Email Deliverability

Why your offering memorandum emails land in spam

Updated September 2026 · by DeshTEK Digital

You spent weeks on the OM. The blast went out Tuesday morning. Half the list never saw it.

Short answer: Most CRE email that disappears fails on authentication, not content. Three DNS records decide it: SPF lists which servers may send as your domain, DKIM signs each message so it cannot be tampered with, and DMARC tells inboxes what to do when a message fails those checks. Since 2024, Gmail and Yahoo require bulk senders to authenticate, so a domain missing any of the three is far more likely to be filtered.

The three records, in plain English

RecordWhat it saysWhat goes wrong
SPFThese servers are allowed to send email as my domain.A new sending tool (CRM, marketing platform) is not listed, so its mail fails.
DKIMThis message carries my cryptographic signature.Not enabled at the provider, so forwarded or relayed mail cannot be verified.
DMARCIf a message fails SPF and DKIM, do this with it.Set to p=none, which only monitors — spoofed mail still lands.

What p=none actually means

A DMARC record with p=none is monitoring only: failures are reported to you, then delivered anyway. It is the right starting point while you find every legitimate sender, and the wrong place to stay. Once your reports are clean, move to quarantine, then reject, so mail forged in your firm's name is actually stopped.

Other reasons CRE email gets filtered

How to check yours

Look up your own domain's SPF and DMARC records, send a test to an address on Gmail and Outlook, and check whether the message shows as authenticated. Our Website Reputation & Blocklist Check tests SPF and DMARC alongside the major blocklists and returns a fix plan you can hand to whoever manages DNS.

In DeshTEK Digital

Run it on your own site

The free plan includes 5 credits a month — no credit card, no time limit.

Start free →

Frequently asked questions

Why do my commercial real estate emails go to spam?

Most often because the domain fails email authentication. SPF, DKIM and DMARC records tell receiving servers that your mail is genuine; if any is missing or misconfigured, Gmail and Outlook are far more likely to filter the message. A blocklisted sending IP or domain is the other common cause.

What is the difference between SPF, DKIM and DMARC?

SPF lists the servers allowed to send email for your domain. DKIM adds a cryptographic signature to each message so it can be verified. DMARC tells inbox providers what to do when a message fails SPF and DKIM — monitor it, quarantine it or reject it.

Is DMARC p=none good enough?

No. p=none only monitors: failing mail is still delivered, so anyone can spoof your domain. Use it to find your legitimate senders, then move to quarantine and finally reject.

Do I need a separate domain for cold outreach?

It is strongly advisable. Cold campaigns attract spam complaints, and keeping them on a separate domain means a bad campaign cannot damage the deliverability of your listing and transactional email.

Related