A retailer can spend heavily on peak trading and still lose the customer at the exact moment the order confirmation should land. That message carries the order number, the delivery window and the returns link. It is the one email shoppers reliably open, and the one that fails most quietly, because nothing bounces. It simply drops into a junk folder, and the first sign of trouble is a contact centre filling with people asking where their order is.
The odds have been shifting against unprepared senders since February 2024, when Google and Yahoo turned long-standing best practice into a condition of entry. Microsoft applied comparable rules to Outlook.com, Hotmail and Live addresses from 5 May 2025, and in November 2025 Google moved from throttling non-compliant traffic to rejecting it outright. The threshold is less forgiving than it sounds. Cross roughly 5,000 messages a day to personal Gmail accounts once and Google classifies the domain as a bulk sender permanently, with every subdomain counting towards the parent. A single Black Friday send is enough. And the rules apply to mail sent to personal Gmail addresses rather than Google Workspace accounts, which is exactly the audience a consumer retailer sells to.
A free inbox cannot vouch for itself
Plenty of independent retailers still send from a gmail.com or hotmail.com address, or route automated mail through one. It usually reads as a habit left over from the founding days rather than a decision anyone made, but it now carries a technical penalty. Nobody outside Google controls the DNS records for gmail.com, so a message claiming that address can never align with the sender’s own authentication, and Google’s guidance treats a Gmail address in the From line of mail that never left a Gmail server as spoofing. Moving to a mailbox on the company’s own domain fixes the technical problem and the perception problem in one step. Google Workspace and Microsoft 365 suit teams already living in those ecosystems, while providers such as one.com bundle email hosting with the domain itself, which suits smaller operators who would rather not manage two contracts. The choice of provider matters less than the condition underneath it: the mailbox has to sit on a domain the retailer controls. Email on your own domain is also what makes authentication possible in the first place, because SPF and DKIM records live in DNS and a business can only publish them for a domain it owns. The perception half matters just as much. Retail business credibility accumulates in small repeated signals, and a consumer domain in the sender field undercuts every one of them at the precise point where a shopper is deciding whether the payment they just made was sensible. A professional business email address is the cheapest reassurance in the whole post-purchase journey.
Three records, and the order you publish them in
SPF, DKIM and DMARC do three different jobs, and treating them as a single task is where most retail implementations go wrong. The NCSC’s anti-spoofing guidance sets the division out plainly: SPF publishes which systems are trusted to send for a domain, DKIM signs each message so that tampering shows, and DMARC tells receiving servers what to do when neither check passes, while reporting back on everything sent in the retailer’s name. The sequence matters more than the acronyms. Publishing DMARC with a policy of none changes nothing about delivery; it simply switches on the reports. Those reports are where a retailer discovers that the returns portal, the review request tool and the loyalty platform have all been sending in its name without anyone documenting it. The NCSC notes that many organisations are ready to move to a quarantine policy after six to eight weeks of monitoring. Retailers carrying a long tail of bolt-on tools take longer, and should. SPF is where that sprawl becomes a hard ceiling. The specification caps a record at ten mechanisms requiring a DNS lookup; exceed it and the record returns a permanent error, which DMARC reads as a failure for every message the domain sends. An ecommerce platform, a marketing suite, a courier notification service, a helpdesk and a reviews tool make five. The break arrives without warning, usually the day after somebody adds one more integration nobody thought to flag to IT.
The moment a dispatch note becomes marketing
Transactional mail sits outside some of the newer requirements, but the exemption is narrower than most retailers assume. Google’s one-click unsubscribe rule covers marketing and promotional messages and excludes transactional ones, giving password resets and reservation confirmations as its examples. It also states that recipients, not Google, determine the nature of the messages they receive. An order confirmation stays transactional right up to the moment a customer reads it as an advert and reports it. Under UK law the line is drawn by content, not by which system sent the message. The ICO’s PECR guidance says routine customer service correspondence about a current contract or past purchase is not direct marketing, and that general branding, logos and straplines do not change that. Add significant promotional material aimed at selling something else and the message becomes marketing, with the consent rules that follow. A “you might also like” block appended to a dispatch note is not a free upsell; it reclassifies the email. Deliverability follows the same logic. Google asks senders to keep user-reported spam below 0.1% and never let it reach 0.3%, and it measures that figure against the sending domain in Postmaster Tools, not against a single campaign. A badly targeted promotional blast therefore drags down the reputation carrying the order confirmations, which is why retailers at any scale run marketing from a subdomain and keep transactional mail on the parent. The separation protects something the research says is worth protecting: Scurri and IMRG found UK shoppers place more confidence in delivery updates from retailers than in the same information from a delivery partner. That confidence is worth nothing if the message never arrives.
The failure shows up in the contact centre first
Deliverability problems rarely announce themselves on a monitoring dashboard. They surface as WISMO (“Where is my order?”) queries. A customer who cannot find a dispatch email is unlikely to suspect a DMARC issue; they’ll assume the retailer is disorganised, then contact support, raise a chargeback or leave a negative review. As more product discovery shifts into AI and zero-click search, owned channels like email become even more valuable. At the same time, weak email authentication leaves retailers vulnerable to convincing phishing emails sent in their name, with the NCSC highlighting brand protection as a key reason for adopting these controls. The fix is straightforward: configure the right DNS records, use a professional email domain and define which systems are authorised to send on the retailer’s behalf. Do it in August and it’s a simple technical task. Discover the problem in November, at peak trading, and it becomes a business problem.












