Home/Learn/Hosting and email

Hosting and email 6 min read

Why your contact form emails go to spam (and the 15-minute fix)

Contact form emails usually land in spam because your website sends them without proper authentication. Here is why it happens and how to fix it properly.

By Shaz, UK web designer

Your contact form emails go to spam because your website is sending them in a way that looks forged. Most WordPress sites send mail straight from the web server using PHP, with a "From" address on your domain, but without any proof that the server is allowed to send for that domain. Gmail, Outlook and other mailbox providers see an unauthenticated message claiming to be from you, and they bin it or file it as junk. The fix is to send form emails through a real, authenticated mailbox or email service using SMTP, and to make sure your domain's SPF, DKIM and DMARC records are in place. Done carefully, that takes about 15 minutes.

Why this happens: the short version

When someone fills in your form, WordPress builds an email and hands it to the web server to send. Three things commonly go wrong:

  • The server is not authorised. Your domain's SPF record lists the servers allowed to send email for you, typically Google Workspace, Microsoft 365 or your email host. Your web server is often not on that list.
  • There is no DKIM signature. Mail sent directly from PHP usually is not signed with your domain's DKIM key, so the receiver cannot verify it.
  • The From address does not match the sender. Some forms put the visitor's own email address in the From field. Your website is now pretending to be, say, a Gmail user, which is exactly what spammers do.

On top of that, shared hosting servers send email for many websites at once. If one of your neighbours is sending junk, the server's reputation suffers and your messages are judged by the company they keep.

Mailbox providers have tightened up in recent years. Google and Yahoo, for example, have published stricter requirements for senders, and authentication with SPF and DKIM is now expected rather than optional. Unauthenticated website mail that used to scrape through often does not any more.

How to confirm this is your problem

Before changing anything, spend two minutes checking:

  1. Submit your own contact form using a personal Gmail or Outlook address as the recipient if you can, or simply check the junk folder of the inbox that should receive it.
  2. Open the message and view the original or the full headers. In Gmail this is "Show original"; in Outlook it is under "View message source" or message details.
  3. Look for the lines showing SPF, DKIM and DMARC results. If you see fail, softfail, none or neutral against your domain, you have found the cause.

If no email arrives at all, not even in spam, the problem may be that your host blocks or limits PHP mail entirely. The fix below solves that too.

The 15-minute fix

You will need: admin access to WordPress, access to the mailbox you want the website to send from, and access to your DNS settings in case records are missing.

Step 1: pick a sending address on your own domain (2 minutes)

Choose a real address on your domain, for example website@yourbusiness.co.uk or your existing info@ address. Ideally create a dedicated mailbox or alias for it with your email provider. This is the address every form email will come from. Never use the visitor's address as the From address.

Step 2: install an SMTP plugin (3 minutes)

An SMTP plugin makes WordPress send mail by logging in to a proper mail service, just as your email app does, instead of using the web server. Popular free options include WP Mail SMTP, FluentSMTP and Post SMTP. Install one from Plugins, then Add New. Only use one SMTP plugin at a time.

Step 3: connect it to your email provider (5 minutes)

In the plugin settings, choose how to send:

  • Google Workspace or Microsoft 365: most SMTP plugins offer a direct connection that uses the provider's official sign-in (OAuth) rather than a stored password. Follow the plugin's setup wizard. This is usually the most reliable route.
  • Your host's email: use the SMTP server name, port and login details from your host's email settings page. Port 587 with TLS or port 465 with SSL are the usual choices.
  • A transactional email service: services built for website mail, such as Brevo, Mailgun, Postmark or Amazon SES, give you an API key or SMTP login. These are a good choice for busier sites or online shops. Check each provider's current free allowance and pricing, as these change.

Set the plugin's From Email to the address from Step 1 and tick the option to force that From address if it offers one, so other plugins cannot override it.

Step 4: fix your form's Reply-To (2 minutes)

Open your form's notification settings in Contact Form 7, WPForms, Gravity Forms, Fluent Forms or whatever you use. Make sure:

  • From is your own domain address.
  • Reply-To is set to the visitor's email field.

That way you can still click Reply and answer the customer directly, but the message itself is honestly sent by your domain.

Step 5: send a test and check the headers (3 minutes)

Use the plugin's test email feature, then submit the real form. Open the received message's original headers again. You want to see spf=pass, dkim=pass and ideally dmarc=pass.

If the test still fails: check your DNS

If SPF or DKIM are not passing, the records on your domain need attention. Log in to wherever your DNS is managed (check your nameservers if you are unsure) and look at your TXT records.

SPF

You need exactly one TXT record on your root domain starting with v=spf1. It must include whichever service is now sending your form mail. For example, if you use Microsoft 365 and a transactional service, both must be included in the same record. Two separate SPF records will cause failures.

DKIM

Your email provider or transactional service will give you DKIM records to add, usually a TXT or CNAME record on a name ending in ._domainkey. With Google Workspace and Microsoft 365, DKIM often has to be switched on in the admin console as well as added to DNS.

DMARC

If you have no DMARC record, add a TXT record on the name _dmarc. A gentle starting point is a monitoring policy such as v=DMARC1; p=none; rua=mailto:you@yourbusiness.co.uk. Once you are confident all your legitimate email passes, you can move to a stricter policy. Do not jump straight to a strict policy without checking, or you may block your own mail.

DNS changes can take a little while to be seen everywhere, so give it an hour before testing again if you have just added records.

Other things that can push form emails into spam

  • Spammy content: if bots are filling your form with junk links, those messages will be flagged and can hurt the sending address's reputation. Add spam protection to the form, such as a honeypot field, Cloudflare Turnstile or reCAPTCHA.
  • Sending to the same address you send from: some providers are suspicious of mail that appears to come from and go to the same mailbox. Using a separate sending address helps.
  • A blocklisted server: if you were using PHP mail on cheap shared hosting, the server IP may be on a blocklist. Switching to SMTP sidesteps this.
  • Your own filter rules: occasionally the culprit is a rule in your inbox. Mark a form email as "not spam" and add the sending address to your safe senders list.

Keep an eye on it

Most SMTP plugins can keep an email log, so you can see every message WordPress tried to send and whether it succeeded. Turn that on. Then put a reminder in your diary to submit your own contact form once a month. In my client work, broken contact forms are one of the most common silent problems: the site looks fine, but enquiries have been disappearing for weeks. A monthly test catches that before it costs you business.

If you want to understand email authentication properly, including how to tighten DMARC safely, the hosting, domains and email course covers it step by step.

Questions people ask

Do I need a paid email service to fix this?

Not necessarily. If you already pay for Google Workspace, Microsoft 365 or email with your host, you can usually send form mail through that account using an SMTP plugin. Transactional services are an option for busier sites.

Why should the From address not be the visitor's email?

Because your server is not authorised to send email on behalf of Gmail, Outlook or any other domain the visitor uses. Receivers treat that as spoofing. Put the visitor's address in Reply-To instead.

My emails pass SPF and DKIM but still go to spam. Why?

Authentication is the foundation, not a guarantee. Check for spammy submissions, make sure DMARC is set up, mark genuine messages as not spam, and check whether your sending address or domain appears on any blocklists.

Keep reading

All guides

Learn it properly, with help

Every course includes personal one-to-one tutoring with Shaz, a practical assessment and a 30-day money-back guarantee.