Skip to content
Flare Built
For new brokerages

Real Estate Email Deliverability: We Checked 43 Brokerages

September 28, 2026·8 min read·Written by Flare Built
A grey cluster mailbox at the entrance of a new subdivision with one compartment open, holding an envelope with a yellow sticker reading RETURN TO SENDER, an orange tag hanging from the key

Real estate email deliverability comes down to a few public records most brokerages never look at. We read them for 43 Sacramento-area brokerage domains on September 28, 2026. 35 of the 43 give Gmail, Yahoo and Outlook no instruction about mail forged in their name. Two have a record error that makes their sender check fail outright, two are not set up to receive email at their own domain, and four publish a free Gmail or Apple address on their website.

None of this shows on the website. All of it decides whether an email from your brokerage reaches the inbox, and whether someone else can send one that looks like yours.

What we checked (43 domains)

Publish no DMARC record

Result24
What we checked (43 domains)

DMARC set to monitor only (p=none)

Result11
What we checked (43 domains)

DMARC set to quarantine or reject

Result8
What we checked (43 domains)

Two SPF records, which breaks SPF

Result2
What we checked (43 domains)

No SPF record

Result3
What we checked (43 domains)

No mail server record

Result2
What we checked (43 domains)

Publish a free Gmail or Apple address

Result4

The sample is every live site from our two earlier audits, the method is at the end, and only the firms doing it well are named.

What Gmail, Yahoo and Outlook now check

Three DNS records do the work. SPF lists the servers allowed to send email as your domain. DKIM signs each message so the receiver can check it was not altered and really came from you. DMARC tells the receiver what to do when a message claiming your domain fails both: nothing, the spam folder, or reject.

Since February 2024 these stopped being optional.

  • Google requires every sender to "set up SPF or DKIM email authentication for your sending domains," and warns that unauthenticated messages "might be marked as spam or rejected." Anyone sending 5,000 or more messages a day to Gmail needs all three, and Google counts every message "sent from the same primary domain," so an office, a CRM and a newsletter add up together. Once over the line, a sender is "permanently considered" a bulk sender. (Google's sender guidelines, FAQ)
  • Yahoo asks all senders to "implement SPF or DKIM at a minimum" and bulk senders to publish DMARC. It says "we will not specify a volume threshold." (Yahoo Sender Hub)
  • Microsoft went furthest. Since May 5, 2025, Outlook.com, Hotmail and Live addresses reject mail from domains sending over 5,000 a day that fail its checks, with the error "550; 5.7.515 Access denied, sending domain [SendingDomain] does not meet the required authentication level." (Microsoft's announcement)

A new brokerage will not send 5,000 emails a day on day one. But every agent on the domain, the monthly newsletter and the automated listing alerts all count toward the same total, and once reached, the status does not expire.

What we found in Sacramento

Most domains have no DMARC policy that does anything. 24 publish no DMARC record and 11 publish one set to p=none, which the current standard, RFC 9989, describes as the owner expressing "no handling preference for messages that fail." Monitoring mode is a fine first step. It is not meant to be the last.

Eight enforce. Four of those send their reports to the same outside address, and three carry a word-for-word identical record, which reads like a default supplied by a host rather than a decision anyone made. The clearest deliberate setup belongs to Quiroz Commercial: quarantine, strict alignment on both checks, and reports sent to an address on its own domain, where someone can read them.

Two domains publish two SPF records. It looks harmless, since both records are valid on their own. The SPF standard, RFC 7208, says that if a domain returns "more than one record," the check produces "permerror," a permanent error. In practice SPF never passes for that domain. It usually happens when a second email service is added and its setup guide says "add this SPF record" rather than "merge it into your existing one."

Two domains publish no mail server record, so the domain is not set up to receive email. One of the two firms lists an address at a different domain instead.

Four sites publish a free mailbox, three Gmail addresses and one Apple address, including a brokerage whose contact page gives a Gmail address as the way to reach it.

Why a free mailbox fails you in a CRM

A Gmail or Yahoo address works fine when you type a message in Gmail or Yahoo. It breaks when a CRM or newsletter tool sends mail "from" that address through its own servers, because you do not own the domain and cannot add those servers to its records. The receiver sees a message claiming to be from yahoo.com that did not come from Yahoo.

Each free provider publishes what should happen next. We looked on September 28: yahoo.com, aol.com and comcast.net all publish p=reject, an instruction to refuse the message outright. icloud.com and me.com say quarantine. gmail.com, outlook.com and hotmail.com still say p=none, but Google's own guidelines say "Gmail will begin using a DMARC quarantine enforcement policy," so the most common free address is on notice.

The CRM vendors say the same thing in their own help pages. Follow Up Boss marks Yahoo, AOL and cable-provider email as not recommended because they "enforce DMARC policies that prevent third-party systems from sending marketing emails on your behalf." Lofty says its "mass emails are sent from your @lofty.com email address." BoldTrail's mass email arrives with "via kunversion" next to your name, which it says "cannot be removed." Mailchimp puts it simply: "you don't own the domain."

The fix is an address on your own domain. Google Workspace and Microsoft 365 both listed their entry business plans at $7 a user a month on an annual plan when we checked, and both include email at your domain.

Why it matters more in real estate

Real estate is where forged email turns into a wire transfer. The FBI's 2025 Internet Crime Report counts 24,768 business email compromise complaints and $3.05 billion in reported losses for the year. One case it describes: buyers "closing on a home when they received an email impersonating their legitimate attorneys" sent a wire of over $449,000. (A note on reading that report: its separate "Real Estate" category covers investment, rental and timeshare fraud. Closing wire fraud is counted under business email compromise.)

A DMARC policy set to quarantine or reject is what stops a stranger sending mail as your exact domain to your clients. It has limits, and the standard says so: RFC 9989 states that DMARC "does not address the use of visually similar domain names," and a stolen password to a real mailbox gets past it entirely. The FBI's advice covers the rest: "Be alert to hyperlinks that may contain misspellings of the actual domain name," and confirm any change to payment details through a second channel (IC3 alert I-091124-PSA).

Our own domain

We ran flarebuilt.com through the same check. SPF and DKIM are in place, and our DMARC policy was p=none on the day we checked, so it would have been one of the 11. That is the monitoring stage the fix below starts with, and the next step is the same one we are recommending to you.

The fix, in order

  1. Get email on your own domain for everyone who sends as the brokerage, and stop using free addresses in any tool that sends for you.
  2. Publish one SPF record that lists every service sending as you: your mailbox provider, your CRM, your newsletter tool. One record, merged, never two.
  3. Turn on DKIM in your mailbox provider and in each sending tool. Most CRMs have a domain authentication page that hands you the records to add.
  4. Publish DMARC at p=none with a reporting address at your own domain, read the reports for a few weeks to find any sender you missed, then move to p=quarantine.
  5. Check your work with Google's free Check MX tool, which checks your mail server, SPF and DMARC records.

If you send a newsletter, the federal CAN-SPAM rules apply on top: the FTC's compliance guide requires "your valid physical postal address" in each message and opt-outs honored "within 10 business days," with penalties of up to $53,088 per email.

What we would build

A brokerage site that shows its licence number, loads fast on a phone and passes the website audit checks, on a domain whose email records are set up to match. A launch site starts at $900 and is live in 48 hours, and a full brokerage site starts at $4,500 and is live in about a week, with Flare Care for the months after. What a new firm needs is worked through in what a brokerage website costs, and the name that goes in front of the domain is covered in how to name a brokerage.

If you want this check run on your domain, tell us about your brokerage, or build your package in about two minutes.

How we checked

The domains are every live website from our two earlier Sacramento-area audits: brokerage corporations licensed in Sacramento County since 2024 (residential) and Sacramento-region corporations with Commercial or CRE in their licensed name (commercial), the same 43 we timed on a phone.

On September 28, 2026 we read each domain's public DNS records through Google's public resolver (mail servers, SPF, DMARC and DKIM at common selectors) and re-read the DMARC records through Cloudflare's resolver, with identical results. We also collected the email addresses shown on each homepage and contact page. This is read-only: public records any mail server reads before accepting a message.

What it cannot see: DKIM keys sit under names each sender chooses, so we report DKIM only where we found it, never its absence. Addresses hidden behind scripts or forms were not collected, so the free-mailbox count is a floor. And a correct record is necessary but not sufficient: what each firm actually sends, and how its recipients treat it, is not visible from outside.

Frequently asked questions

Why are my real estate emails going to spam?

The most common cause for a small brokerage is missing or broken email authentication: the SPF, DKIM and DMARC records that tell Gmail, Yahoo and Outlook which servers may send as your domain. Google requires every sender to have SPF or DKIM, and bulk senders all three. A second common cause is sending from a CRM or newsletter tool with a free Yahoo, AOL or Gmail address in the From line.

Can I use a Gmail address for my brokerage?

You can receive and reply from one, but it is a poor sending address for anything that goes out through a CRM or newsletter tool, because you cannot authenticate a domain you do not own. Yahoo and AOL publish a policy telling receivers to reject such mail outright. Business email on your own domain from Google Workspace or Microsoft 365 started at $7 a user a month on an annual plan when we checked.

What is DMARC and do I need it?

DMARC is a public DNS record that tells receiving mail servers what to do with a message that claims to come from your domain but fails authentication: nothing, spam folder, or reject. Google, Yahoo and Microsoft require it of bulk senders. For a brokerage it is also the one control that stops a stranger sending email as your exact domain to your clients.

Does DMARC stop wire fraud?

It stops one form of it: forged mail that uses your exact domain. The DMARC standard itself says it does not address look-alike domains or a fake display name, and it cannot help if a real mailbox is broken into. So set it up, and keep the phone-call rule for any change to wiring instructions.

See what your site tells referrals.
Get a free teardown.

A short, plain-language video showing where your site wins trust, where it loses the call, and what fixing it would look like. Yours to keep either way.

Start a project
Only 2 builds a month · 1 slot leftThe Love-It-Live GuaranteeThe On-Time Promise