{"id":1216,"date":"2026-08-23T10:00:00","date_gmt":"2026-08-23T10:00:00","guid":{"rendered":"https:\/\/www.kailashcloud.com\/blog\/?p=1216"},"modified":"2026-08-13T14:02:50","modified_gmt":"2026-08-13T14:02:50","slug":"emails-going-to-spam-solutions-cpanel","status":"publish","type":"post","link":"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/","title":{"rendered":"Emails Going to Spam? 9 Easy Ways to Fix It in cPanel"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">You created a professional email address on your domain, sent your first message to a customer, and then found out days later that it was sitting in their spam folder. Nothing looked wrong on your side. The message was sent, it left your outbox, and cPanel reported no errors.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Emails going to spam is one of the most common problems with domain email, and it is almost never caused by what you wrote. In most cases, the receiving mail server could not confirm that the message really came from your domain, so it treated it as suspicious.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The good news is that the checks these servers run are predictable. Once you understand what they are looking for, you can fix the problem in cPanel yourself, usually in under an hour, without any technical background.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This guide explains why emails going to spam happens, how to fix each cause in cPanel step by step, what changes if your DNS is managed by Cloudflare, how to test whether the fix worked, and what to do when every check passes but the problem stays.<\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_87_1 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#Quick_Answer_How_to_Stop_Emails_Going_to_Spam_in_cPanel\" >Quick Answer: How to Stop Emails Going to Spam in cPanel<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#A_Few_Terms_You_Will_See_in_This_Guide\" >A Few Terms You Will See in This Guide<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#Why_Emails_Go_to_Spam_in_the_First_Place\" >Why Emails Go to Spam in the First Place<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#Step_1_Run_the_Email_Deliverability_Tool_in_cPanel\" >Step 1: Run the Email Deliverability Tool in cPanel<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#Step_2_Check_and_Fix_Your_SPF_Record\" >Step 2: Check and Fix Your SPF Record<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#Step_3_Enable_DKIM_Signing\" >Step 3: Enable DKIM Signing<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#Step_4_Check_Your_DMARC_Record\" >Step 4: Check Your DMARC Record<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#How_to_add_or_edit_it_manually\" >How to add or edit it manually<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#Step_5_Check_Your_MX_Records_and_Email_Routing\" >Step 5: Check Your MX Records and Email Routing<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#How_to_check_your_MX_records\" >How to check your MX records<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#How_to_check_Email_Routing\" >How to check Email Routing<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#If_Your_DNS_Is_Managed_by_Cloudflare\" >If Your DNS Is Managed by Cloudflare<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#Which_records_to_add\" >Which records to add<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-14\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#The_mistake_that_breaks_mail_on_Cloudflare\" >The mistake that breaks mail on Cloudflare<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-15\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#Step_6_Check_Whether_Your_Server_IP_Is_Blacklisted\" >Step 6: Check Whether Your Server IP Is Blacklisted<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-16\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#Step_7_Look_at_the_Message_Itself\" >Step 7: Look at the Message Itself<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-17\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#Step_8_Test_Before_You_Trust_It\" >Step 8: Test Before You Trust It<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-18\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#Step_9_Move_Your_Email_to_Google_Workspace\" >Step 9: Move Your Email to Google Workspace<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-19\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#Frequently_Asked_Questions\" >Frequently Asked Questions<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-20\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#Why_are_my_emails_going_to_spam_even_though_SPF_and_DKIM_are_set_up\" >Why are my emails going to spam even though SPF and DKIM are set up?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-21\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#How_do_I_know_if_I_even_have_an_SPF_record\" >How do I know if I even have an SPF record?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-22\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#Do_MX_records_affect_whether_my_email_goes_to_spam\" >Do MX records affect whether my email goes to spam?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-23\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#What_should_my_MX_record_point_to\" >What should my MX record point to?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-24\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#What_is_Email_Routing_in_cPanel\" >What is Email Routing in cPanel?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-25\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#How_do_I_set_up_SPF_DKIM_and_DMARC_when_my_DNS_is_on_Cloudflare\" >How do I set up SPF, DKIM, and DMARC when my DNS is on Cloudflare?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-26\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#Should_my_mail_record_be_proxied_in_Cloudflare\" >Should my mail record be proxied in Cloudflare?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-27\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#How_long_does_it_take_for_SPF_and_DKIM_changes_to_work\" >How long does it take for SPF and DKIM changes to work?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-28\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#Can_I_have_more_than_one_SPF_record\" >Can I have more than one SPF record?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-29\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#Where_do_I_add_a_DMARC_record_in_cPanel\" >Where do I add a DMARC record in cPanel?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-30\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#What_is_a_good_DMARC_policy_to_start_with\" >What is a good DMARC policy to start with?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-31\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#Does_an_SSL_certificate_affect_whether_my_email_goes_to_spam\" >Does an SSL certificate affect whether my email goes to spam?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-32\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#Why_does_my_mail_reach_Gmail_but_not_Outlook\" >Why does my mail reach Gmail but not Outlook?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-33\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#Can_a_hacked_website_cause_my_emails_to_go_to_spam\" >Can a hacked website cause my emails to go to spam?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-34\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#Will_switching_to_Google_Workspace_fix_spam_problems_immediately\" >Will switching to Google Workspace fix spam problems immediately?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-35\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#Do_I_have_to_move_my_website_if_I_use_Google_Workspace_for_email\" >Do I have to move my website if I use Google Workspace for email?<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-36\" href=\"https:\/\/www.kailashcloud.com\/blog\/emails-going-to-spam-solutions-cpanel\/#Final_Thoughts\" >Final Thoughts<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Quick_Answer_How_to_Stop_Emails_Going_to_Spam_in_cPanel\"><\/span>Quick Answer: How to Stop Emails Going to Spam in cPanel<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">To stop emails going to spam, log in to cPanel and open <strong>Email Deliverability<\/strong> under the Email section. Click <strong>Repair<\/strong> on any domain showing a problem, which installs the correct <strong>SPF<\/strong>, <strong>DKIM<\/strong>, and usually a default <strong>DMARC<\/strong> record. Then confirm your <strong>MX records<\/strong> are correct, check that your server IP is not blacklisted, and test your address with a mail testing tool.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"A_Few_Terms_You_Will_See_in_This_Guide\"><\/span>A Few Terms You Will See in This Guide<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you have never edited DNS before, these five words appear throughout the guide. You do not need to memorise them, but knowing roughly what they mean will make every step easier.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>DNS<\/strong> is the address book of the internet. It stores small pieces of information about your domain that other computers can look up.<\/li>\n\n\n\n<li><strong>A DNS record<\/strong> is one line in that address book. Each record has a type, a name, and a value.<\/li>\n\n\n\n<li><strong>A TXT record<\/strong> is a record that holds plain text. SPF, DKIM, and DMARC are all just TXT records with a specific format.<\/li>\n\n\n\n<li><strong>An MX record<\/strong> tells other mail servers where to deliver mail addressed to your domain.<\/li>\n\n\n\n<li><strong>Zone Editor<\/strong> is the tool inside cPanel where you view and edit all of these records.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If you would like a fuller explanation before you start, our <a href=\"https:\/\/www.kailashcloud.com\/blog\/what-is-dns-guide\/\">beginner&#8217;s guide to DNS records and nameservers<\/a> covers how the whole system fits together.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_Emails_Go_to_Spam_in_the_First_Place\"><\/span>Why Emails Go to Spam in the First Place<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">When your mail server delivers a message, the receiving server has to decide within seconds whether it is genuine. It does not know you. It only knows what your domain&#8217;s DNS records claim, and whether the message matches those claims.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There are six common reasons a message fails that test:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>No SPF record<\/strong>, so the receiver cannot confirm your server is allowed to send mail for your domain.<\/li>\n\n\n\n<li><strong>No DKIM signature<\/strong>, so the receiver cannot confirm the message was not altered on the way.<\/li>\n\n\n\n<li><strong>No DMARC policy<\/strong>, so the receiver has no instruction about what to do when the first two checks fail.<\/li>\n\n\n\n<li><strong>The sending IP is blacklisted<\/strong>, usually because another website on the same shared server sent spam.<\/li>\n\n\n\n<li><strong>The message itself looks like spam<\/strong>, because of link-heavy content, misleading subject lines, or attachments.<\/li>\n\n\n\n<li><strong>You have no sending history<\/strong>, which makes a brand-new domain look untrusted for its first few weeks.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The first three are entirely within your control, and fixing them solves the majority of cases.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here is the simplest way to picture the three records you are about to check:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>SPF is the guest list.<\/strong> It names the servers allowed to send mail for your domain.<\/li>\n\n\n\n<li><strong>DKIM is the tamper-proof seal.<\/strong> It proves the message was not changed after it left.<\/li>\n\n\n\n<li><strong>DMARC is the instruction to the doorman.<\/strong> It says what to do if the guest list or the seal does not check out.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Step_1_Run_the_Email_Deliverability_Tool_in_cPanel\"><\/span>Step 1: Run the Email Deliverability Tool in cPanel<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Before changing anything manually, let cPanel tell you what is wrong.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Log in to cPanel, find the <strong>Email<\/strong> section, and open <strong>Email Deliverability<\/strong>. If you cannot see it, type &#8220;deliverability&#8221; into the search box at the top of the dashboard.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The page lists every domain on your account with a status beside each one:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Valid<\/strong> means SPF and DKIM are configured correctly.<\/li>\n\n\n\n<li><strong>Problems Exist<\/strong> means one or both records are missing or incorrect.<\/li>\n\n\n\n<li><strong>DNS Errors Occurred<\/strong> means your DNS is managed elsewhere, such as at <strong>Cloudflare<\/strong> or your domain registrar, so cPanel cannot edit the records itself.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1969\" height=\"799\" src=\"https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-email-deliverability-status.png\" alt=\"Email Deliverability page in cPanel showing domain status\" class=\"wp-image-1223\" srcset=\"https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-email-deliverability-status.png 1969w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-email-deliverability-status-300x122.png 300w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-email-deliverability-status-1024x416.png 1024w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-email-deliverability-status-768x312.png 768w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-email-deliverability-status-1536x623.png 1536w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-email-deliverability-status-528x214.png 528w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-email-deliverability-status-1056x429.png 1056w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-email-deliverability-status-820x333.png 820w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-email-deliverability-status-1240x503.png 1240w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-email-deliverability-status-1920x779.png 1920w\" sizes=\"auto, (max-width: 1969px) 100vw, 1969px\" \/><figcaption class=\"wp-element-caption\">The status column tells you immediately whether your records need repair<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">If a domain shows a problem, click <strong>Repair<\/strong>. cPanel shows you the records it wants to create and asks you to confirm. On current versions this single button installs SPF and DKIM together, and usually a basic DMARC record as well, so most people never need to write a record by hand.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If your domain shows <strong>DNS Errors Occurred<\/strong>, cPanel cannot make the change for you, but it will still display the exact records you need. Copy them and add them wherever your DNS is managed. The Cloudflare section below covers the most common case.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>How long does this take to work?<\/strong> DNS changes are not instant. Give them at least an hour before testing, and up to 24 hours before assuming something is wrong.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Step_2_Check_and_Fix_Your_SPF_Record\"><\/span>Step 2: Check and Fix Your SPF Record<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">SPF (<strong>Sender Policy Framework<\/strong>) is a DNS record that lists which mail servers are allowed to send email for your domain. If a message arrives from a server that is not on that list, the receiver treats it with suspicion.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>First, see what you already have<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Open <strong>Zone Editor<\/strong> in cPanel, click <strong>Manage<\/strong> beside your domain, and filter the list by <strong>TXT<\/strong>. An SPF record starts with <code>v=spf1<\/code>. A free lookup tool such as <a href=\"https:\/\/mxtoolbox.com\/SuperTool.aspx\" target=\"_blank\" rel=\"noopener\">MXToolbox<\/a> shows you the same thing if you enter your domain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What an SPF record looks like<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A basic SPF record looks like this:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>v=spf1 +mx +a +ip4:192.0.2.1 ~all<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Do not copy this example into your DNS.<\/strong> The IP address shown is a placeholder used for documentation. Always use the exact record cPanel generates for your domain, because it contains your own server&#8217;s address.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The parts that matter:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>v=spf1<\/code> identifies it as an SPF record.<\/li>\n\n\n\n<li><code>+mx<\/code> and <code>+a<\/code> allow the servers listed in your MX and A records.<\/li>\n\n\n\n<li><code>ip4:<\/code> lists the specific IP address of your mail server.<\/li>\n\n\n\n<li><code>~all<\/code> tells receivers to treat anything else as suspicious rather than rejecting it outright.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Notice that <code>+mx<\/code> depends on your MX records being correct. This is why Step 5 matters even though it looks like a receiving-mail issue.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Two rules are worth remembering. First, <strong>a domain can only have one SPF record.<\/strong> If you add a second one instead of editing the first, both stop working. Second, if you send mail through any other service, such as a newsletter tool or a contact form plugin using an external SMTP provider, that service must be included in the same record.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Step_3_Enable_DKIM_Signing\"><\/span>Step 3: Enable DKIM Signing<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">DKIM (<strong>DomainKeys Identified Mail<\/strong>) adds a digital signature to every message you send. The matching key sits in your DNS as a TXT record. When the message arrives, the receiver compares the two and confirms that the message came from your domain and was not changed on the way.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You do not have to create any of this yourself. cPanel generates the key pair for you. On the <strong>Email Deliverability<\/strong> page, if DKIM shows a problem, click <strong>Repair<\/strong> and confirm.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If your DNS is managed elsewhere, copy the DKIM record cPanel displays and add it as a TXT record at your DNS provider. The record name will look something like <code>default._domainkey<\/code>, and the value is a long string of characters. Copy the whole thing, exactly as shown, with no spaces added or removed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">DKIM matters more than most people expect. Large providers treat an unsigned message from a domain that has previously sent signed messages as a warning sign, so once you enable it, keep it enabled.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Step_4_Check_Your_DMARC_Record\"><\/span>Step 4: Check Your DMARC Record<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">DMARC tells receiving servers what to do when a message fails SPF or DKIM, and asks them to send you reports about it. Without DMARC, each provider guesses. With it, you decide.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>You may not need to create this manually.<\/strong> On current cPanel versions, the Repair button in Step 1 usually installs a default DMARC record along with SPF and DKIM. Check before doing anything else:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Open <strong>Email Deliverability<\/strong>, click <strong>Manage<\/strong> beside your domain, and look for the DMARC section. If a record is shown as valid, you are done. <\/li>\n\n\n\n<li>Or open <strong>Zone Editor<\/strong>, filter by TXT, and look for a record on the name <code>_dmarc<\/code>.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The default record cPanel installs is usually the minimal version:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>v=DMARC1; p=none;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">That is enough to satisfy the check. It is worth customising it, though, because the default does not include a reporting address, so you never see the reports that tell you which of your senders are failing.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1947\" height=\"808\" src=\"https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-dmarc-txt-record.png\" alt=\"DMARC TXT record in the cPanel\" class=\"wp-image-1225\" srcset=\"https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-dmarc-txt-record.png 1947w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-dmarc-txt-record-300x124.png 300w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-dmarc-txt-record-1024x425.png 1024w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-dmarc-txt-record-768x319.png 768w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-dmarc-txt-record-1536x637.png 1536w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-dmarc-txt-record-528x219.png 528w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-dmarc-txt-record-1056x438.png 1056w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-dmarc-txt-record-820x340.png 820w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-dmarc-txt-record-1240x515.png 1240w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-dmarc-txt-record-1920x797.png 1920w\" sizes=\"auto, (max-width: 1947px) 100vw, 1947px\" \/><figcaption class=\"wp-element-caption\">DMARC TXT record in the cPanel<\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_to_add_or_edit_it_manually\"><\/span>How to add or edit it manually<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Do this if no DMARC record exists, or if you want to add a reporting address.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>In cPanel, open <strong>Zone Editor<\/strong> under the Domains section.<\/li>\n\n\n\n<li>Click <strong>Manage<\/strong> beside your domain.<\/li>\n\n\n\n<li>Click <strong>Add Record<\/strong>, or <strong>Edit<\/strong> if a <code>_dmarc<\/code> record already exists.<\/li>\n\n\n\n<li>Set <strong>Type<\/strong> to <code>TXT<\/code>.<\/li>\n\n\n\n<li>Set <strong>Name<\/strong> to <code>_dmarc<\/code> (cPanel completes it to <code>_dmarc.yourdomain.com<\/code>).<\/li>\n\n\n\n<li>Paste this into the <strong>Record<\/strong> field, using your own address:<\/li>\n<\/ol>\n\n\n\n<pre class=\"wp-block-code\"><code>v=DMARC1; p=none; rua=mailto:you@yourdomain.com<\/code><\/pre>\n\n\n\n<ol start=\"7\" class=\"wp-block-list\">\n<li>Click <strong>Save Record<\/strong>.<\/li>\n<\/ol>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1593\" height=\"448\" src=\"https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-zone-editor-dmarc-txt-record.png.png\" alt=\"Adding a DMARC TXT record in the cPanel Zone Editor\" class=\"wp-image-1227\" srcset=\"https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-zone-editor-dmarc-txt-record.png.png 1593w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-zone-editor-dmarc-txt-record.png-300x84.png 300w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-zone-editor-dmarc-txt-record.png-1024x288.png 1024w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-zone-editor-dmarc-txt-record.png-768x216.png 768w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-zone-editor-dmarc-txt-record.png-1536x432.png 1536w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-zone-editor-dmarc-txt-record.png-528x148.png 528w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-zone-editor-dmarc-txt-record.png-1056x297.png 1056w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-zone-editor-dmarc-txt-record.png-820x231.png 820w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-zone-editor-dmarc-txt-record.png-1240x349.png 1240w\" sizes=\"auto, (max-width: 1593px) 100vw, 1593px\" \/><figcaption class=\"wp-element-caption\">Adding a DMARC TXT record in the cPanel Zone Editor<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What the policy means<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><code>p=none<\/code> means &#8220;do not block anything yet, just tell me what is happening.&#8221; Run this for a few weeks and read the reports that arrive at the address you entered. Once you are confident that all your legitimate mail passes, you can tighten the policy to <code>p=quarantine<\/code> and later <code>p=reject<\/code>, which stops other people from sending mail pretending to be your domain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Do not start at <code>p=reject<\/code>.<\/strong> If any of your legitimate senders are missing from SPF, that setting will block your own mail.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The four records at a glance<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Record<\/th><th>What it proves<\/th><th>Where it lives<\/th><th>Set up in cPanel?<\/th><\/tr><\/thead><tbody><tr><td><strong>SPF<\/strong><\/td><td>Which servers may send for your domain<\/td><td>TXT record on your domain<\/td><td>Yes, via Email Deliverability<\/td><\/tr><tr><td><strong>DKIM<\/strong><\/td><td>The message was not altered in transit<\/td><td>TXT record on a key name<\/td><td>Yes, via Email Deliverability<\/td><\/tr><tr><td><strong>DMARC<\/strong><\/td><td>What to do when SPF or DKIM fails<\/td><td>TXT record on <code>_dmarc<\/code><\/td><td>Usually yes, worth customising<\/td><\/tr><tr><td><strong>MX<\/strong><\/td><td>Tells other servers where to deliver your mail<\/td><td>MX record on your domain<\/td><td>Yes, created with the account<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Step_5_Check_Your_MX_Records_and_Email_Routing\"><\/span>Step 5: Check Your MX Records and Email Routing<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">MX records are the part everyone forgets, because they look like an incoming-mail setting. They affect outgoing mail too, in two ways.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">First, if your SPF record uses <code>+mx<\/code>, it authorises whatever your MX records point to. If those records are wrong or point to an old host, your SPF quietly authorises the wrong server.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Second, cPanel decides where to deliver mail for your own domain based on a setting called Email Routing. Get it wrong and messages either loop back to your server or never arrive.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_to_check_your_MX_records\"><\/span>How to check your MX records<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Open <strong>Zone Editor<\/strong> in cPanel and click <strong>Manage<\/strong> beside your domain.<\/li>\n\n\n\n<li>Filter the list by <strong>MX<\/strong>.<\/li>\n\n\n\n<li>For mail hosted on your cPanel server, you should see one record pointing at <code>mail.yourdomain.com<\/code> with a priority of <code>0<\/code> or <code>10<\/code>.<\/li>\n\n\n\n<li>If you use Google Workspace or another mail provider, the MX records should point at that provider instead, and there should be no leftover records pointing at your old server.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_to_check_Email_Routing\"><\/span>How to check Email Routing<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>In cPanel, open <strong>Email Routing<\/strong> under the Email section.<\/li>\n\n\n\n<li>Select your domain.<\/li>\n\n\n\n<li>Choose <strong>Local Mail Exchanger<\/strong> if your mailboxes are on this server.<\/li>\n\n\n\n<li>Choose <strong>Remote Mail Exchanger<\/strong> if your mail is handled elsewhere, such as Google Workspace.<\/li>\n<\/ol>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1614\" height=\"975\" src=\"https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-email-routing-local-remote.png\" alt=\"Email Routing settings in cPanel showing Local and Remote Mail Exchanger options\" class=\"wp-image-1228\" srcset=\"https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-email-routing-local-remote.png 1614w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-email-routing-local-remote-300x181.png 300w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-email-routing-local-remote-1024x619.png 1024w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-email-routing-local-remote-768x464.png 768w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-email-routing-local-remote-1536x928.png 1536w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-email-routing-local-remote-528x319.png 528w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-email-routing-local-remote-1056x638.png 1056w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-email-routing-local-remote-820x495.png 820w, https:\/\/www.kailashcloud.com\/blog\/wp-content\/uploads\/2026\/08\/cpanel-email-routing-local-remote-1240x749.png 1240w\" sizes=\"auto, (max-width: 1614px) 100vw, 1614px\" \/><figcaption class=\"wp-element-caption\">Choose Remote Mail Exchanger when your mail is handled by Google Workspace.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Leaving this on Local while your MX records point to Google is one of the most common reasons mail disappears entirely after a Workspace migration. The server sees mail for your domain, assumes it is responsible for it, and delivers it to a local mailbox nobody checks.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"If_Your_DNS_Is_Managed_by_Cloudflare\"><\/span>If Your DNS Is Managed by Cloudflare<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Cloudflare is the most common reason cPanel reports <strong>DNS Errors Occurred<\/strong>. When your domain uses Cloudflare&#8217;s nameservers, cPanel can generate the correct records but cannot install them, so you add them at Cloudflare yourself.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Which_records_to_add\"><\/span>Which records to add<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In cPanel, open <strong>Email Deliverability<\/strong> and click <strong>Manage<\/strong> beside your domain. Copy each suggested value, then in Cloudflare go to <strong>DNS \u2192 Records \u2192 Add record<\/strong> and create:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Type<\/th><th>Name<\/th><th>Value<\/th><th>Proxy status<\/th><\/tr><\/thead><tbody><tr><td>TXT<\/td><td><code>@<\/code> (or your domain)<\/td><td>The SPF value from cPanel<\/td><td>Not applicable<\/td><\/tr><tr><td>TXT<\/td><td><code>default._domainkey<\/code><\/td><td>The DKIM value from cPanel<\/td><td>Not applicable<\/td><\/tr><tr><td>TXT<\/td><td><code>_dmarc<\/code><\/td><td><code>v=DMARC1; p=none; rua=mailto:you@yourdomain.com<\/code><\/td><td>Not applicable<\/td><\/tr><tr><td>MX<\/td><td><code>@<\/code><\/td><td><code>mail.yourdomain.com<\/code>, priority 0<\/td><td>Not applicable<\/td><\/tr><tr><td>A<\/td><td><code>mail<\/code><\/td><td>Your server&#8217;s IP address<\/td><td><strong>DNS only (grey cloud)<\/strong><\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">TXT and MX records are never proxied, so there is no cloud icon to worry about on those. The A record is where people get caught.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_mistake_that_breaks_mail_on_Cloudflare\"><\/span>The mistake that breaks mail on Cloudflare<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The <code>mail<\/code> record must be set to DNS only, not Proxied.<\/strong> If the cloud icon is orange, Cloudflare hides your server&#8217;s real IP address behind its own. Web traffic still works, because Cloudflare proxies web traffic. Mail does not, because Cloudflare does not proxy SMTP, IMAP, or POP3 connections. The result is a mail app that cannot connect and outgoing mail that fails authentication checks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Click the orange cloud beside the <code>mail<\/code> record until it turns grey. The same applies to any <code>webmail<\/code> or <code>cpanel<\/code> records you use for mail access.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cloudflare&#8217;s own <a href=\"https:\/\/developers.cloudflare.com\/dns\/manage-dns-records\/how-to\/create-dns-records\/\" target=\"_blank\" rel=\"noopener\">DNS records documentation<\/a> walks through the add-record screen if you have not used it before.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Step_6_Check_Whether_Your_Server_IP_Is_Blacklisted\"><\/span>Step 6: Check Whether Your Server IP Is Blacklisted<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If all your records are correct and mail still lands in spam, the problem may not be your domain at all.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On shared hosting, your messages leave from an IP address shared with other websites on the same server. If one of those sites is compromised and starts sending spam, the whole IP can end up on a blacklist, and your legitimate mail suffers with it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To check, find your server&#8217;s IP address in cPanel. It appears under <strong>General Information<\/strong> in the sidebar, usually labelled <strong>Shared IP Address<\/strong>. If you cannot find it, your hosting support team can tell you in seconds. Then enter that IP into a public blacklist lookup such as <a href=\"https:\/\/mxtoolbox.com\/blacklists.aspx\" target=\"_blank\" rel=\"noopener\">MXToolbox Blacklist Check<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the IP is listed, contact your hosting provider rather than trying to delist it yourself. They can identify the source, stop it, and submit the delisting request on your behalf.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the compromised account turns out to be yours, clean the site before requesting delisting. Our guide on <a href=\"https:\/\/www.kailashcloud.com\/blog\/why-websites-get-hacked\/\">why websites get hacked<\/a> covers how to find and close the entry point.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Step_7_Look_at_the_Message_Itself\"><\/span>Step 7: Look at the Message Itself<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Authentication gets your message accepted. The content decides whether it lands in the inbox or the promotions and spam folders.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A few habits make a measurable difference:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Write a plain, accurate subject line.<\/strong> Words like <em>free<\/em>, <em>urgent<\/em>, <em>winner<\/em>, and rows of exclamation marks are classic spam signals.<\/li>\n\n\n\n<li><strong>Keep the link count low<\/strong>, especially shortened links, which hide their destination.<\/li>\n\n\n\n<li><strong>Avoid sending a single large image<\/strong> with almost no text. Filters cannot read images and treat them as evasion.<\/li>\n\n\n\n<li><strong>Always include a plain text version<\/strong> if you send HTML mail. Most mail apps do this automatically.<\/li>\n\n\n\n<li><strong>Send to people who expect your mail.<\/strong> Bulk sending to a purchased list is the fastest way to damage a domain&#8217;s reputation permanently.<\/li>\n\n\n\n<li><strong>Set up a signature with your real business details.<\/strong> It is a small trust signal, and it costs nothing.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Step_8_Test_Before_You_Trust_It\"><\/span>Step 8: Test Before You Trust It<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Do not assume the fix worked because one test message reached your own Gmail account. Test properly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Open <a href=\"https:\/\/www.mail-tester.com\/\" target=\"_blank\" rel=\"noopener\">Mail Tester<\/a>, copy the temporary address it shows you, and send a normal message to it from your domain address. Then return to the page and click the button to see your score.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It returns a score out of ten along with a breakdown of exactly what passed and what failed: SPF, DKIM, DMARC, blacklist status, and content warnings.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Aim for 9 or 10 out of 10. Anything below 7 usually means one of the records is still missing or incorrect, and the report will tell you which one.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Test again from a different address a few days later. Reputation builds gradually, so a domain that scores well but has no sending history may still see the occasional message filtered for the first week or two.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Step_9_Move_Your_Email_to_Google_Workspace\"><\/span>Step 9: Move Your Email to Google Workspace<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Sometimes every record is correct, the IP is clean, the content is fine, and mail still ends up filtered. At that point the limitation is the shared sending environment, not your configuration, and there is nothing left to fix inside cPanel.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The reliable answer is to stop sending business mail from the shared server and use <strong>Google Workspace<\/strong> instead. Your messages then leave from Google&#8217;s own infrastructure, which carries one of the strongest sending reputations on the internet, so the shared-IP problem disappears completely.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is worth doing when:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Your mail keeps getting filtered<\/strong> even after SPF, DKIM, and DMARC all pass.<\/li>\n\n\n\n<li><strong>You send a high volume of mail.<\/strong> Shared hosting applies hourly sending limits that a busy support or sales team will hit.<\/li>\n\n\n\n<li><strong>Deliverability is business critical.<\/strong> If a missed order or enquiry costs real money, dedicated mail infrastructure pays for itself quickly.<\/li>\n\n\n\n<li><strong>Your mailbox storage keeps filling up<\/strong>, since cPanel mailboxes share disk space with your website files.<\/li>\n\n\n\n<li><strong>You want more than mail<\/strong>, such as Drive, Docs, Meet, and shared calendars under the same business addresses.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Two things people usually worry about, and neither is a problem in practice. <strong>Your website does not move.<\/strong> It stays on your current hosting exactly as it is, because only the MX records in your DNS change to point at Google. And <strong>your addresses do not change<\/strong> either, so <em><code>info@yourdomain.com<\/code><\/em> keeps working, along with every address you have already printed or shared.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Two settings to get right during the switch: replace your old MX records completely rather than adding Google&#8217;s alongside them, and set Email Routing in cPanel to <strong>Remote Mail Exchanger<\/strong> as described in Step 5. You will also still need SPF, DKIM, and DMARC records, but they point at Google instead of your server, and Workspace walks you through creating them during setup.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Frequently_Asked_Questions\"><\/span>Frequently Asked Questions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_are_my_emails_going_to_spam_even_though_SPF_and_DKIM_are_set_up\"><\/span>Why are my emails going to spam even though SPF and DKIM are set up?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The most common remaining causes are a missing or minimal DMARC record, a blacklisted server IP, incorrect MX records, or a domain with no sending history. Test your address with a mail testing tool to see which check is failing.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_do_I_know_if_I_even_have_an_SPF_record\"><\/span>How do I know if I even have an SPF record? <span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Open Zone Editor in cPanel, click Manage beside your domain, and filter by TXT. An SPF record starts with <code>v=spf1<\/code>. A free lookup tool shows the same information if you enter your domain.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Do_MX_records_affect_whether_my_email_goes_to_spam\"><\/span>Do MX records affect whether my email goes to spam? <span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Indirectly, yes. If your SPF record uses the <code>+mx<\/code> mechanism, it authorises whatever your MX records point to, so incorrect MX records can cause SPF to authorise the wrong server.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_should_my_MX_record_point_to\"><\/span>What should my MX record point to? <span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">For mail hosted on your cPanel server, it should point to <code>mail.yourdomain.com<\/code> with priority 0. If you use Google Workspace or another provider, it should point at their servers instead, with no leftover records for the old host.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_is_Email_Routing_in_cPanel\"><\/span>What is Email Routing in cPanel? <span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">It tells the server whether your mailboxes are local or hosted elsewhere. Set it to Local Mail Exchanger when mail is on your cPanel server, and Remote Mail Exchanger when it is handled by a provider such as Google Workspace.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_do_I_set_up_SPF_DKIM_and_DMARC_when_my_DNS_is_on_Cloudflare\"><\/span>How do I set up SPF, DKIM, and DMARC when my DNS is on Cloudflare? <span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Copy each record from cPanel&#8217;s Email Deliverability page and add it in Cloudflare under DNS, Records, Add record. All three are TXT records. Cloudflare does not proxy TXT or MX records, so no proxy setting is involved.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Should_my_mail_record_be_proxied_in_Cloudflare\"><\/span>Should my mail record be proxied in Cloudflare? <span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No. The <code>mail<\/code> A record must be set to DNS only, shown by a grey cloud. Cloudflare does not proxy mail connections, so an orange cloud breaks both sending and receiving.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_long_does_it_take_for_SPF_and_DKIM_changes_to_work\"><\/span>How long does it take for SPF and DKIM changes to work?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">DNS changes usually take effect within an hour, but can take up to 24 to 48 hours to reach every mail server. Wait at least a few hours before testing again.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Can_I_have_more_than_one_SPF_record\"><\/span>Can I have more than one SPF record?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No. A domain must have exactly one SPF record. If you use another sending service, add it to the existing record instead of creating a second one.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Where_do_I_add_a_DMARC_record_in_cPanel\"><\/span>Where do I add a DMARC record in cPanel?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Open Zone Editor, click Manage beside your domain, then Add Record. Set the type to TXT, the name to <code>_dmarc<\/code>, and paste your DMARC policy into the record field.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_is_a_good_DMARC_policy_to_start_with\"><\/span>What is a good DMARC policy to start with?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Start with <code>p=none<\/code>, which reports problems without blocking anything. Once you confirm that all your legitimate mail passes, move to <code>p=quarantine<\/code> and then <code>p=reject<\/code>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Does_an_SSL_certificate_affect_whether_my_email_goes_to_spam\"><\/span>Does an SSL certificate affect whether my email goes to spam?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Not directly. SSL secures the connection between your mail app and the server. Deliverability depends on your DNS authentication records instead. That said, both matter for a professional setup.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_does_my_mail_reach_Gmail_but_not_Outlook\"><\/span>Why does my mail reach Gmail but not Outlook?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Each provider weighs the signals differently, and Microsoft is stricter about DMARC and sender reputation. A domain that passes Gmail but fails Outlook usually has DMARC missing or a weak sending history.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Can_a_hacked_website_cause_my_emails_to_go_to_spam\"><\/span>Can a hacked website cause my emails to go to spam?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Yes. A compromised site can be used to send spam from your account, which gets the server IP blacklisted. Clean the site first, then ask your host to request delisting.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Will_switching_to_Google_Workspace_fix_spam_problems_immediately\"><\/span>Will switching to Google Workspace fix spam problems immediately?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">It removes the shared-IP reputation problem, which is the most common stubborn cause. You still need SPF, DKIM, and DMARC records pointing at Google, and Workspace guides you through those during setup.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Do_I_have_to_move_my_website_if_I_use_Google_Workspace_for_email\"><\/span>Do I have to move my website if I use Google Workspace for email?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No. Your website stays on your current hosting. Only the MX records in your DNS change so mail is delivered to Google instead of your server, and your existing addresses keep working.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Final_Thoughts\"><\/span>Final Thoughts<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Emails going to spam is almost always a configuration problem rather than a content problem. Run the Email Deliverability tool in cPanel and click Repair, confirm the DMARC record it created is there, check your MX records and Email Routing, make sure your server IP is clean, and test the result with a mail testing tool before sending anything important.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If your DNS is managed by Cloudflare, the records are the same but you add them at Cloudflare rather than in cPanel, and the <code>mail<\/code> record must stay unproxied.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Work through the steps in order and most domains go from being filtered to reaching the inbox reliably. If you are new to DNS, do them one at a time and wait an hour between changes so you can see what each one fixed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the problem persists after all of that, the limitation is the shared sending environment rather than anything you have configured wrongly. That is the point to move your business email to <a href=\"https:\/\/www.kailashcloud.com\/google-workspace-in-nepal\">Google Workspace<\/a>, which removes the shared reputation problem entirely. Your website stays where it is, your addresses stay the same, and only your MX records change.<\/p>\n","protected":false},"excerpt":{"rendered":"You created a professional email address on your domain, sent your first message to a customer, and then&hellip;","protected":false},"author":4,"featured_media":1230,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"csco_display_header_overlay":false,"csco_singular_sidebar":"","csco_page_header_type":"","csco_page_load_nextpost":"","csco_post_video_location":[],"csco_post_video_location_hash":"","csco_post_video_url":"","csco_post_video_bg_start_time":0,"csco_post_video_bg_end_time":0,"csco_post_video_bg_volume":false,"footnotes":""},"categories":[42],"tags":[73,72],"class_list":["post-1216","post","type-post","status-publish","format-standard","has-post-thumbnail","category-domain-email","tag-email-deliverability","tag-emails-going-to-spam","cs-entry","cs-video-wrap"],"_links":{"self":[{"href":"https:\/\/www.kailashcloud.com\/blog\/wp-json\/wp\/v2\/posts\/1216","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kailashcloud.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kailashcloud.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kailashcloud.com\/blog\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kailashcloud.com\/blog\/wp-json\/wp\/v2\/comments?post=1216"}],"version-history":[{"count":6,"href":"https:\/\/www.kailashcloud.com\/blog\/wp-json\/wp\/v2\/posts\/1216\/revisions"}],"predecessor-version":[{"id":1231,"href":"https:\/\/www.kailashcloud.com\/blog\/wp-json\/wp\/v2\/posts\/1216\/revisions\/1231"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kailashcloud.com\/blog\/wp-json\/wp\/v2\/media\/1230"}],"wp:attachment":[{"href":"https:\/\/www.kailashcloud.com\/blog\/wp-json\/wp\/v2\/media?parent=1216"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kailashcloud.com\/blog\/wp-json\/wp\/v2\/categories?post=1216"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kailashcloud.com\/blog\/wp-json\/wp\/v2\/tags?post=1216"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}