Blog

· 6 min read

SPF, DKIM and DMARC for cold email: what you actually need

The three DNS records every sending domain needs, what each one proves, and the settings that are safe for cold outreach.

If you send cold email from a domain without SPF, DKIM and DMARC, you are asking Gmail and Outlook to trust a stranger with no ID. Since early 2024 both Google and Yahoo require authentication from anyone sending in volume, and unauthenticated mail is the first thing their filters push aside.

The good news: it's three DNS records, set up once.

What each record proves

RecordQuestion it answersWhere it lives
SPFIs this server allowed to send for the domain?TXT on the domain
DKIMWas this email signed by the domain, and left unchanged?TXT at selector._domainkey
DMARCWhat should a receiver do when SPF or DKIM fails?TXT at _dmarc

They work together. SPF and DKIM are the evidence; DMARC is the policy that tells receivers to act on it, and it requires that at least one of them aligns with the domain in your From address.

SPF: one record, every sender

List every service that sends email as your domain — your mailbox provider, your newsletter tool, your helpdesk — in a single TXT record:

v=spf1 include:_spf.google.com ~all

Two mistakes to avoid:

  • Two SPF records. Receivers treat that as an error. Merge them.
  • Ending in +all. That allows anyone to send as you. Use ~all (soft fail) or -all (hard fail).

SPF also has a limit of 10 DNS lookups. Each include: counts, and some include others, so long records quietly break. Remove services you no longer use.

DKIM: turn it on at your provider

DKIM is generated by whoever sends your mail. In Google Workspace it's under Apps → Gmail → Authenticate email; in Microsoft 365 it's in the Defender portal under Email authentication settings. You publish the key they give you as a TXT (or CNAME) record, then switch signing on.

Use a 2048-bit key if your DNS host allows it.

DMARC: start gentle, then tighten

A first DMARC record can simply watch:

v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com

p=none changes nothing about delivery but sends you reports about who is sending as your domain. Once those reports show only your own services passing, move to p=quarantine, and eventually p=reject. Receivers trust domains with an enforced policy more — and it stops others from spoofing you.

A separate domain for outreach?

Many teams send cold email from a second domain (for example getacme.com next to acme.com). If that domain's reputation suffers, your company's main email keeps working. If you do this:

  • set up SPF, DKIM and DMARC on the new domain too;
  • point its website at your main site, so prospects who check it find you;
  • give new mailboxes on it time to ramp up — see ramping up a new mailbox.

Checking your setup

Outsquid checks SPF, DKIM and DMARC for every connected mailbox's domain, and re-checks automatically. Each record is rated pass, partial or fail on the Mailboxes page, with the fix. The step-by-step guide in the help center has example records for Google and Microsoft, and the free DNS checker shows what any domain has right now.

Send your next campaign without worrying about the domain.

Start free

Free plan · 100 emails a month · no credit card