Disclosure: This guide contains affiliate links to tools we use and recommend (Instantly, Smartlead). If you sign up through them, we may earn a commission at no extra cost to you. We only recommend infrastructure we would deploy for our own clients.
You can write the best-performing cold email sequence in the world, but if your domain does not have correctly configured SPF, DKIM, and DMARC records, most of those emails will land in spam. These three DNS records are the email authentication trinity: together they tell receiving mail servers that your domain can be trusted. The good news is that they are not difficult to set up. The bad news is that a misconfigured DMARC record can block every single email you send. In this guide we cover what each protocol does, how they work together, and the exact step-by-step setup process for Google Workspace, Microsoft 365, and any domain.
| Quick answer SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting and Conformance) are DNS-based email authentication protocols required for cold email deliverability. SPF specifies which mail servers are authorised to send email on behalf of your domain. DKIM adds a cryptographic signature to outgoing emails that proves they have not been tampered with. DMARC tells receiving servers what to do with emails that fail SPF or DKIM checks — reject, quarantine, or allow. All three must be correctly configured before you start any cold email sequence; missing or incorrect records directly increase spam placement rates. |
| 2026 update: this is now mandatory, not optional The major mailbox providers now enforce email authentication for anyone sending at volume. In February 2024, Google and Yahoo began requiring bulk senders (roughly 5,000+ messages per day) to have SPF, DKIM, and a DMARC record with at least p=none, with SPF or DKIM aligned to the sending domain. On May 5, 2025, Microsoft applied the same rule to Outlook.com, Hotmail.com, and Live.com: high-volume senders without valid SPF, DKIM, and DMARC (minimum p=none) are first routed to Junk, with outright rejection to follow. For cold email — where you often warm up several sending domains at once — treat all three records as a hard requirement on every domain from day one. |
What Is SPF, DKIM & DMARC — Plain-Language Explanation
Before touching your DNS, it helps to understand what each record actually does. Think of the three protocols as three layers of the same security check: one verifies who is allowed to send, one verifies the message was not altered, and one decides what happens when either check fails.
SPF — Sender Policy Framework
SPF is a DNS TXT record that lists which mail servers are allowed to send email on behalf of your domain. The simplest way to picture it is a guest list at the door: only messengers on the list get through, and anything sent from a server that is not listed looks suspicious to the receiving server.
A correct SPF record for a Google Workspace domain looks like this:
| v=spf1 include:_spf.google.com ~all |
The ending matters. ~all is a soft fail — mail from unlisted servers is accepted but marked as suspicious. -all is a hard fail — mail from unlisted servers is rejected outright. For cold email we recommend ~all, because a soft fail avoids accidentally blocking legitimate mail while your setup settles.
DKIM — DomainKeys Identified Mail
DKIM adds a digital signature to every email you send. When you enable it, your email provider generates a public/private key pair. The private key signs each outgoing message; the receiving server looks up the matching public key (published in your DNS) and verifies the signature. If the two match, the server knows the message genuinely came from your domain and was not modified in transit.
In practice, DKIM is what proves the content of your email has not been tampered with between your server and the recipient’s inbox. It is configured inside your email service provider — Google Workspace, Microsoft 365, Instantly, and Smartlead all generate the DKIM key for you and tell you exactly which DNS record to add.
DMARC — Domain-based Message Authentication, Reporting & Conformance
DMARC is the decision-making layer, and it is the record most cold email senders skip — which is exactly why it is worth getting right. It does two jobs. First, it tells receiving servers what to do with emails that fail SPF or DKIM checks. Second, it gives you reporting, so for the first time you can actually see who is sending mail using your domain, including anyone spoofing it. There are three policy options:
- p=none — monitoring only. Nothing is blocked; you simply collect data.
- p=quarantine — failing emails are sent to the spam folder.
- p=reject — failing emails are blocked entirely.
For cold email, the recommended approach is to start with p=none (monitor without blocking), then move to p=quarantine after about 30 days once you have confirmed there are no legitimate-sender problems. The DMARC record also includes a rua=mailto: address, which is where you receive XML reports showing exactly who is sending email on behalf of your domain.
| “Domains without DMARC records average 41% lower inbox placement rates on Microsoft/Outlook servers compared to DMARC-enabled domains, according to replyratepro.com’s 2026 deliverability infrastructure audit across 200+ sending domains.” |
The three records work as one system: SPF verifies the sending server is authorised, DKIM verifies the content has not been altered, and DMARC tells receiving servers what to do when either check fails. This matters most on Microsoft and Outlook servers, which enforce DMARC more strictly than Gmail. A domain missing any one of the three records will see measurably higher spam placement rates.
SPF Setup — Step-by-Step
Google Workspace SPF Setup
- Log in to your DNS management panel (Cloudflare, Namecheap, GoDaddy, or wherever your domain is hosted).
- Find the TXT records section and create a new TXT record with these values:
| Name: @ (or your domain, e.g. yourdomain.com) Type: TXT Value: v=spf1 include:_spf.google.com ~all TTL: 3600 |
- Save the record. DNS propagation takes 24–48 hours.
- Verify with the MXToolbox SPF Checker.
Microsoft 365 SPF Setup
The process is identical, only the include value changes. Create a single TXT record with:
| v=spf1 include:spf.protection.outlook.com ~all |
Instantly / Smartlead (Custom Sending Domain) SPF Setup
If you send through a cold email platform on a dedicated sending domain, each tool publishes its own SPF include value in its documentation. The key rule is that you can combine multiple senders in a single line:
| v=spf1 include:_spf.google.com include:sendgrid.net ~all |
| ⚠ Important: You cannot have two separate SPF TXT records for the same domain. All authorised senders must live inside one record. |
| “The most common SPF configuration mistake is creating two separate SPF TXT records for the same domain. This causes SPF to fail entirely — receiving servers use only the first record they find and ignore the second. Always combine multiple senders into a single SPF record.” |
DKIM Setup — Step-by-Step
Google Workspace DKIM Setup
- In the Google Admin Console, go to Apps → Google Workspace → Gmail → Authenticate email.
- Click “Generate new record.” Google will produce a DKIM public key.
- Copy the DNS record values:
| Name: google._domainkey.yourdomain.com Type: TXT Value: v=DKIM1; k=rsa; p=[your unique public key] |
- Add this record in your DNS management panel.
- Return to the Google Admin Console and click “Start authentication.”
- Verify with the MXToolbox DKIM Checker.
Microsoft 365 DKIM Setup
In Microsoft 365 open the Admin Center, then go to Security → Email & collaboration → Policies & rules → Threat policies → DKIM. Select your domain and choose Enable / Rotate keys. Microsoft automatically generates two CNAME records for you to add to your DNS.
DKIM for Instantly / Smartlead
If you use a custom tracking domain with a cold email platform, that domain also needs DKIM. Each tool’s documentation walks you through the exact records. One recommendation applies everywhere:
| Use a 2048-bit DKIM key, not 1024-bit. The longer key gives a stronger cryptographic signature and is the current standard receiving servers expect. |
Both providers make DKIM a two-step job: generate the key pair in the admin panel, then publish the public key as a DNS record. The setup itself takes under ten minutes, but DNS propagation can take 24–48 hours. Always verify with MXToolbox after propagation before starting any cold email sequence.
DMARC Setup — Step-by-Step
Starting DMARC Record (Recommended for Cold Email Senders)
- In your DNS panel, create a new TXT record:
| Name: _dmarc.yourdomain.com Type: TXT Value: v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com; pct=100 TTL: 3600 |
- Create a mailbox at dmarc@yourdomain.com, or use a free DMARC reporting service (MXToolbox, Postmark DMARC, or dmarcdigests.com).
- After 2–4 weeks, review the reports and confirm that only your authorised senders are sending on behalf of your domain.
- After 30 days, change the policy to p=quarantine if the reports show everything is clean.
DMARC Policy Progression & Reply Rate Impact
| DMARC Policy | What happens to failing email | Recommended period | Reply Rate Impact |
| p=none | Nothing — monitoring only | First 2–4 weeks | Baseline |
| p=quarantine | Emails go to the spam folder | After 30 days, if reports are clean | +0.3pp (signals Outlook trust) |
| p=reject | Emails are rejected entirely | Only if you control 100% of senders | +0.4pp (highest trust) |
| ⚠ Use p=reject only when you are 100% certain that all your authorised senders — newsletter tools, CRM, third-party apps — have SPF and DKIM configured correctly. A mistake here means every one of your emails is blocked. |
| “Cold email senders using DMARC p=quarantine or p=reject policies average 18% higher inbox placement on Microsoft/Outlook servers compared to p=none senders — Outlook actively rewards DMARC enforcement. Implementing a quarantine policy after a 30-day monitoring period adds approximately 0.3pp to cold email reply rates at scale.” — replyratepro.com 2026 deliverability benchmark |
The safe progression, then, is: start at p=none for 2–4 weeks to collect reporting data, then move to p=quarantine once the reports confirm all legitimate senders pass authentication. p=reject gives the strongest deliverability signal but carries real risk: any misconfigured third-party sender will have its emails silently dropped. Most cold email practitioners stay at p=quarantine for ongoing campaigns.
SPF, DKIM & DMARC Verification — How to Test Your Setup
Never launch a sequence on faith. After propagation, confirm that all three records resolve and that a real test message scores well. These free tools are the ones we rely on:
| Tool | What it checks | Price |
| MXToolbox | SPF, DKIM, DMARC, blacklists | Free |
| Mail-Tester | Overall spam score (aim for 10/10) | 3 free tests/day |
| Google Postmaster Tools | Gmail sender reputation | Free |
| DMARC Analyzer / dmarcdigests.com | Reads and interprets DMARC reports | Free (basic) |
| Instantly Warm-Up Analytics | Real-time deliverability monitoring | Included in Instantly plan |
How to Read Your Mail-Tester Result
- 10/10 — excellent; you are clear to send.
- 8–9/10 — good; usually sufficient to launch.
- Below 7/10 — a problem; find and fix it before running any sequence.
Run MXToolbox for each record individually, then send a live test through Mail-Tester and read the full breakdown — it tells you exactly which check failed and why. Set up Google Postmaster Tools even if you mainly target Outlook, as it catches Gmail reputation issues early, and if you send to Outlook at volume, keep an eye on your DMARC reports to confirm you meet Microsoft’s authentication requirements.
Common SPF, DKIM & DMARC Mistakes — And Fixes
Most deliverability problems that look mysterious come down to one of a handful of small configuration errors. Before you assume your copy or your list is the issue, rule these out first — each takes minutes to check and can be the difference between the inbox and the spam folder:
- Two SPF records on the same domain. Fix: Combine all include: values into a single TXT record.
- DKIM not enabled after generating the key. Fix: Google Workspace requires a manual “Start authentication” click after the DNS record is added.
- Setting p=reject too early. Fix: Start with p=none, monitor for 30 days, then escalate.
- Wrong DMARC subdomain (typing dmarc. instead of _dmarc.). Fix: The underscore is mandatory: _dmarc.yourdomain.com.
- Forgetting authentication for custom sending domains. Fix: Every sending domain, including outreach subdomains such as replies.yourdomain.com, needs its own SPF, DKIM, and DMARC.
- Not monitoring DMARC reports. Fix: Use dmarcdigests.com or Postmark’s free DMARC monitoring to catch spoofing attempts early.
- Exceeding the SPF 10-DNS-lookup limit. Fix: SPF allows a maximum of 10 DNS lookups (per RFC 7208); stacking too many include: statements causes a permerror and SPF failure. Keep your record lean or use SPF flattening if you send through several providers.
Full Cold Email DNS Checklist
Before you launch your first sequence, confirm every one of these:
☐ Dedicated sending domain (not your primary business domain)
☐ SPF record created and verified (MXToolbox)
☐ DKIM enabled and DNS record added
☐ DMARC created (p=none to start) with a reporting email
☐ Custom tracking domain configured (Instantly / Smartlead)
☐ MX records set (for receiving replies, if you use a reply domain)
☐ Email warmup running (at least 3–4 weeks before sequences)
☐ Mail-Tester.com score of 8/10 or higher
A fully configured cold email domain requires one SPF TXT record listing all authorised senders, one DKIM TXT record per sending provider, one DMARC TXT record starting with a p=none policy, MX records if the domain also receives replies, and a custom tracking domain for click tracking. Total DNS setup time is roughly 30–45 minutes; propagation adds 24–48 hours. Email warmup should run for 3–4 weeks before your first cold sequence goes live.
Expert Take
| “SPF, DKIM, and DMARC are not optional extras — they are the foundation your entire cold email program runs on. I see agencies spend weeks optimising subject lines while their domain is missing a DMARC record. Fix the infrastructure first. The good news: this is a one-time 30-minute setup that pays dividends for every email you ever send from that domain.” — Justina, SEO Specialist & Founder of SEO Skills Central |
Frequently Asked Questions
Do I need SPF, DKIM, and DMARC for cold email?
Yes — all three are now required, not just recommended. In February 2024 Google and Yahoo began requiring bulk senders (about 5,000+ messages/day) to authenticate with SPF and DKIM and publish a DMARC record with at least p=none. On May 5, 2025 Microsoft applied the same requirement to Outlook.com, Hotmail.com, and Live.com — high-volume senders that fail authentication are routed to Junk, with full rejection planned. Even below those volume thresholds, domains missing any of the three records experience materially higher spam placement rates, so for cold email you should configure all three on every sending domain.
What is the correct DMARC policy for cold email?
Start with p=none for the first 30 days to collect reporting data without blocking any emails. After reviewing the DMARC reports and confirming all your legitimate senders (ESP, CRM, newsletter tools) pass authentication, move to p=quarantine. Most cold email practitioners use p=quarantine as their ongoing policy. Only use p=reject if you have complete control over every sender using your domain.
Can I have multiple SPF records on the same domain?
No — having two SPF TXT records on the same domain causes SPF to fail entirely (per RFC 7208). All authorised sending sources must be combined into a single SPF record using multiple include: statements, for example: v=spf1 include:_spf.google.com include:sendgrid.net ~all.
How long does SPF, DKIM & DMARC setup take?
The actual configuration takes 30–45 minutes. DNS propagation then takes 24–48 hours before the records are active globally. Plan to set up all three at least 48–72 hours before starting email warmup, and at least 3–4 weeks before your first cold email sequence.
How do I check if my SPF, DKIM & DMARC are configured correctly?
Use MXToolbox to check all three records independently. Then send a test email to Mail-Tester.com and aim for a score of 8+/10. Google Postmaster Tools provides ongoing monitoring of your reputation with Gmail servers, and for DMARC report analysis use dmarcdigests.com or Postmark’s free DMARC monitoring tool.
