Short answer: Gmail shows “via” followed by another domain, for example Anna Smith via mailservice.com, when the message was sent and authenticated by a domain that does not match the domain in your From address. It usually happens when a newsletter tool, CRM, shop platform or website plugin sends mail in your name but signs it with its own DKIM key. The fix is to set up DKIM for your own domain in that service, so the signature domain matches your From address, and to keep SPF and DMARC consistent with it.
What the “via” label actually tells you
When Gmail displays a message, it looks at the domain in the visible From address and compares it with the domains that authenticated the message. If the message passed authentication only for a different domain, Gmail shows the sender name followed by “via” and that other domain. It is Gmail’s way of saying: this message says it is from you, but it was really sent through someone else’s system.
The label is not an error message and it does not mean the message went to spam. Many legitimate messages carry it. But it does change how the message looks to the recipient. A customer who sees Your Shop via bulkmailer-example.net may hesitate before clicking a link or paying an invoice, and that hesitation is exactly what you want to avoid in order confirmations, invoices and password reset emails.
Other mail apps show similar hints in their own way. Outlook, for example, may show “sent on behalf of” when the technical Sender header differs from the From address. The causes overlap: a third party sends in your name without fully proving that it is allowed to.
The technical cause: DKIM signed by another domain
Every authenticated email can carry a DKIM signature. Inside the signature header there is a d= tag with the domain that signed the message. If you send through a service that has not been configured for your domain, that tag contains the service’s own domain, such as d=mailservice.com, while your From address says [email protected].
The same mismatch can happen with SPF. SPF checks the envelope sender, also called the Return-Path, not the visible From address. Many services use their own bounce domain there, so SPF passes for their domain, not yours. When neither DKIM nor SPF passes for a domain that matches your From address, Gmail has no proof that your domain sent the message, and the “via” label appears.
If you want to see this for yourself, open the message in Gmail, choose “Show original” and look at the lines for SPF, DKIM and DMARC, together with the DKIM-Signature header. Our guide on reading email headers walks through every line. You will usually find that DKIM passes, but for a domain other than yours.
Common sources of the “via” label
In small businesses, the label almost always comes from one of these senders:
- Newsletter and marketing tools that were set up quickly with only a verified From address, without the DNS records for domain authentication.
- CRM and helpdesk systems that send replies to customers “from” your support address.
- Online shop platforms sending order confirmations, shipping updates and abandoned cart reminders.
- Invoicing and booking tools that email invoices, quotes or appointment reminders in your name.
- Website forms and plugins that send mail through the hosting server, which signs with the hosting company’s domain or does not sign at all.
- Mailing lists and groups that forward messages from members to other members.
The last case is different from the others: when a list forwards someone else’s message, the list is not you, and some label or rewriting is expected. For the first five, the service sends on your behalf, so it can and should authenticate as your domain.
How to remove “via”: set up DKIM for your domain
Nearly every reputable sending service offers a setting usually called domain authentication, custom DKIM, sender authentication or verified domain. The steps follow the same pattern everywhere:
- Open the sending service’s domain settings and add your domain, for example
yourshop.com. - Copy the DNS records it gives you. These are usually one to three CNAME or TXT records for DKIM, with names like
s1._domainkey.yourshop.com, and sometimes a record for a custom bounce or tracking domain. - Add the records at your DNS provider exactly as shown. Do not change existing DKIM records of other services; each service uses its own selector, as explained in our guide to DKIM selectors.
- Verify the domain in the service once the records have propagated, which often takes minutes but can take longer.
- Send a test message to a Gmail address and check “Show original”: DKIM should now pass with
d=yourshop.com, and the “via” label should be gone.
If the service offers a custom Return-Path or bounce domain, set that up too. It lets SPF pass for a subdomain of your domain, which gives you a second aligned result. Our guide to authenticating third-party senders explains how to do this for several services without breaking your SPF record.
What alignment means and why DMARC cares
DMARC uses the same idea as Gmail’s label but turns it into a policy. A message passes DMARC only if SPF or DKIM passes and the domain that passed is aligned with the From domain. In relaxed mode, the default, a subdomain counts as aligned: d=mail.yourshop.com aligns with [email protected]. In strict mode the domains must match exactly.
This matters because a message that shows “via” is very often a message that fails DMARC alignment. While your DMARC policy is p=none, nothing happens apart from the label and the entries in your aggregate reports. Once you move to p=quarantine or p=reject, unaligned messages from that service may land in spam or be rejected. Fixing “via” before tightening DMARC is therefore not cosmetic. Read more in DMARC alignment explained.
Your DMARC aggregate reports are the best place to find every sender that still causes the problem. Look for sources where DKIM passes but is not aligned: those are the services that sign mail with their own domain.
Special cases: website forms, forwarding and shared addresses
Contact forms on your website. Many plugins send mail through the web server with a From address on your domain. The server is not listed in your SPF and does not sign with your DKIM key, so the message may show “via” a hosting domain, or worse, land in spam. The reliable fix is to send website mail through an authenticated SMTP account or a transactional email service that has DKIM set up for your domain.
Using a visitor’s address as From. Some forms put the visitor’s own address in the From field. That can never authenticate, because you do not control the visitor’s domain. Put your own address in From and the visitor’s address in Reply-To instead.
Sending as another address in Gmail. If you use Gmail’s “Send mail as” feature with a different domain and send through Gmail’s servers, recipients can see “via gmail.com” or a similar hint. Configure the alias to send through your own domain’s SMTP server, or use an email provider for that domain.
Forwarding and mailing lists. Forwarded messages may lose SPF, and lists that modify messages can break DKIM. Here the label reflects reality and is not something you can fully control as the original sender, which is one reason why DKIM, which survives most simple forwarding, is so important.
A quick checklist to keep “via” away
- List every service that sends email using your domain in the From address, including shop, CRM, invoicing and website plugins.
- Set up DKIM for your domain in each of them, with its own selector.
- Add each service to SPF only if it uses your domain in the Return-Path, and keep the total within the 10 DNS lookup limit.
- Publish a DMARC record and read the aggregate reports for unaligned sources.
- Send a test message from every service to a Gmail address after each change.
- Repeat the check whenever you add a new tool or switch provider.
How Site AI Audit helps
Site AI Audit checks email authentication for your domain alongside the website itself: SPF and its lookup limit, DKIM signatures, the DMARC policy and MX records. Missing or broken records are reported with a plain-language explanation of what they mean for the inbox and a concrete fix, ranked by impact. It checks your DNS from the outside, so it does not see how each individual service signs its messages; use a test email and “Show original” for that. You can check your domain for free; paid plans add re-checks and monitoring with alerts, as listed on the pricing page.
Related reading
- What Is DKIM and How to Set It Up for Your Domain
- From Name and Address: Email Sender Details That Build Trust
- DKIM Failing? How to Troubleshoot dkim=fail and dkim=none
- DMARC Explained: Policies, Alignment and a Safe Rollout
The bottom line
The “via” label in Gmail means a message carries your name but was authenticated by someone else’s domain. It is common, harmless to delivery on its own, but it costs trust and usually signals a DMARC alignment gap. Set up DKIM for your own domain in every service that sends in your name, check the result with a test message, and the label disappears while your domain becomes ready for a stricter DMARC policy.
DUK
Does the “via” label mean my email went to spam?
No. The label only shows that the message was authenticated by a different domain than the one in the From address. It can appear on messages in the inbox, but it often points to an alignment gap that can hurt delivery once DMARC is enforced.
Why does “via” appear only for some of my emails?
Because each sending service is configured separately. Messages from your main mailbox may be signed with your domain, while a newsletter tool, shop or website form still signs with its own domain.
Is adding the service to my SPF record enough?
Usually not. SPF checks the Return-Path domain, which many services set to their own domain. DKIM signed with your domain is the reliable way to remove the label.
How long does it take for the label to disappear?
New messages are affected as soon as the service starts signing with your domain, usually right after DNS verification. Messages already delivered keep the label.
Can I remove “via” for messages forwarded by a mailing list?
Only partly. The list sends the message, not you, so the list itself must handle authentication. As the original sender you can make sure your DKIM signature is in place so it survives simple forwarding.



