· 6 min read
SPF, DKIM and DMARC for cold email: what you actually need
The three DNS records every sending domain needs, what each one proves, and the settings that are safe for cold outreach.
If you send cold email from a domain without SPF, DKIM and DMARC, you are asking Gmail and Outlook to trust a stranger with no ID. Since early 2024 both Google and Yahoo require authentication from anyone sending in volume, and unauthenticated mail is the first thing their filters push aside.
The good news: it's three DNS records, set up once.
What each record proves
| Record | Question it answers | Where it lives |
|---|---|---|
| SPF | Is this server allowed to send for the domain? | TXT on the domain |
| DKIM | Was this email signed by the domain, and left unchanged? | TXT at selector._domainkey |
| DMARC | What should a receiver do when SPF or DKIM fails? | TXT at _dmarc |
They work together. SPF and DKIM are the evidence; DMARC is the policy that tells receivers to act on it, and it requires that at least one of them aligns with the domain in your From address.
SPF: one record, every sender
List every service that sends email as your domain — your mailbox provider, your newsletter tool, your helpdesk — in a single TXT record:
v=spf1 include:_spf.google.com ~all
Two mistakes to avoid:
- Two SPF records. Receivers treat that as an error. Merge them.
- Ending in
+all. That allows anyone to send as you. Use~all(soft fail) or-all(hard fail).
SPF also has a limit of 10 DNS lookups. Each include: counts, and some
include others, so long records quietly break. Remove services you no longer
use.
DKIM: turn it on at your provider
DKIM is generated by whoever sends your mail. In Google Workspace it's under Apps → Gmail → Authenticate email; in Microsoft 365 it's in the Defender portal under Email authentication settings. You publish the key they give you as a TXT (or CNAME) record, then switch signing on.
Use a 2048-bit key if your DNS host allows it.
DMARC: start gentle, then tighten
A first DMARC record can simply watch:
v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com
p=none changes nothing about delivery but sends you reports about who is
sending as your domain. Once those reports show only your own services
passing, move to p=quarantine, and eventually p=reject. Receivers trust
domains with an enforced policy more — and it stops others from spoofing you.
A separate domain for outreach?
Many teams send cold email from a second domain (for example getacme.com
next to acme.com). If that domain's reputation suffers, your company's main
email keeps working. If you do this:
- set up SPF, DKIM and DMARC on the new domain too;
- point its website at your main site, so prospects who check it find you;
- give new mailboxes on it time to ramp up — see ramping up a new mailbox.
Checking your setup
Outsquid checks SPF, DKIM and DMARC for every connected mailbox's domain, and re-checks automatically. Each record is rated pass, partial or fail on the Mailboxes page, with the fix. The step-by-step guide in the help center has example records for Google and Microsoft, and the free DNS checker shows what any domain has right now.