Practical troubleshooting guide · The business scenario is illustrative, not a client case study. Administrative changes require authorised access.

A contractor in Grimsby can send ordinary email successfully while invoices from a new estimating platform are rejected. These are separate sending paths. The useful question is not whether email works in general, but which service sent the rejected invoice and what the receiving server reported.

Collect one failure before changing DNS

Save the complete delivery failure notice, the sending time and a non-sensitive test invoice reference. Compare a message from the estimating platform with one from your usual mailbox. A wrong recipient address and an authentication failure need different fixes. Do not treat every 550 response as an SPF problem: read the accompanying diagnostic text.

Inspect the authorised senders

SPF is a DNS TXT record that describes permitted senders. Use the read-only lookup below for your own domain, then compare its contents with the current instructions from your mailbox and invoicing providers. Inventory website notifications and other senders too. DNS access may belong to your registrar, Cloudflare or another host; confirm the authoritative provider before editing.

Correct the configuration with a rollback plan

Save the existing DNS values first. Have the administrator reconcile the authorised senders into a valid SPF configuration rather than pasting a vendor example over an existing record. Enable the invoicing provider’s DKIM signing when supported. Do not guess include values or assume your normal mailbox provider also authenticates the invoicing platform. Schedule the change when someone can monitor results.

Prove the invoice path works

After DNS caches refresh, send a labelled test through the quoting tool and inspect the recipient’s authentication results and the platform’s delivery log. Repeat with the normal mailbox to catch regressions. Keep a dated note of the configuration and test outcome. If authentication passes but delivery still fails, use the new rejection details to continue with the provider rather than repeatedly changing DNS.

Technical check

Read-only Windows PowerShell lookup — replace example.com with your domain

Resolve-DnsName -Name example.com -Type TXT

This command reads public information; it does not change configuration. Example domains are placeholders.

MAKE IT ACTIONABLE

Your next steps

  • Keep the complete bounce diagnostic.
  • List every business sender before editing DNS.
  • Retest both invoices and ordinary mail.

Official reference

Google: Set up SPF

Technical guidance checked October 1, 2026. Product features and requirements can change. The business checklists above are practical suggestions from Cyber Bounds.

PUT THE NEXT STEP INTO PRACTICE

Help with email deliverability.

Help your quotes, invoices, and everyday messages reach the people waiting for them. Tell us about your situation and we’ll discuss a suitable scope and quote.

Explore Email Deliverability