QuietForgeTools · Free diagnostic guide
Free guide · DIY first · no uploads

WordPress Contact Form Emails Going to Spam? What to Check

The form submits successfully. The notification email is generated and reaches the mail system — but it lands in Spam, Junk, or quarantine instead of the inbox. This page focuses on that exact symptom, not “form not sending” or “email never arrives at all.”

Wrong symptom? If the form never completes or shows errors, use WordPress contact form not sending emails. If the UI says sent but you cannot find the message even in spam/junk, use form says sent but no email arrives first — then return here once placement in spam is confirmed.

1. Verify that spam placement is actually the failure

Confirm the message exists and was filtered — not missing, not undelivered.

  • Search the recipient mailbox for a unique phrase you put in a test submission.
  • Open Spam / Junk folders (and “All Mail” / “Clutter” views where the provider has them).
  • Check provider quarantine (Google Workspace Admin, Microsoft 365 quarantine, host spam dashboard).
  • If you still find nothing in inbox or spam/quarantine, treat it as missing mail — use the sent but no email guide before changing spam-related settings.
  • Note the exact folder/label and any “phishing / spoof / failed authentication” banners on the message.

2. Check From / sender address configuration

Spam filters weigh who appears to send the mail as heavily as what the form does.

  • Open the form’s Mail / Notification settings and copy the From name and From email exactly.
  • Prefer a real mailbox you control on a domain related to the site (not a random free-mail From).
  • Avoid empty From, invalid addresses, or placeholders left after a migration.
  • Compare From with Settings → General → Administration Email Address — mismatch is common and worth noting.
  • If the From address cannot receive bounces, you will miss delivery-rejection feedback.

3. Site domain versus an unrelated From address

Sending as an address on a domain you do not control often triggers spam or spoof warnings.

  • If the site is example.com, a From like noreply@example.com or a staff mailbox on that domain is usually clearer than a visitor’s Gmail as From.
  • Using the visitor’s personal email as From (common Contact Form 7 pattern) frequently causes spam placement or rejection — even when the form “succeeds.”
  • Hosting that forces mail through its own relays may rewrite or reject mismatched From addresses.
  • Record: site hostname, From domain, and whether they match. Misalignment is a diagnostic signal, not a guarantee of spam.

4. Reply-To versus From — keep them distinct on purpose

You can let staff reply to the visitor without pretending the visitor sent the mail.

  • Set From to a domain you control; set Reply-To to the visitor’s submitted email (or a staff alias).
  • Confirm the form plugin supports separate From and Reply-To fields (or mail-tags) and that both are populated.
  • Test a reply from the notification message — it should go to Reply-To, not only bounce to From.
  • Do not “fix spam” by putting the visitor in From; that often worsens filtering.

5. Practical SMTP configuration (high level)

Authenticated SMTP usually improves deliverability versus raw PHP mail(), but it is not magic.

  • Confirm whether the site uses an SMTP plugin / transactional API or only PHP mail.
  • If SMTP is configured: correct host, port, encryption (TLS/SSL), and credentials; run the plugin’s own test to the same spam-hitting recipient.
  • Prefer sending through a provider that matches the From domain’s expected relay where practical.
  • Watch for rate limits, “send as” restrictions, and shared-IP reputation on cheap shared hosts.
  • Changing SMTP alone does not guarantee inbox placement — retest spam folders after each change.

6. SPF, DKIM, and DMARC as diagnostic concepts

These are authentication signals. They help filters decide trust — they do not promise inbox delivery.

  • SPF: which servers may send for the From domain. If your SMTP host is missing from SPF, receivers may mark fail/softfail.
  • DKIM: cryptographic signature on the message. Broken or unsigned mail is a common spam factor.
  • DMARC: policy for what to do when SPF/DKIM fail (none / quarantine / reject). Quarantine policies can explain “in spam.”
  • Use provider “show original” / message headers to see Authentication-Results (pass/fail/neutral).
  • Do not claim that fixing one DNS record will stop spam. Treat auth failures as high-priority diagnostics among others.

7. Recipient-side spam filters and quarantine

Sometimes the site sends correctly and the recipient’s filter is the bottleneck.

  • Ask the recipient (or check admin consoles) for spam rules, blocked senders, and quarantine releases.
  • Corporate Microsoft 365 / Google Workspace often quarantine first-time form mail from new domains.
  • Consumer Gmail/Outlook: mark Not spam once, then retest — still record whether later messages stay in inbox.
  • Subject lines with urgency, ALL CAPS, or heavy marketing phrasing can worsen filtering even for legitimate enquiries.
  • If only one company inbox filters and others do not, bias toward that recipient’s policy — not a site-wide “form broken” rewrite.

8. Controlled testing with more than one mailbox

One mailbox is anecdote; two or three reduce guesswork.

  • Submit identical tests to: (a) the production recipient, (b) a mailbox you control on a different provider, (c) optionally a same-domain staff address.
  • Use a unique phrase per test. Check inbox and spam within a few minutes for each.
  • Pattern A: all land in spam → bias toward From/SMTP/auth/reputation.
  • Pattern B: only production recipient spam → bias toward that mailbox’s filters/quarantine.
  • Pattern C: none appear anywhere → leave this guide; follow sent but no email.
  • Restore production recipients after tests; do not leave personal inboxes as live To addresses.

9. Logging and evidence to retain

A short evidence pack beats vague “it’s always spam.”

  • Date/time with timezone, form URL, unique body phrase, From / Reply-To / To as configured.
  • Where the message was found (inbox / spam / quarantine / not found) for each test mailbox.
  • Header snippet: Authentication-Results, Received chain, any spam score if shown.
  • SMTP/plugin log line showing accept/reject for that attempt.
  • One change between tests — then retest the same phrase pattern.

Tip: mark the same items on the free Enquiry Path Checklist so you can hand a clear summary to a developer or host.

10. When the symptom points beyond a simple isolated fix

A single wrong From, missing Reply-To, or one spam-folder false positive is often an isolated fix. Treat it as a wider enquiry-path problem when several of these hold:

  • Spam placement is inconsistent across recipients, days, or form variants.
  • SMTP, DNS (SPF/DKIM/DMARC), and plugin notification templates all need coordinated changes.
  • Reputation / shared IP / branding issues sit outside one form setting.
  • You cannot reproduce reliably enough to verify one change.

Isolated, reproducible “arrives in spam” with a clear single fault → short fix territory. Multi-step / inconsistent delivery across the whole enquiry path → map and repair the path, not one random toggle. This guide does not claim any sequence will stop emails going to spam.

If you want help fixing it

This guide and the free checklist are complete on their own. Use a paid option only if you prefer bounded help after you’ve narrowed the failure — not as a required next step.

£149 Enquiry Path Repair covers one bounded, reproducible defect on an enquiry, contact, or quote path. If several independent breaks appear, one is bounded for £149 and the rest are quoted separately; anything that cannot be bounded after a written look at the URL is quoted separately before any charge.

Related diagnostics: form not sending (broad) · says sent, no email · Catalogue: QuietForgeTools hub. No private payment links on this page.