A green SPF, DKIM, and DMARC check does not guarantee inbox placement because authentication is not a receiver’s spam folder. The checker looked at published records and maybe one test hop. Gmail and Outlook still classify. Content, reputation, user reports, leftover MX, and list behavior all sit outside that green badge. MailerZ does not publish an inboxing percentage. Anyone who sells you one on a forwarding product is selling a number they cannot own.
Quick answer for spf dkim dmarc inbox placement
SPF says which hosts may use an envelope domain. IETF RFC 7208 — Sender Policy Framework (SPF) is that policy. DKIM signs headers. DMARC asks whether Header From aligns with a passing SPF or DKIM result and what to do if not. None of those RFCs assign a Primary tab. IETF RFC 5321 — Simple Mail Transfer Protocol delivers to MX. The mailbox provider then decides spam, promotions, or inbox.
A website checker often evaluates the records you published, or a simulated message from a lab. It does not sit in your customer’s account. It does not know their filter, their prior complaints, or whether you mixed a newsletter into reply SMTP. See email forwarding and features.
Forwarding adds a hop. MailerZ rewrites the envelope with SRS and leaves Header From intact. Authentication-Results on Gmail describe that hop. A pass there is good hygiene. It is not a placement SLA. Troubleshooting and tools help you read headers, not to promise a folder.
If mail is in spam after a green check, open original on a third mailbox. Confirm you are not looking at leftover MX. Confirm you did not blast a list. Then work the receiver’s tools (not spam, user filters). Do not republish DNS in a loop hoping the badge gets greener.
User problem and decision criteria
Founders paste a screenshot of a green trio into a ticket and write “so why spam?” Because the question assumed authentication equals placement. It never did. Seed-list companies sell percentages. Forwarding companies that repeat those percentages are outside their product. MailerZ will not invent one here.
Decision criteria: can you read Authentication-Results on a real received copy; is MX exclusive; is Header From intact; is the stream operational or a campaign; are you over a send-as hourly cap and retrying in ways that look automated; have users marked you as spam before.
Criteria that do not belong: a promised inbox rate, buying Workspace solely to “get inboxing,” or adding a second SPF record to please a checker. Duplicates cause permerror. They do not buy Primary.
New domains have no reputation. Green records on day one are necessary and insufficient. Warm-up folklore from ESPs does not translate to five MailerZ send-as messages an hour. Send real operational mail. Do not fake engagement.
User-level filters and blocked senders beat your DMARC. If the destination owner blocked the customer’s domain last year, your perfect auth will not unjam it. That is a Gmail setting, not MX.
Agencies should separate “auth is correct” from “folder is Primary” in every report. Mixing them trains clients to demand numbers nobody can warrant.
Catch-all FORWARD filling Gmail trains the filter that the destination is noisy. Hold unknown. A green DMARC on your outbound does not clean a cannon on inbound.
Technical mail flow
Inbound: MX, local-part, forward hop, destination filter. Auth on the last hop can pass while the filter files Promotions or spam. Envelope SRS does not choose a tab.
Outbound paid send-as: dashboard SMTP, your SPF/DKIM/DMARC. Receiver still classifies. Copy host, port, TLS or STARTTLS. Free cannot send-as. Caps exist. Bursting like a bot after a cap can look worse than waiting.
Checkers that only read DNS will stay green while leftover MX sends half your inbound to an abandoned host. The badge and the user story disagree. Trust the hop you can open.
Content heuristics—short links, sudden volume, lookalike brands—are receiver-side. This article will not list spam-trigger myths as MailerZ facts. It will say: do not expect DNS to override them.
Step-by-step setup / decision path
- Treat the green checker as homework done, not as go-live for a list.
- Confirm one MX set in public. Leftovers make “auth green, mail missing.”
- Confirm one SPF record. Duplicates are permerror, not extra safety.
- Send a unique operational message to a third mailbox. Open original. Record Authentication-Results and folder.
- Confirm Header From is intact on inbound forwards. Envelope may show SRS.
- Keep newsletters on an ESP. Keep receipts on SMTP. Mixing streams confuses filters and caps.
- If the folder is spam, use the receiver’s not-spam and check user filters. Do not republish MX as a placement fix.
- Do not ask MailerZ support for an inboxing percentage. They should not invent one.
Write the folder result in the ticket as observation, not as a KPI you will hit next week. Placement varies by recipient.
If you have no third mailbox, you do not have a placement test. Create one before you argue with a checker screenshot.
Failure modes and proof
Checker-only go-live: spam at customers. Proof: third mailbox folder versus the badge.
Leftover MX: missing mail, green DNS. Proof: public MX two companies.
Duplicate SPF: permerror under a pretty UI. Proof: two v=spf1.
List on reply SMTP: cap plus filter heat. Proof: volume versus Solo five per hour.
Header rewrite: auth looks odd, users distrust. Proof: original From.
Self-send: false inbox. Proof: no third party.
User block: perfect auth, still spam. Proof: destination blocked senders.
Catch-all cannon: destination trained as noisy. Proof: made-up local-part still arrives.
Promised percentage: vendor overclaim. Proof: they cannot see every inbox. Walk away.
Open relay “to improve inboxing”: 550. Opposite of helpful.
MailerZ workflow and product boundary
MailerZ is custom-domain aliasing and forwarding with optional paid send-as. Secuno LLC operates mailerz.net. The app is mail.mailerz.net. Not Workspace, not IMAP, not an open relay, not a placement warranty.
Envelope SRS. Headers intact. Exclusive MX. Hold unknown on Free. Sending DNS from the dashboard when you send. Free: no send-as. Solo forty dollars a year, fifteen aliases, ninety-day store, one hundred outgoing, five send-as per hour. Starter eight or eighty. Business nineteen or one hundred ninety. Agency thirty-nine or three hundred ninety. Quote pricing.
This page does not invent SOC 2, ISO, HIPAA, SLAs, or inboxing rates. A green check is hygiene. Placement is the receiver.
Cost, alternatives, and trade-offs
Seed-list tools cost money and still are not a guarantee. They are another sample. A Workspace seat does not buy Gmail’s filter for other people. An ESP is the right spend for campaigns that need list hygiene, not a magic inbox.
Doing nothing after a green check except arguing with customers costs more than one third-mailbox test.
Agencies should price “auth correct” and “folder observed” as different lines. Do not sell a number MailerZ will not print.
If the only goal is inbound aliases, you may not need DMARC theater. If you send, publish the dashboard trio once, correctly. Then stop chasing greener badges.
Reputation time is a cost. New domains wait in filters more often. That is not a MailerZ defect and not a reason to dual-publish MX.
Catch-all off is free placement hygiene for the destination inbox. Noise makes filters twitchy. Hold unknown.
Shared seed inboxes used by ten agencies will get a different folder than a real customer. If your “proof” is a seed, label it as a seed. Do not put that folder on a sales slide as if it were the market.
Language and script tricks—homograph domains, lookalike local-parts—are receiver problems. Your green DMARC on the real domain does not stop a lookalike from landing beside you in the same thread list. Teach customers to read the exact Header From, not the display name.
After you change nothing but a logo in the HTML, placement can still move. That is content and engagement, not a reason to delete DKIM. Keep the records stable. Change the stream or the ESP if the job is a campaign.
Green is published records, not Primary
A green SPF, DKIM, and DMARC check still does not guarantee inbox placement because checkers prove that records exist and often that a synthetic message aligned. Gmail and Outlook still classify. Promotions, spam, and filters are hop four. MailerZ does not publish an inboxing percentage. MailerZ does not sell an inbox SLA. Confirm /pricing for plan ceilings only. Treat the checker as proof of publication, not as a folder command.
Open original on a third mailbox and read Authentication-Results for the hop that actually arrived. Confirm exclusive MX so the hop you authenticated is the hop customers use. Leftover MX can make a checker look at a path senders do not take. Intact Header From matters because we do not rewrite it. Envelope SRS only. If another forwarder rewrote Header From, dest auth stories get noisier. Cite RFC 7208, RFC 6376, and RFC 7489 for what those records mean. They authenticate. They do not encrypt. They do not move a message to Primary.
Two SPF records permerror. One v=spf1. DKIM from the dashboard when you send. DMARC alignment is not a vault. TLS is a hop. MailerZ is not HIPAA, not SOC 2, not ISO 27001. A passing reject policy does not stop a human from forwarding a PDF. Confidentiality after delivery is the dest store and the human.
List blasts through reply SMTP train bulk filters. This hop is operational send-as with hourly and monthly caps. Free cannot finish send-as. Unauthorized send is 550. Do not warm up by mailing a scraped list. Self-send hides both auth and filters. Use a third mailbox.
What sales can say
You can say: exclusive MX, named aliases, hold unknowns, authenticated SMTP, SRS on envelope, no Header From rewrite, published auth records for send-as. You cannot say we guarantee Primary, we encrypt Gmail, we are HIPAA. Point questionnaires at /security. Store windows are recovery, not legal hold.
Dest 250 plus spam is delivered-to-the-store. Empty history is leftover MX or held/unnamed, not a failed DMARC. Do not rebuild aliases because a checker is green and a customer looks in Primary only.
A green checker and a spam folder
An operator pasted checker screenshots into a ticket. Authentication-Results at the dest showed pass. The message sat in spam because the subject looked like a blast and the volume hit a hourly spike. They asked MailerZ to “fix inboxing.” There is no such control here. They lowered volume, kept From an identity they created, probed one operational message, and the next dest filed it in a tab. Still not a promise.
A second operator had a green checker against leftover Google MX. Customers hit MailerZ on some paths and Google on others. Results looked random. Delete leftovers. Two views. New subject. Read auth on the hop that actually arrived.
Related: features, security, send and reply, troubleshooting. Google and Microsoft auth and spam docs. Commercial checkers nofollow if you cite a vendor. Do not invent feature parity with a ciphertext mailbox.
Placement proof that fits in a ticket
Unique operational subject. Third mailbox. Open original. Paste Authentication-Results. Name the folder. Print public MX. History accepted/forwarded if inbound. For outbound, history 250 and the dest folder. No list. No self-send. No second SPF. Start free to prove inbound first. Sign in if the zone already lives here.
Agencies keep checker screenshots per zone after every cut, then still probe. A green record on a leftover zone is a lie about the path. The next action is a dest original, not another checker brand. That is why a green SPF DKIM DMARC check still does not guarantee inbox placement.
Review after a plugin swap or a volume change. Caps are on /pricing. They are not a placement warranty.
Checker versus original, side by side
A checker often injects its own test message or only reads published DNS. Original at the dest is the path a human used. If the checker is green and original shows dkim=fail, another hop rewrote or you sent a different From than the checker assumed. MailerZ does not rewrite Header From on inbound. If inbound original fails DKIM, look at the sender’s path or a leftover forwarder, not at a request to “turn on encryption.” Auth is not confidentiality.
If original shows pass and the folder is spam, you have placement, not auth. Lower volume. Keep From a created identity. Do not add a second SPF. Do not buy a suite seat to move a tab. Do not promise Primary on a sales call. Cite dest vendor spam docs. Confirm /pricing for send-as caps only.
If the checker ran against a zone with leftover Google MX, throw the screenshot out. Print exclusive MailerZ MX on two views. Probe again. Read original again. Green records on the wrong owner are how tickets last a week.
Agencies attach checker plus original plus MX prints per client. One without the others is incomplete. Related: features, security, send and reply, troubleshooting. RFC 7208, RFC 6376, RFC 7489. Not SOC 2. Not HIPAA. Store windows are recovery, not legal hold. That is why a green SPF DKIM DMARC check still does not guarantee inbox placement.
Volume and From identity
Hourly send-as caps exist so this hop stays operational. Hitting the cap and retrying in a tight loop looks like bulk to dests. Queue. Upgrade the card if the product is really transactional at scale, or use a specialist and cite them. Do not treat a green checker as permission to mail a scraped list. From must be an identity you created. Catch-all does not mint a From. Free cannot finish send-as. Confirm /pricing.
Header From intact on inbound does not force Primary. Dest tabs still apply. Record the folder. Do not rewrite bodies to “look more personal.” We will not rewrite the body. Related: send and reply, security, features.
Tab versus spam versus missing
Promotions is not a bounce. Spam is not a 550 from MailerZ. Missing with empty history is leftover MX or hold. Missing with dest 250 is a folder you did not open. Name which of the four you have before you change DNS. A green checker does not distinguish them. Original plus MX print plus history does. Confirm /pricing for caps, not for a Primary promise. Related: troubleshooting, send and reply, features. RFC 7489 is alignment, not a tab.
Questionnaire sentence
Write: we publish SPF, DKIM, and DMARC for authenticated send-as; we do not rewrite Header From on inbound; envelope rewrite is SRS only; dest providers classify after 250; we do not sell an inbox-placement percentage; we are not SOC 2 and not HIPAA. Point at /security and /pricing. A green checker is not that sentence. Original plus folder plus MX print is the evidence. That is why a green SPF DKIM DMARC check still does not guarantee inbox placement.
If a prospect asks for a placement warranty, the honest next product is not this hop. Keep exclusive MX. Keep From an identity you created. Keep volume inside the card. Record the folder. Do not invent a percentage. Do not add a second SPF to “look greener.” Two v=spf1 records permerror and still do not move a message to Primary.
FAQ
- What is the safest way to handle spf dkim dmarc inbox placement?
- Treat a green checker as proof that published records exist, not as a placement guarantee. Open original on a third mailbox and read Authentication-Results for the hop that actually arrived. Confirm exclusive MX, intact Header From, and that you did not blast a list through reply SMTP. Filters live at Gmail and Outlook. MailerZ does not publish an inboxing percentage.
- Does this require a new mailbox?
- No. Placement is a receiver filter decision. A new IMAP seat does not turn a green checker into Primary. MailerZ is not webmail. Keep Gmail or Outlook as the store unless you need a suite for other reasons.
- Will it work with Gmail or Outlook?
- Those products apply their own spam and tab classification after authentication. A pass can still land in spam or Promotions. Self-send hides both auth and filters. Use a third mailbox and open original.
- What DNS records are involved?
- SPF, DKIM, and DMARC are the records a checker paints green. MX still decides who receives. Leftover MX can make the checker look at the wrong hop. Verification TXT is ownership, not placement. One SPF only—no duplicates.
- What should I test before production?
- Send a unique operational message to a third mailbox. Confirm Header From, Authentication-Results, and which folder it landed in. That folder is evidence, not a promise for every future recipient. Do not use a list blast as the first test.
Key takeaways
- A green SPF/DKIM/DMARC check is not inbox placement. Filters sit at the receiver.
- MailerZ does not publish an inboxing percentage. Do not buy one on a forwarder.
- Open original on a third mailbox. Read Authentication-Results and the folder.
- Exclusive MX and one SPF record are hygiene, not a Primary-tab SLA.
- Header From intact plus envelope SRS is the forwarding-safe pair.
- Do not blast lists through reply SMTP. Caps and filters both object.
- User blocks and prior complaints beat your green badge.
- Self-send and checker screenshots are not production proof.
Conclusion
Publish honest records. Prove the hop. Accept that folders are not yours to command. Anyone offering a placement guarantee on forwarding is answering a question their MX cannot see.
Use MailerZ for aliases and optional send-as. Use a third mailbox for truth. Use an ESP for lists. Do not confuse the three.