Skip to content
FormSubmit
Email Deliverability

Contact Form Emails Going to Spam? Causes and Fixes

Contact form emails going to spam or never arriving? Learn why DIY form mail fails, how SPF, DKIM and DMARC work, and a checklist to fix email deliverability.

FormSubmit Team

5 min read

Contact form notification email landing in a spam folder next to SPF, DKIM and DMARC records

Contact form emails going to spam is almost always a sending problem, not a content problem: the message is sent from an unauthenticated server, often pretending to be the visitor's address, so mailbox providers treat it as spoofed. Fix it by sending from an authenticated domain, putting the visitor's address in Reply-To, and publishing SPF, DKIM and DMARC records.

A missed lead is expensive, and form notifications not received is one of the most common complaints from site owners. The frustrating part is that everything looks fine from the website: the visitor sees a thank-you message, but the email never shows up. This guide explains why, then walks through the fixes and a troubleshooting checklist.

Why contact form emails are going to spam

The From address is the visitor's email

Many DIY scripts and older plugins set the From header to whatever the visitor typed, so the email appears to come from jane@gmail.com. But your web server is not authorized to send mail for Gmail. Receiving servers check that, see the mismatch and filter or reject the message. This is exactly what phishing looks like, so providers are strict about it.

No SPF, DKIM or DMARC for the sending domain

Even when the From address is on your own domain, mail sent from a server that your DNS does not authorize will fail authentication. Without SPF, DKIM and DMARC, receivers have no proof the message is legitimate.

Shared hosting IP reputation

Cheap shared hosting puts many sites on one IP address. If any of them sends spam, the shared IP's reputation suffers, and your legitimate notifications are judged by the company they keep.

PHP mail() and wp_mail defaults

PHP's mail() function hands the message to the server's local mail program with minimal configuration. WordPress's wp_mail uses it by default. The result is often email with no DKIM signature, a generic envelope sender, and a hostname that does not match your domain. That combination is why wp_mail spam complaints are so common.

Spammy content and test messages

Content matters less than authentication, but it can tip a borderline message over. Notifications full of links (often from spam submissions), all-caps text or empty subjects look suspicious. Repeated "test test test" submissions can also train your own filters.

How to fix contact form email deliverability

1. Send from your domain, reply to the visitor

Use a fixed sender like forms@yourdomain.com and set the visitor's address as Reply-To:

text
From: Website Forms <forms@yourdomain.com>
Reply-To: Jane Doe <jane@gmail.com>
Subject: New contact form message from Jane Doe

You can still hit Reply in your inbox and answer Jane directly, and the message passes authentication because it really comes from your domain.

2. Publish SPF, DKIM and DMARC

These three DNS records work together:

RecordWhat it does
SPFLists which servers may send mail for your domain
DKIMAdds a cryptographic signature that proves the message was not altered and was sent by an authorized service
DMARCTells receivers what to do when SPF or DKIM fail, and requires them to align with the From domain

Example records (your email provider gives you the exact values):

text
example.com.                      TXT  "v=spf1 include:_spf.your-email-provider.com ~all"
selector1._domainkey.example.com. TXT  "v=DKIM1; k=rsa; p=MIIBIjANBgkqh..."
_dmarc.example.com.               TXT  "v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com"

A few practical notes:

  • A domain should have only one SPF record. Merge include: entries rather than adding a second record.
  • Start DMARC with p=none to collect reports, then move to quarantine or reject once all legitimate senders pass.
  • DNS changes can take time to propagate. Test with a fresh message after updating.

3. Use a transactional email provider

Instead of sending from your web server, route form mail through a transactional email service or an authenticated SMTP account. They handle IP reputation, DKIM signing and bounce handling, and they give you delivery logs. In WordPress, an SMTP plugin can point wp_mail at such a service.

4. Allowlist the sender in your inbox

Once mail is authenticated, help your own mailbox learn. Add the sending address to your contacts, mark any misfiled notification as "Not spam", and create a filter that always delivers it to the inbox. This is especially useful in shared or corporate mailboxes with aggressive filtering.

5. Filter spam before it is emailed

If bots are submitting your form, your notifications will contain spammy links that hurt their reputation. Block spam at the form with a honeypot, timing check and content filters so only real messages are emailed. See how to stop form spam.

Troubleshooting checklist

When form notifications are not received, work through this in order:

  1. Confirm the submission actually arrived, either in your form tool's dashboard or your server logs. If it did not, the problem is the form, not email.
  2. Check the spam, junk, promotions and quarantine folders, including any admin quarantine in your email platform.
  3. Inspect the headers of a notification that did arrive for SPF, DKIM and DMARC results.
  4. Verify the From address is on a domain you control and the visitor's address is only in Reply-To.
  5. Make sure your domain has exactly one SPF record that includes your sending service.
  6. Look for bounces or errors in your sending service's logs.
  7. Send a test with a plain, realistic message rather than "test".
  8. Add the sender to your contacts and create an inbox filter.

How a form backend handles notification email

If you would rather not run mail infrastructure for a contact form, a form backend takes the sending off your hands. Your form posts to the backend, and the backend emails you from its own sending domain, which the provider is responsible for authenticating and maintaining.

With FormSubmit, email notifications are sent from notifications@formsubmit.app with Reply-To set to the submitter, so you reply straight from your inbox. Spam is filtered before anything is emailed, and the dashboard keeps every submission, so a filtered email never means a lost lead. If something does go missing, the email notifications docs cover the checks, from the Spam tab to the delivery log.

html
<form action="https://formsubmit.app/f/YOUR_FORM_ID" method="POST">
  <input type="text" name="name" required>
  <input type="email" name="email" required>
  <textarea name="message" required></textarea>
  <input type="hidden" name="_subject" value="New message from the website">
  <input type="text" name="_gotcha" tabindex="-1" autocomplete="off" style="display:none">
  <button type="submit">Send</button>
</form>

Add notifications@formsubmit.app to your contacts on day one. If you are moving away from a mailto: link or a PHP script, our comparison of mailto forms and form backends explains the trade-offs.

You can generate a working form in the form generator and start on the free plan; pricing lists what each plan includes.

Last updated .

Frequently asked questions

Why do my contact form emails go to spam?

Usually because the email claims to be from the visitor's address, is sent from a server not authorized for your domain, or lacks SPF, DKIM and DMARC alignment. Receiving providers treat that like spoofing.

Should the From address be the person who filled in the form?

No. Send from an address on a domain you control and authenticate, and put the visitor's email in the Reply-To header so replies still go to them.

Why does wp_mail end up in spam?

By default WordPress sends through the server's PHP mail function, often from a shared hosting IP with no domain authentication. Routing it through an authenticated SMTP or transactional email provider usually fixes it.

Do I need SPF, DKIM and DMARC for a contact form?

If your server or app sends email as your domain, yes. Major mailbox providers expect senders to authenticate, and unauthenticated mail is far more likely to be filtered or rejected.

Related resources

Keep reading

Your form backend is 60 seconds away

Sign up with Google or email, create a form, paste the endpoint. Free forever for small sites — no credit card.