Your form plugin or SMTP log says the email was sent, but it is not in your Gmail inbox. This usually means the email reached Google and was then filtered, sent to spam, or held back. The good news: Gmail tells you a lot about why, if you know where to look.
If you are not sure the email was sent at all, start with the full guide: Contact form not sending email? Why it happens and how to fix it.
1. Search every folder
In Gmail’s search box, type in:anywhere followed by words from the form’s subject line. Normal searches skip Spam and Trash; in:anywhere includes them. Also check:
- Settings → Filters and Blocked Addresses. A filter may archive or delete the emails.
- Settings → Forwarding and POP/IMAP. Forwarding can be set to delete Gmail’s copy.
- The Promotions and Updates tabs, if they are turned on.
2. If it is in Spam, read why
Open the email and choose ⋮ → Show original. At the top Gmail lists SPF, DKIM and DMARC with PASS or FAIL. This tells you exactly what to fix:
- SPF: FAIL or NEUTRAL — the server that sent it is not listed in your domain’s SPF record.
- DKIM: none or FAIL — the email was not signed for your domain.
- DMARC: FAIL — neither SPF nor DKIM passed for the domain in the From address.
A very common case: your form sends From [email protected], your email is hosted on Google Workspace, and your SPF record only includes Google. Your website server is not allowed to send for your own domain, so Gmail treats your own form as an impersonation attempt.
3. Google Workspace: ask your admin to check the logs
If you use Google Workspace and cannot find the email anywhere, an administrator can search for it in the Admin console under Reporting → Email log search. It shows whether Google received the message and what it did with it: delivered, sent to spam, quarantined, or rejected. Workspace admins can also set rules that quarantine unauthenticated mail claiming to be from your own domain, which catches website forms.
Avoid fixing this with an allow-list or a rule that skips the spam filter for your website. It hides the symptom for your mailbox only, and anyone forging your domain gets the same free pass.
4. Fix the sending side
Since 2024 Gmail requires every sender to pass SPF or DKIM, and bulk senders to also pass DMARC. To make contact form email pass reliably:
- Send through an authenticated mail service instead of the web server’s PHP mail function.
- Add that service to your SPF record and publish its DKIM key for your domain.
- Publish a DMARC record. See SPF vs DKIM vs DMARC.
- Send from your own domain, never from the visitor’s address: why the From address matters.
SecureSMTP signs every email with DKIM and passes SPF and DMARC. Once a form sends through it, “Show original” should read PASS on all three, and each email appears in your SecureSMTP delivery log as delivered or bounced.
Frequently asked questions
Does “Not spam” fix the problem?
Only for your own mailbox, and only partly. It teaches your Gmail account to trust that sender. It does nothing for authentication, so other people at your company or your clients can still miss the same emails.
Gmail says the email is from my own domain but marks it as suspicious. Why?
Your website sent it using your domain in the From address, but your website server is not in your domain’s SPF record and the email is not DKIM-signed for your domain. To Gmail that looks like someone impersonating you.
Do Gmail’s bulk sender rules apply to a contact form?
The strictest rules apply to senders of more than 5,000 messages a day to Gmail. But the basic requirement, that every sender passes SPF or DKIM, applies to everyone, including a small contact form.