffer too.

What "sent" really means

When billing software reports that an email was sent, it usually means a mail server accepted it. That's not the same as reaching the inbox. A message can be accepted and then filtered to spam, or quarantined by the customer's company. If a customer says they didn't receive an invoice, check:

  1. Was it accepted by the mail server, or did it fail?
  2. Did it go to the right address?
  3. Has the customer checked spam and any company quarantine?
  4. Do your domain's SPF and DKIM cover the server that sent it?

A deliverability checklist for billing emails

  1. List every service that sends email using your domain: your mailbox provider, billing software, CRM, website forms, marketing tools.
  2. Make sure your single SPF record includes each one.
  3. Set up DKIM for each sending service.
  4. Publish a DMARC record in monitoring mode, review the reports, then tighten it.
  5. Send invoices from a consistent, recognisable address with a monitored reply-to.
  6. Keep subjects plain: document type, number and your business name.
  7. Include a short text summary and a pay link, not only an attachment.
  8. Keep billing contacts up to date and act on bounces.
  9. Send a test invoice to accounts at the major providers you and your customers use, and check where it lands.

If you're still collecting by bank transfer with reminders, our payment reminder email templates work best once deliverability is sorted.

How CentraPoint helps

CentraPoint gives you two ways to send customer emails such as invoices, receipts, reminders and portal sign-in codes:

  • Sent by CentraPoint (the default). Emails go through CentraPoint's mail server and show your company name with CentraPoint's sending address, for example "Your Business via CentraPoint". This keeps SPF and DKIM valid without any DNS changes on your side, and replies go to your company email.
  • Your own SMTP server. To send from your own domain, enter your SMTP details under Settings, use Test connection and Send test email to check them, then switch it on. Make sure your domain's SPF and DKIM records cover that server.

Every email appears in the email log with its status (sent, failed or skipped), and failed emails can be resent. Templates are editable with a live preview, invoice and receipt PDFs are attached automatically, and every invoice includes a pay-by-link. See the email documentation.

Frequently asked questions

Why do my invoices go to spam but my normal emails don't?

Usually because invoices are sent by a different service, such as billing software, that isn't authorised in your domain's SPF and DKIM records. Add every sending service to your DNS records.

Do I need DMARC if I already have SPF?

Yes. SPF alone doesn't tell receiving servers what to do when a check fails, and it doesn't give you reports. DMARC adds both and makes your domain harder to spoof.

Can I send invoices from a Gmail or Outlook.com address?

You can, but it looks less professional and you lose control over authentication for your brand. A domain you own, or a service that sends on your behalf correctly, is more reliable.

How do I check if my SPF, DKIM and DMARC are set up?

Send an email to an account you control at a major provider and view the message headers or "show original" option, which reports whether SPF, DKIM and DMARC passed. Your domain or email provider can also check the DNS records for you.

  • #email deliverability
  • #invoicing
  • #spf
  • #dkim
  • #dmarc