For a nonprofit, email is not a marketing channel, it is the operation. The donor appeal, the event invite, the volunteer shift reminder, the grant thank-you. If your domain is not authenticated, that email goes to the spam folder or gets rejected outright, and you lose the donation, the attendee, or the volunteer before you ever know it happened. The good news: the fixes are cheap, they take an afternoon, and most of them are free. Here is the exact list.
Nonprofits hit deliverability problems for a few specific reasons. First, most run their email through a tool they did not set up the domain for: Mailchimp, Constant Contact, or a free Gmail and Yahoo account for the whole team. The tool sends from your domain, but your domain's DNS does not say that tool is allowed to. Second, the list is large and the sending is bursty: a 4,000-person donor list that gets one big blast a month looks like spam behavior to a mailbox provider if the domain is not authenticated. Third, there is usually no one on staff who owns DNS, so a record that was set up three years ago quietly stops working when the ESP changes or the key rotates. The result is the same every time: the email lands in spam, open rates drop, and nobody connects the two until a donor asks why they never saw the appeal.
Every domain that sends email needs the same five records in place. Run them in this order, and fix the failures before the next send:
1. MX points to a real mail server. Without it, replies to your appeal bounce and the domain looks abandoned.
2. SPF lists every tool that sends for you and ends in -all. If you send through Mailchimp and also from a staff Gmail, both need to be in the record. A missing -all is the most common silent failure.
3. DKIM signs the mail on the same domain as the From header. Most ESPs hand you the exact record to add; the failure is adding it and then not confirming it is actually signing.
4. DMARC is present, usually starting at p=none with a reporting address, then tightened over time. It tells receivers what to do with mail that fails SPF or DKIM.
5. TLS/STARTTLS is available on the sending path. Plain-text SMTP is a spam signal, and it is the check most nonprofits never think to run.
The free audit runs all five in seconds and shows you the exact record to add or fix, in plain language. For a single domain that is usually enough to get back to inbox-ready.
Sending through Mailchimp, Constant Contact, or a similar ESP. The ESP's help center gives you the SPF include and the DKIM record. Add both to your domain's DNS, confirm DKIM is signing, and set a DMARC record at p=none pointing to a report you will actually read. This is the setup that fixes the most nonprofit spam problems, and it is entirely free.
Using a free Gmail or Yahoo for the whole team. This is the weakest setup. A free mailbox sending a 4,000-person blast is a strong spam signal, and you have no SPF or DKIM control over the sending domain. The fix is to move the sending to a real ESP on your own domain and authenticate it the way above. Keep the free mailbox for reading, not for the blast.
Sending from your own domain on a small server or a self-hosted setup. Same five checks, but you own the whole path. Confirm the PTR (reverse DNS) on your sending IP matches the server hostname, because a missing PTR is a classic rejection reason that the free audit flags.
Two problems pass a casual look and still cost you deliverability. The first is the SPF lookup limit: if your SPF record chains more than ten DNS lookups, receivers must reject it, and many nonprofit records quietly exceed that after a few years of adding tools. The second is SPF ending in ~all instead of -all. Softfail means spoofed mail is not firmly rejected, and mailbox providers treat the domain as less trustworthy. Both are one-line DNS fixes, and both are exactly what the audit points at.
The records above get you inbox-ready today. The failure mode for a nonprofit is that nobody owns the DNS, so a record breaks in six months and the next appeal quietly underperforms. The cheap version of the fix is a monthly check: run the free audit on your sending domain, confirm the five checks still pass, and fix anything that changed. The automatic version is Inboxproof Pro, which re-runs the full check on your domain every day and emails you the moment a record breaks, an IP gets blocklisted, or a new issue appears, so the fix happens on the day it happens instead of at the next donor appeal.
Run the free audit on your sending domain now and see the five-check score and the exact record to fix first: free email deliverability audit. For the nonprofit-specific view of what breaks and why, see Inboxproof for nonprofits.