You sent the quote, the invoice or the password reset, and nothing came back. A week later the client mentions it was sitting in their junk. If you've got emails going to junk folder Outlook-side, take a breath: this is almost always fixable in under an hour, once you know which of two very different problems you actually have.
Quick Answer (as of September 2026): If mail you receive lands in Junk, check Outlook's junk filter level, your Blocked Senders list and your inbox rules. If mail you send lands in other people's Junk, the cause is almost always your domain. Fix SPF, DKIM and DMARC so all three pass, check your sending reputation, then confirm with the message headers. Most DNS fixes take effect within 24-48 hours.
Hostaccent's engineers resolve 20-30 client issues every day, and a business mailbox quietly landing in junk is one of the requests we see over and over. This guide follows the same sequence our team runs on those tickets, written so you can run it yourself without waiting on anyone.
60-second triage: send a plain test message (no links, no attachments) from the affected mailbox to a free outlook.com address you control. Inbox? Your domain is probably fine and the problem sits with the recipient. Junk? It's your sending setup, so focus on the domain and reputation sections below.
Why Are Emails Going to Junk Folder Outlook? Causes Ranked
A message in Junk was delivered. Microsoft accepted it, scored it and decided it was probably unwanted, and the reason is usually weak domain authentication, a reputation problem or a local setting.
What the Junk folder is really telling you
As of September 2026, Microsoft filters mail in two places. On the server, Exchange Online Protection gives every message a spam confidence level (SCL) from -1 to 9, where 5 or 6 normally means Junk and 7 to 9 means high-confidence spam. The classic Outlook desktop app can then run its own junk filter on top, using your Safe and Blocked Senders lists.
So when someone searches "Outlook sending my email to junk", they could mean Microsoft's servers, the Outlook app on one PC, or a rule nobody remembers creating. Changing the wrong layer wastes an afternoon.
Is it my Outlook, or my recipient's Outlook?
- Mail you receive goes to your Junk: start with the next section (settings, rules, blocked senders or a compromised account).
- Mail you send goes to their Junk: your domain can't prove who it is, or Microsoft doesn't trust it yet. Jump to the SPF, DKIM and DMARC steps.
- Only one company's staff see your mail in Junk: their Microsoft 365 tenant policy is the likely cause.
For sending-side problems, this is the order we'd check, based on the pattern in the email tickets that reach our queue:
- A broken SPF record. Two SPF records on one domain (which invalidates both), a CRM that was never added, or more than 10 DNS lookups.
- DKIM not signing with your domain. A tool signing with its own domain passes DKIM but fails DMARC alignment.
- No DMARC record, which leaves the domain looking unproven.
- Poor sending reputation: a noisy shared IP, no matching reverse DNS (PTR), or a new domain sending hundreds of messages on day one.
- A compromised mailbox or abused contact form.
- Content signals: URL shorteners, image-only messages, mismatched link domains.
From the Ticket Queue: According to Hostaccent's support-queue data (September 2026), brute-force and malware cases make up about 25% of monthly support tickets, with SSL problems at roughly 20%. That first number matters here: a hijacked mailbox or a spam-relaying contact form damages a domain's standing with Microsoft far faster than any DNS typo.
Fix authentication first. It's free and fully in your control.
Fix Your Own Inbox First: Outlook Settings and Rules
If legitimate mail arriving in your mailbox keeps landing in Junk, the fix lives in your Outlook settings, and it takes about 10 minutes.
In classic Outlook for Windows:
- Go to Home > Junk > Junk E-mail Options.
- On the Options tab, check the protection level. If it says High or Safe Lists Only, drop it to Low.
- Open Blocked Senders and remove any address or domain you actually want mail from. A single stray entry like
@gmail.comcan junk half your inbox. - Open Safe Senders and add the people and domains you always need.
- Go to File > Info > Manage Rules & Alerts and delete any rule that moves mail to Junk Email.
In Outlook on the web and the new Outlook for Windows: open Settings > Mail > Junk email for the Blocked and Safe lists, then Settings > Mail > Rules for rules. For a single message, right-click it in Junk and choose Mark as not junk, which also teaches the filter.
Should you stop Outlook junk filtering altogether with No Automatic Filtering? In our experience, that rarely helps a work mailbox. That option only switches off the desktop app's filter. Microsoft's server-side scoring still runs, so you lose a layer of protection and often don't fix the problem anyway.
When the rules aren't yours
Worry if everything suddenly goes to Junk, and you find rules you never created, or forwarding switched on to an address you don't recognise. That's a classic sign of an account takeover. Attackers hide replies from you so you won't notice the spam they're sending.
If you see that, act in this order:
- Change the mailbox password from a clean device.
- Delete the unknown rules and turn off forwarding.
- Use Sign out everywhere in your Microsoft account security settings (it can take up to 24 hours to end every session).
- Turn on two-step verification, and on cPanel check Email > Track Delivery for mail you didn't send.
A compromised account also explains many "my sent mail is suddenly junk" cases, so check this before touching DNS.
Fix Your Domain: SPF, DKIM and DMARC Step by Step
When your business email lands in junk at Outlook recipients, the fix is to make your domain provably yours. That means three DNS records that all pass and all align with the address in your From line.
SPF lists which servers may send for you, DKIM signs each message, and DMARC tells receivers what to do when either check fails. Microsoft wants at least one of SPF or DKIM to match your visible From domain.
Step 1: Publish one correct SPF record
Your domain needs exactly one TXT record at the root that starts with v=spf1. A typical record for a site on cPanel hosting that also sends through Microsoft 365 looks like this:
bashv=spf1 +a +mx include:spf.protection.outlook.com ~all
Only include services you really use, and merge every sender into this one record; never publish a second SPF line. The SPF specification in RFC 7208 caps evaluation at 10 DNS lookups, and going over produces a permanent error that fails SPF entirely, even when the syntax looks perfect.
On cPanel, Email > Email Deliverability shows whether SPF is valid and suggests a corrected record you can install in one click.
Step 2: Turn on DKIM signing
DKIM signs every message with a key published in your DNS. On cPanel, the same Email Deliverability screen generates a TXT record at default._domainkey.yourdomain.com; use a 2048-bit key where your DNS provider allows it.
If you send through Microsoft 365, enable DKIM for your custom domain in the Defender portal and publish the two CNAME records it gives you (selector1 and selector2). Each third-party sender needs DKIM set up with your domain, per the DKIM standard, RFC 6376.
Step 3: Add a DMARC record
Create a TXT record at _dmarc.yourdomain.com:
bashv=DMARC1; p=none; rua=mailto:[email protected]; fo=1
Start with p=none so nothing gets blocked while you watch the reports. Once every legitimate sender passes for two to four weeks, move to p=quarantine, then p=reject. Cloudflare's guide to DMARC records explains each tag.
Step 4: Check reverse DNS
Your sending IP needs a PTR record pointing to a hostname that resolves back to the same IP. On shared hosting that's your host's job, so ask them to confirm it.
Pro Tip: If your DNS runs through Cloudflare, make sure the A record for your mail hostname (usually
mail.yourdomain.com) is set to DNS only, the grey cloud. Proxied records break mail traffic, and we've seen that one orange cloud cause days of mystery delivery problems.
Live mailbox and no time to experiment? Our engineers can set up SPF, DKIM and DMARC for your domain for a small one-time fee, and you'll see the exact quote before we touch anything. Already hosting with Hostaccent? Then email authentication issues like this are simply covered by support, free. Have an engineer fix it
Still seeing the mail error?
Share the bounce message, affected domain, and sending route. We can investigate DNS, authentication, reputation, and server configuration across providers.
Fix Reputation, Content and Office 365 Junk Placement
Passing SPF, DKIM and DMARC proves who you are. It doesn't prove Microsoft should trust you, so if all three pass and mail still lands in Junk, your reputation or content is the next suspect.
Since May 5, 2025, Microsoft has required any domain sending more than 5,000 messages a day to Outlook.com, Hotmail.com and Live.com addresses to pass SPF and DKIM and publish a DMARC record of at least p=none that aligns with one of them. Senders who don't comply can have messages rejected with the bounce code 550 5.7.515, which is a harder failure than a junk-folder placement.
Most small businesses sit far below that volume, but the same signals still decide where their mail lands.
How do I rebuild a damaged sender reputation?
Reputation recovers through boring, consistent behaviour. Stop the cause first (a hacked account, a bought list, a spamming form), then:
- Send steadily. A new or recovering domain should ramp volume gradually over days, not jump from 20 to 2,000 messages overnight.
- Clean your list. Remove addresses that bounce and people who haven't opened anything in six months.
- Check the IP. Running your own mail server? Register it with Microsoft's Smart Network Data Services (SNDS) to see how Microsoft rates it.
- Watch your limits. Shared plans cap hourly sending, and hitting that ceiling mid-campaign causes deferrals that look like delivery problems. Our guide on shared hosting resource limit exceeded errors covers how those caps work.
What about Office 365 junk folder emails?
When only one organisation's staff find your mail in Junk, their Microsoft 365 tenant is usually deciding. Its admins control anti-spam policies, transport rules and block lists, none of which you can change. Ask their IT team to run a message trace on one of your emails and, if it looks clean, add your domain to their Tenant Allow/Block List.
Content that trips the filter
Even with perfect records, URL shorteners, one-big-image messages, a Reply-To on another domain and links that don't match your brand all push the score up. Phishing-style wording ("verify your account") is scored cautiously too. Website mail is a frequent culprit. A contact form that sends "From" the visitor's address fails authentication every time. Send from your own domain and put the visitor in Reply-To instead; our walkthrough on WordPress emails going to spam shows the SMTP setup step by step.
How to Confirm the Fix and Keep Mail Out of Junk
Confirm the fix in the message headers rather than trusting one test that reached the inbox, then keep watching, because deliverability drifts whenever you add a new tool.
We use a routine we call The Three-Header Check. Send a test to an outlook.com address, open it, and view the full headers (in classic Outlook, open the message and go to File > Properties; on the web, open the message menu and choose View > View message details). Then read three things:
- Authentication-Results. You want
spf=pass,dkim=pass,dmarc=passandcompauth=pass. Any "fail" or "none" sends you back to section 4. - X-Forefront-Antispam-Report. Find the
SCL:value. A score of 1 or lower is good; 5 or above explains the Junk placement even when authentication passes. Microsoft's reference on anti-spam message headers decodes the other fields, includingSFV:BLK, which means the recipient blocked you. - Received. The first external hop should show your sending server's hostname, and that hostname should match its PTR record.
Here's a self-contained rule worth remembering: in September 2026, a business email that shows dmarc=pass and an SCL of 1 or lower in its Outlook headers has no authentication or filtering problem, so any remaining Junk placement comes from a recipient rule, block list or tenant policy.
Insider Insight: Test to both a free outlook.com address and a Microsoft 365 business mailbox. They use different policy layers, and when mail reaches one inbox but the other's Junk, you instantly know whether reputation or a tenant setting is to blame.
Keeping it fixed
- Every time you add a service that sends as your domain, add it to SPF and turn on its DKIM the same day.
- Read DMARC reports weekly for the first month, keep two-step verification on every mailbox, and allow days to weeks for a damaged reputation to recover.
- If you run your own Postfix or Exim server with spam and virus scanning, watch memory closely; a starved server delays and drops mail. See why a VPS runs out of RAM for the diagnosis steps.
- Audit your site the same way you audit mail. A plugin sending notifications through PHP's default mailer is a common leak, and our WordPress site slow diagnosis guide shows how to spot misbehaving plugins.
Fixed It, or Still Stuck? Your Next Step
You now know that most emails going to junk folder Outlook-side come down to three DNS records and one habit.
Fixed it? Keep the habit: new sending tool, same-day SPF and DKIM. On a well-managed host, this upkeep is support's job, not yours. The engineers at Hostaccent look after mail servers, DNS and rDNS around the clock. You can start on the Economy shared hosting plan at Economy, $1.99/mo, renewing at the same $1.99/mo, with a 30-day money-back guarantee. It's not built for bulk marketing above 5,000 emails a day, though.
Still stuck? Open a ticket with our engineers. It's a small one-time fee, and you'll see the exact quote before any work starts.
Frequently Asked Questions
Why are my emails going to junk folder Outlook even though SPF passes?
SPF alone isn't enough. Microsoft also checks DKIM, DMARC alignment and your sending reputation, so a message can pass SPF and still score high enough to land in Junk. The most common hidden cause is DMARC failing because SPF passed for your host's bounce domain rather than your own From domain. Open the headers, look for dmarc=pass and compauth=pass, and fix whichever one fails before looking at content or reputation.
How long does it take for Outlook to stop junking my emails?
Correct DNS records usually take effect within a few hours and almost always within 24-48 hours, depending on your TTL. If the Junk placement came from damaged reputation, such as a hacked mailbox, a bought list or a spam burst from a contact form, recovery is slower. Expect several days to a few weeks of steady, clean sending before Microsoft's filters fully trust the domain again.
Does adding myself to Safe Senders fix it for my recipients?
No. Your Safe Senders list only affects mail arriving in your own mailbox. Each recipient controls their own list, so you could ask a few key clients to add your address, but that doesn't fix the underlying cause and won't help with anyone new. For mail you send, the real fix is passing SPF, DKIM and DMARC, plus a clean reputation. Treat recipient safe-listing as a temporary patch while you correct your domain.
Do I need DMARC if I only send a few emails a day?
Yes. Microsoft's strict 5,000-a-day rule only applies to high-volume senders, but its filters weigh DMARC for everyone, and a domain without it looks less trustworthy. A DMARC record also stops criminals from spoofing your domain, which protects your reputation. Starting with p=none costs nothing, blocks nothing, and sends you reports showing every service mailing as your domain, which often uncovers forgotten tools that were quietly failing authentication.
Will moving to a different host fix junk folder problems?
Only if the host was the cause, such as a poorly rated shared IP or a missing PTR record. Your DNS records travel with your domain, so broken SPF, DKIM or DMARC will follow you to any new provider until you correct them. When sites move to Hostaccent, our team checks and rebuilds those records as part of the migration, because we've found that carrying over an old broken SPF record is one of the easiest mistakes to miss.
How do I check if my domain or sending IP is on a blocklist?
Use a public blocklist checker such as MXToolbox, which tests your IP and domain against dozens of lists in one go. For Microsoft specifically, register your sending IP with Smart Network Data Services (SNDS) to see its rating, and use the Outlook.com sender support form to request a review. If you're on shared hosting, the IP belongs to your host, so send them the listing details and ask them to investigate and request removal.






Discussion
Have a question or tip about this topic? Share it below — your comment will appear after review.