A client called me recently with what sounded like a small problem. Emails from one particular sender were not showing up. Everything else seemed normal, so that is where we started. Within an hour, however, the real answer turned out to be far bigger. Their email DNS records had been left half-finished on the day the account was created, and almost nothing sent from outside their company had ever reached the inbox.
Nobody noticed for weeks. That is the part worth your attention, because the same thing could be happening to you right now.
Sending Worked. Receiving Never Did.
Here is the detail that hid the problem for so long: outgoing mail worked perfectly. My client wrote emails, hit send, and people replied. So the account felt healthy.
Sending and receiving, though, are two completely separate systems. Sending only requires a valid login. Receiving requires the entire internet to know where your mail should be delivered. In other words, you can have a perfectly working outbox sitting on top of a completely broken inbox, and nothing on your screen will warn you.
Worse, the failure was silent on both ends. Senders got no bounce message. My client got no error. Mail simply went to a server that quietly threw it away.
What Your Email DNS Records Actually Do
Think of your domain name as a business address. Your email DNS records are the paperwork on file at the post office that tells the world how to handle mail sent to that address. Four records do the heavy lifting.
- MX is the forwarding address. It tells every mail server on earth which building to deliver your mail to. Get this wrong and mail goes somewhere else entirely.
- SPF is the guest list. It names the servers allowed to send mail using your domain.
- DKIM is the tamper seal. It signs your messages so the recipient can confirm nothing was altered along the way.
- DMARC is the instruction sheet. It tells other mail servers what to do when a message claiming to be from you fails those checks.
MX controls whether you receive mail at all. The other three control whether anyone can convincingly pretend to be you.

How These Email DNS Records Got Broken
My client had bought a Google Workspace subscription through Network Solutions, their domain registrar. That is a common arrangement, and on paper it is convenient. The registrar handles billing and sets everything up for you.
Their automated setup, however, finished about three quarters of the job.
It proved the customer owned the domain, then created the mailbox. It even generated the correct SPF, DKIM, and DMARC values. Then it filed all three of them under the wrong names, so none of them did anything. Picture writing the right apartment number on an envelope and mailing it to the wrong building.
On top of that, it left its own mail server listed in the MX record. As a result, incoming mail kept going to the registrar’s server instead of to the mailbox the client was actually paying for and reading.

Silent Failure Is the Real Danger
Missing mail is bad. Being impersonated is worse.
Because three of the four email DNS records were inert, anyone on the internet could have sent email that appeared to come from that business, and no receiving server would have flagged it. For a company that sends invoices, contracts, or payment instructions, that is not a theoretical risk.
The FBI’s Internet Crime Complaint Center logged 24,768 business email compromise complaints in 2025, with losses topping $3 billion. That works out to roughly $123,000 per reported incident. I have watched this play out up close, and I wrote about the five-minute phone call that stopped a six-figure wire fraud because the pattern is so consistent.
Email authentication will not stop every attack. Still, it removes the easiest version of it.
Check Your Own Email DNS Records in Five Minutes
You do not need to be technical to run a basic sanity check. First, send yourself a test message from an outside account, such as a personal Gmail address, and confirm it arrives. Second, ask someone at a different company to reply to a thread and confirm that lands too.
Then look at the calendar. When did you last receive an email from someone outside your own organization? If you cannot answer that quickly, check now rather than assuming.
Finally, do not trust your provider’s dashboard by itself. My client’s admin console reported one of the records as correctly configured when it was not published at all. Dashboards report what they were told. DNS reports what is true, and those are not always the same thing.
If Something Looks Wrong
Resist the urge to start deleting email DNS records yourself. Mail routing is unforgiving, and a wrong edit can take a working mailbox offline for a day or more. Google notes that MX changes can take up to 72 hours to take effect, so mistakes are slow to surface and slow to undo.
Fix the delivery path first, because nothing else matters if mail is not arriving. Authentication comes second. After that, turn on reporting so you can see what is actually happening to your domain. I spent six months reading my own reports and wrote up what they were really telling me, which is a good primer if you want to understand what you are looking at.
Above all, verify the fix from outside your own dashboard. Then check again a month later. Automated provisioning tools that got it wrong once can get it wrong again.
The Takeaway
Email is the one system every small business assumes is simply working. Because it fails quietly, that assumption can go unchallenged for months. My client lost weeks of correspondence before anyone thought to ask whether the plumbing was sound.
Correct email DNS records are not glamorous work. Nevertheless, they decide whether your business receives what it is sent and whether strangers can send mail wearing your name.
If you are not certain yours are right, I am happy to take a look. Get in touch and I will check your email DNS records as part of a free assessment. It takes a few minutes, and it is a lot cheaper than finding out the hard way.


