Inbox filters weigh many signals before they deliver a message. A missing authentication record, a sudden burst of mail, or a list of old addresses can be enough to send a legitimate message to spam. Most of that is fixable.
We set this up with you. Unsure which product or DNS mode you are on? Open a support ticket and we will check.
This article is about outbound mail (what other people see). If mail you are expecting never arrives, start with Email is not sending or receiving. On LochStudios Mail, also check Spam and the quarantine.
Which mail product sends
Filters judge the product that actually sends the message. Do not mix those paths.
- Shared hosting (mailboxes you create in cPanel): send from that account. Shared hosting allows 1000 emails per hour. Open the hosting service in the portal and click Log in to cPanel. Webmail is Roundcube. See Create an email account.
- LochStudios Mail (hosted business email): send from that service. It allows 2000 emails per hour. Open the mail service in the portal and click Log in to WebMail. See What is Axigen webmail and how to sign in. Plans are on LochStudios Mail.
- A VPS you manage: you send from that server. Credentials and the console are on the server in the portal.
- Another sending system (a newsletter tool, a CRM, or mail that is not hosted here): they must appear in your one SPF string and publish their own DKIM selector.
A cPanel mailbox will not authenticate as LochStudios Mail, and the other way around.
The hostname is usually mail.yourdomain.com once DNS and MX point at that product.
Authentication (start here)
Most inbox problems we see are missing or incomplete SPF, DKIM, and DMARC. Publish those three on the live zone before you chase subject lines.
AtlasDNS is the default. Add records under Domains → the domain → DNS. When the domain uses AtlasDNS, the nameservers are:
ns1.atlasdns.net.au
ns2.atlasdns.net.au
ns3.atlasdns.net.au
If the domain is in cPanel Hosting DNS mode (paired with a shared hosting service), open the hosting service, click Log in to cPanel, and use Email Deliverability or the Zone Editor. Do not send the domain to a third-party DNS host.
Unsure which mode you are on? Open a support ticket.
SPF
What goes wrong: the receiving server cannot tell that our mail product (or your newsletter tool) is allowed to send as the domain.
What to do:
- Publish one SPF TXT on the root name. See SPF records explained.
- Include every system that sends as the domain in that single string.
- Do not publish two SPF records. Merge senders.
DKIM
What goes wrong: the message is not signed, or the public key in DNS does not match the private key on the product that sent it.
What to do:
- Enable DKIM on the product that actually sends. See DKIM explained.
- Shared hosting: Email Deliverability in cPanel.
- LochStudios Mail: copy the DKIM value from the mail service in the portal.
- Publish the public TXT exactly as shown. No extra spaces.
DMARC
What goes wrong: inboxes have no policy for mail that fails SPF or DKIM alignment, so they treat the domain as less trustworthy.
What to do:
- Publish one
_dmarcTXT starting atp=none. See DMARC explained. - Tighten to
p=quarantineorp=rejectonly after reports show your real senders passing.
We can set all three with you if you open a support ticket.
Reverse DNS (PTR)
Receiving servers also look up the sending IP and expect a PTR that matches the mail hostname.
- Shared hosting and LochStudios Mail: we set reverse DNS on the sending addresses. You do not add a PTR in the domain DNS.
- A VPS you manage: if that server sends mail, the PTR should match the hostname it uses. Open a support ticket and we will set it.
You can confirm a PTR with nslookup -type=PTR and the sending IP. If you do not have the IP, we will look it up for you.
Content that looks like spam
Authentication gets you most of the way. The words and links still matter.
Subject lines
Avoid all-caps, stacked punctuation, and fake urgency.
Examples to avoid:
- "ACT NOW!!!! LIMITED TIME!!!!"
- "You've won $1,000,000 - click here"
- "URGENT: Verify your account NOW"
Use a clear subject. Do not use "$$$", "no-reply", or "urgent" as the whole headline.
Links and attachments
- Link to your own domain (
yourdomain.com/action) instead of a URL shortener. - Prefer a PDF over
.exeor a random.zip. - A few links is fine. A wall of them is not.
From name and address
The visible From address must be a domain you have authenticated with SPF and DKIM.
- Do not pretend to be Gmail, a bank, or a payment company.
- Use a real sender name:
Customer Support <support@yourdomain.com>. - Sign every address that sends as the domain, including no-reply addresses on that product.
Layout
- Send both HTML and a plain-text part (multipart/alternative).
- Keep the design simple. Standard fonts, reasonable colours.
- Heavy tables and hidden text are a classic spam pattern.
Sending behaviour
Volume
A sudden jump in volume looks like a compromised mailbox or a bulk blast.
- Shared hosting: 1000 emails per hour from the account.
- LochStudios Mail: 2000 emails per hour from the mailbox.
- Split large sends. If you regularly need more, open a support ticket and we will talk through a better setup.
A dedicated newsletter tool is often the right place for marketing mail. Add their include to SPF and their DKIM selector. Do not replace our records if we still send day-to-day mail as the same domain.
Outbound mail on LochStudios Mail goes through our spam filtering. That is expected. It is not a client-settings problem.
New sending IP (VPS)
A fresh VPS IP has no sending history. Warm it up: small volumes first, then more over days. Shared hosting and LochStudios Mail send from our mail infrastructure, so you do not warm those IPs yourself.
If you suspect the sending address has a poor reputation, open a support ticket. We will check.
Bounces and engagement
- Confirm addresses (double opt-in) before you add them.
- Remove addresses that bounce, and do it straight away.
- Drop people who have not opened mail in six months, or run a re-engagement send first.
- Aim to keep bounce rates low (under about 5%).
Unsubscribes
If people cannot leave, they mark the message as spam instead.
- Put a one-click unsubscribe in the footer.
- Honour it immediately (do not make them confirm).
- Only mail people who asked for it.
- This also matches email laws in Australia (the Spam Act) and elsewhere (CAN-SPAM, GDPR).
Lists
Spam traps and bought lists
Send only to people who opted in. Do not buy lists. Remove addresses that bounce more than once.
Quiet recipients
Filters learn from opens and clicks. A list that never engages trains them the wrong way.
- Segment by engagement.
- Write less often if daily mail is being ignored.
- Remove or re-engage after six months of silence.
Server and SMTP
Shared hosting and LochStudios Mail already require SMTP authentication. You cannot run them as an open relay.
- In the mail app, turn SMTP login on. Username is the full address. See IMAP, POP, and SMTP settings for shared hosting, or Axigen server settings for LochStudios Mail.
- Send only as addresses that exist on that product.
- On a VPS you manage, require SMTP AUTH and do not accept mail from the world for relay.
If you think a mailbox was used to send spam (unknown messages in Sent, or people complaining), change that mailbox password and open a support ticket.
Check a real message
- Confirm SPF, DKIM, and DMARC are published on the live zone (AtlasDNS or cPanel Hosting).
- Send a test from the same product you use every day:
- Shared hosting: Access Webmail (Roundcube).
- LochStudios Mail: Log in to WebMail on the mail service.
- Send it to an inbox you control. In Gmail, open the message, use the three-dot menu, choose Show original, and look for
SPF=PASS,DKIM=PASS, andDMARC=PASS. - Wait for DNS propagation if you just changed records.
- If mail is not leaving the account at all, start with Email is not sending or receiving.
If you would rather we read the headers, open a support ticket and include the domain, the product, and a recent example (sender, recipient, subject, and time).
Quick wins
- Publish SPF and enable DKIM today. Then add DMARC at
p=none. - Clean the list: bounces, test addresses, and people who never open mail.
- Use a real From name and your own domain.
- Keep the message focused. A handful of links is enough.
- Add an unsubscribe footer to anything that is not a one-to-one reply.
When to open a support ticket
- Authentication looks right and mail still lands in spam
- You want us to publish SPF, DKIM, and DMARC with you
- You need reverse DNS on a VPS
- You think a mailbox was compromised
- You regularly hit the hourly send limit
- You are moving a large list onto a new VPS IP and want a warm-up plan
Tell us the domain, which product sends, and one recent example. We will take it from there.
Next steps
Set SPF, DKIM, and DMARC in that order, test a real message, then keep the list clean. Most delivery issues settle once authentication is in place.
Related
- SPF records explained
- DKIM explained
- DMARC explained
- MX records and how email routing works
- Email is not sending or receiving
- Access Webmail
- What is Axigen webmail and how to sign in
- Manage spam and the quarantine in Axigen
- DNS record types explained
- Edit DNS with the Zone Editor
- Point your domain at your hosting