Dynamics 365·9 min read·By Solzet

Dynamics 365 Marketing Emails Landing in Spam and Taking Transactional Mail With Them

When marketing sends from Dynamics 365 have damaged your domain reputation so badly that invoices and HR mail are now blocked, stop the damage before diagnosing it. Pause marketing sends. Route critical transactional mail through a separate, properly authenticated subdomain, or replace attachments with secure portal links and confirm urgent items by phone. Then diagnose: read the authentication results in the headers of a message that landed in spam, verify SPF, DKIM and DMARC alignment for the sending domain, and check whether marketing and transactional mail share a domain at all. Recover reputation by sending only to engaged recipients, warming volume up gradually and suppressing every address whose consent you cannot prove.

What should you do first when marketing email has got invoices and HR mail blocked?

Contain it. Every marketing send made while reputation is damaged makes the recovery longer, and the business cost of blocked invoices and payroll or HR notices is far higher than a delayed newsletter.

  1. Pause marketing sends. Stop live journeys that send email and cancel scheduled sends in Customer Insights - Journeys, and tell everyone who can press send why.
  2. List the critical transactional mail: invoices, remittances, payslip and HR notices, password resets, contract documents. Note which system sends each one and from which address.
  3. Give the most critical mail a clean route. Send it from a separate subdomain with its own SPF, DKIM and DMARC records, through the system that already sends it. Be aware that a brand new subdomain has no reputation of its own, so start with the most important, lowest volume messages.
  4. Where mail is still not arriving, stop depending on it for the next cycle: put invoices and HR documents in a secure portal or document library, send a short notification with a link and no attachment, and confirm the most urgent items by phone.
  5. Tell finance, HR and customer-facing teams what is happening, so recipients who report missing invoices get a clear answer.

How do you read the authentication results in a message header?

Ask a recipient whose copy went to spam or was rejected to send you the full message headers, or send a test to mailboxes at the major providers you can access. Look for the Authentication-Results header added by the receiving server.

  • spf=pass or fail, and smtp.mailfrom: the envelope sender domain that SPF was checked against.
  • dkim=pass or fail, and header.d: the domain that signed the message.
  • dmarc=pass or fail, and header.from: the visible From domain DMARC checks the other two against.
  • A rejection or bounce message, if there is one, usually carries a status code and a reason text naming authentication, policy, reputation or a blocklist. Keep it; it is the most direct evidence you will get.

The pattern tells you the problem. SPF and DKIM passing but DMARC failing means alignment: the domains that passed are not the From domain. DMARC passing while mail still lands in spam points to reputation or content rather than authentication. Transactional mail from a different system failing on the same domain means the damage is at domain level, which is why separating traffic matters.

How do you verify SPF, DKIM and DMARC alignment for the Customer Insights sending domain?

DMARC passes only when SPF or DKIM passes for a domain that aligns with the visible From domain. For marketing mail, DKIM alignment is the one to rely on, because the envelope sender used by a sending service often belongs to the service rather than to you.

  • Domain authentication in Customer Insights - Journeys. The app lets you add your sending domain and gives you DNS records to publish, typically for DKIM signing and SPF. Confirm the domain shows as authenticated in the app and that the From address on your emails uses that domain. The exact records, verification steps and settings change, so follow current Microsoft documentation for your version rather than records copied from an old project.
  • SPF. Publish a single SPF record per domain that includes every service allowed to send for it. Several SPF records on one domain, or a record with too many lookups, cause SPF to fail. Check the lookup limit in current guidance.
  • DKIM. Check header.d in a real message from each system. It should be your domain or a subdomain of it, not only the provider's domain.
  • DMARC. Publish a DMARC record with reporting addresses so you receive aggregate reports showing every source sending as your domain. Start with a monitoring policy while you find all legitimate senders, then tighten. Moving straight to reject on a domain whose senders are not all aligned will block your own legitimate mail.

Major mailbox providers have tightened their requirements for bulk senders, including authentication, alignment, easy unsubscribe and low complaint rates. Check their current sender guidelines, because thresholds and enforcement dates have changed more than once.

Why should marketing and transactional mail never share a sending domain?

Because mailbox providers build reputation partly on the domain, and a marketing campaign sent to a stale list can drag down everything else sent from the same domain. Invoices from your finance system, HR notices from Microsoft 365 and a newsletter from Customer Insights all look like the same sender if they share the From domain.

  • Send marketing from a dedicated subdomain, such as one reserved for news or marketing, authenticated in Customer Insights - Journeys.
  • Send transactional mail from a different subdomain or the main domain, through the systems that generate it.
  • Use separate reply-to addresses and unsubscribe handling for marketing.
  • Keep consent purposes separate too: in Customer Insights - Journeys, transactional and commercial messages can be sent under different purposes and compliance settings, so a contact who has not consented to marketing can still receive the messages they are owed.

Separation limits the damage; it does not make a poor sending practice safe. Providers can still associate subdomains with the parent domain, so a marketing subdomain with bad habits will still hurt.

What usually damaged the reputation in the first place?

Knowing the cause stops you repeating it once sends resume. The usual causes are:

  • A large list sent to for the first time, often imported from an old system, a purchased source or event badge scans, with addresses that no longer exist or never agreed to hear from you.
  • Hard bounces not suppressed, so invalid addresses are mailed again on every send.
  • Spam complaints from people who do not remember opting in.
  • Recycled or trap addresses hidden in old lists.
  • Sudden volume from a domain that normally sends little mail.
  • Marketing sent from the same domain, sometimes the same address, as transactional mail.
  • Missing or hard to find unsubscribe links, which push people to the spam button instead.

If the send list came from an import, check how contacts were matched and cleaned; our guide to cleaning duplicate data in Dynamics 365 covers why the same person often receives the same email twice.

How do you rebuild sender reputation without making it worse?

Slowly, and to people who want the mail.

  1. Build an engaged segment: people who recently clicked, bought, registered, logged in or contacted you. Treat opens with caution, because privacy features and security scanners can register opens no person made.
  2. Suppress everyone else for now, including every contact point whose consent you cannot prove, hard bounces and previous complainers.
  3. Start sending to the most engaged part of that segment at low volume on the marketing subdomain.
  4. Increase volume gradually, only while bounces and complaints stay low, and hold or step back if they rise.
  5. Watch the evidence at each step: DMARC aggregate reports, bounce and complaint figures in Customer Insights - Journeys, and the postmaster or sender tools the major mailbox providers offer.
  6. Bring less engaged contacts back only through a clear re-engagement or re-permission route, and remove those who do not respond.

There is no fixed timetable. It depends on how badly reputation was damaged and how much engaged volume you have, so plan for weeks rather than days and do not promise the business a date.

How do you prove consent for the people you keep emailing?

A recovery that keeps mailing people without consent will fail again, and in many jurisdictions it is also a legal exposure. Consent in Customer Insights - Journeys is held per contact point, per channel and per purpose rather than as a single tick box, and it needs evidence behind it.

  • Record the source, timestamp, the exact wording shown and its version, and the capture point for every opt-in.
  • Use double opt-in for new sign-ups where your adviser recommends it, so an address is confirmed before it is mailed.
  • Treat contact points without provable consent as suppressed by default and keep a dated record of that decision.
  • Rebuild permission only through a channel your legal adviser confirms is lawful, because in some jurisdictions a re-permission email is itself marketing.

How the consent model works for legacy contacts, including purposes, topics and compliance profiles, is set out on our Customer Insights implementation page. Retention, erasure and subject access requests for the same contacts are covered in our guide to GDPR retention, erasure and DSAR in Dynamics 365. This is technical guidance, not legal advice.

How do you monitor deliverability so this does not happen again?

Make somebody responsible for sender health and give them the evidence.

  • Review DMARC aggregate reports regularly for unknown senders and alignment failures.
  • Track hard bounces, complaints and unsubscribes per send and per journey, and stop a send automatically or by rule when they spike.
  • Require a check before any first send to an imported or long-unused list.
  • Keep hard bounces and complainers suppressed permanently, and remove long-inactive contacts on a schedule.
  • Seed important sends to test mailboxes at the providers your recipients use.
  • Check after any DNS change, website migration or new sending system that SPF, DKIM and DMARC still pass for every sender.

How does Solzet help when marketing email is blocking business mail?

Senior consultants at Solzet, with 8+ years of Dynamics 365 Customer Engagement delivery, work through this in the same order: containment, header and DNS diagnosis, domain authentication and separation in Customer Insights - Journeys, consent and suppression rules, then a monitored warm-up. We configure the Dynamics 365 and Customer Insights side and work alongside whoever manages your DNS and mail systems. We do not implement finance or ERP systems, so where invoices come from one, we help you route and authenticate its mail rather than change the system itself.

If Microsoft marketing licensing is more than your email volume justifies, campaign sending, consent records and suppression can also be built into a custom-built CRM you own.

When marketing email from Dynamics 365 Customer Insights has damaged your domain reputation so badly that invoices and HR mail are blocked, stop the damage first: pause marketing sends and move critical transactional mail to a separate, properly authenticated subdomain, or send portal links and confirm by phone for the most urgent items. Then diagnose from evidence. Read the Authentication-Results header on a message that landed in spam, verify SPF, DKIM and DMARC alignment for the domain Customer Insights sends from, and check whether marketing and transactional mail share a domain at all. Recover reputation slowly: send only to recently engaged recipients, increase volume gradually, and suppress every address whose consent you cannot prove. Keep marketing and transactional traffic on separate subdomains for good.

What do readers ask?

Why are our Dynamics 365 marketing emails going to spam?

Usually a combination of authentication and reputation. Check the Authentication-Results header for SPF, DKIM and DMARC results and confirm the From domain is authenticated in Customer Insights - Journeys. If authentication passes, the cause is usually reputation: old or imported lists, unsuppressed bounces, complaints, sudden volume or marketing sharing a domain with other mail.

Can marketing emails cause our invoices to be blocked?

Yes. Mailbox providers build reputation partly on the sending domain, so marketing sent from the same domain as invoices and HR mail can drag all of it into spam or rejection. Pause marketing sends, move critical transactional mail to a separately authenticated subdomain or portal links, and keep marketing and transactional traffic on different subdomains permanently.

How do I check SPF, DKIM and DMARC alignment?

Open the full headers of a real message and read Authentication-Results: smtp.mailfrom for SPF, header.d for DKIM and header.from for DMARC. DMARC passes only when SPF or DKIM passes on a domain that aligns with the From domain. Publish a DMARC record with reporting addresses to see every source sending as your domain.

How do I set up domain authentication in Customer Insights - Journeys?

Add your sending domain in the app settings, publish the DNS records it generates, typically for DKIM and SPF, and confirm the domain shows as authenticated before sending from it. The records, steps and settings change between releases, so follow current Microsoft documentation for your version.

Should marketing emails be sent from a subdomain?

Yes. A dedicated marketing subdomain, authenticated separately, keeps marketing reputation apart from invoices, HR mail and everyday business email. It limits damage rather than preventing it, because providers can still associate a subdomain with its parent, so the subdomain still needs consented, engaged recipients.

How long does it take to recover email sender reputation?

There is no fixed timetable. It depends on how badly reputation was damaged and how many engaged recipients you can send to. Send to recently engaged people at low volume, increase gradually while bounces and complaints stay low, and suppress unproven consent. Plan for weeks rather than days.

How do we prove email consent in Dynamics 365 Customer Insights?

Store consent per contact point and purpose with its source, timestamp, exact wording and version, and capture point, and use double opt-in where your adviser recommends it. Suppress contact points without provable consent by default and keep a dated record of that decision. This is technical guidance, not legal advice.

Email DeliverabilityCustomer InsightsSPF DKIM DMARCConsentEmail MarketingDynamics 365

Have a project in mind?

Talk to a Solzet consultant about your CRM needs, whether that is Dynamics 365, Power Platform, or a custom-built CRM. We respond within one business day.