AuthenticationBy the MailFleet teamPublished 22 September 20266 min read

SPF, DKIM and DMARC for cold email — set up and check all three in 20 minutes

What SPF, DKIM and DMARC each do, the exact DNS records for Google Workspace and Microsoft 365, the alignment rule Gmail enforces, how to check them, and the mistakes that silently fail.

Three DNS records decide whether a receiving server believes your email came from you. Since 2024, Gmail requires every sender to have at least one of them and bulk senders to have all three (Google's sender guidelines); Yahoo has matching rules and Microsoft announced equivalent ones for Outlook.com in 2025. For cold email — where you have no relationship with the recipient to fall back on — treat all three as mandatory from the first message.

This is the whole job, in order.

What each one does

SPF (Sender Policy Framework) is a DNS TXT record on your domain that lists which servers may send mail claiming to be from it. A receiver checks the connecting server's IP against that list.

DKIM (DomainKeys Identified Mail) is a cryptographic signature added to each message by your mail provider, verified against a public key you publish in DNS. It proves the message wasn't altered and that it was sent by a server holding your private key.

DMARC (Domain-based Message Authentication, Reporting and Conformance) is a policy record that tells receivers what to do when SPF or DKIM fails and whether the domain that passed matches the domain in your From address (alignment). It also asks receivers to send you reports.

SPF and DKIM say "this mail is from a server we authorised." DMARC says "and it must be our domain that was authorised, not just someone's." Alignment is the part people miss.

The records

Replace yourdomain.com with the domain in your From address — for cold email, that should be a lookalike outreach domain, not your primary one.

Google Workspace

SPF — TXT record at the root of the domain:

v=spf1 include:_spf.google.com ~all

DKIM — in the Google Admin console: Apps → Google Workspace → Gmail → Authenticate email, generate a 2048-bit key, publish the TXT record it gives you at google._domainkey.yourdomain.com, then click Start authentication. It can take up to 48 hours for Google to begin signing.

Microsoft 365

SPF:

v=spf1 include:spf.protection.outlook.com -all

DKIM — in the Microsoft 365 Defender portal under Email authentication settings → DKIM, select the domain, create the two CNAME records it shows (selector1._domainkey and selector2._domainkey pointing at Microsoft's hosts), then enable signing.

DMARC (any provider)

TXT record at _dmarc.yourdomain.com:

v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com; adkim=r; aspf=r

Start with p=none — it changes nothing about delivery and starts sending you aggregate reports. After a week or two of reports showing that all your legitimate mail passes, move to p=quarantine, and later p=reject if you are confident. Cold email itself does not need reject; it needs the record to exist and alignment to pass.

Alignment — the rule Gmail actually enforces

For DMARC to pass, at least one of these must be true:

  • SPF alignment: the domain in the Return-Path (the envelope sender your provider uses) matches the From domain (relaxed alignment allows a subdomain).
  • DKIM alignment: the d= domain in the DKIM signature matches the From domain.

Google Workspace and Microsoft 365 both sign DKIM with your own domain when set up as above, so DKIM alignment passes. If you send through a third-party SMTP relay, its DKIM signature may be for its domain — then you need the relay to sign with a key on your domain, or DMARC fails even though "DKIM passes".

Check it before sending

  1. Send a message to a Gmail address you control, open it, choose Show original. The header block shows SPF, DKIM and DMARC as PASS or FAIL, with the domain each was evaluated against.
  2. Look up the records directly. From a terminal: dig TXT yourdomain.com, dig TXT google._domainkey.yourdomain.com (or selector1._domainkey), dig TXT _dmarc.yourdomain.com.
  3. Read one DMARC aggregate report after a few days. It lists every source that sent mail as your domain and whether each passed — which is also how you discover a forgotten SaaS tool sending on your behalf.

In MailFleet, the Domains tab on the Mailboxes page shows SPF, DKIM and DMARC per sending domain (with a Check DNS button to look again after you change a record), and Final Review will not let you deploy a campaign while SPF or DKIM is missing on a sender's domain.

The mistakes that fail silently

  • Two SPF records. A domain may have exactly one v=spf1 record. Two — often from adding a new provider without editing the existing record — means SPF fails outright. Merge them into one.
  • More than 10 DNS lookups in SPF. Each include: (and the includes inside it) counts. Over ten, receivers treat SPF as a permanent error. Remove services you no longer use; some providers offer a "flattened" include.
  • +all or no all term. +all authorises everyone. End the record with ~all (soft fail) or -all (hard fail).
  • DKIM generated but not enabled. Publishing the key is step one; clicking Start authentication / Enable is step two. Until then nothing is signed.
  • A 1024-bit key when 2048 is available. Some receivers score short keys lower. Use 2048.
  • Sending via a relay that doesn't align. Covered above — check the d= domain in Show original.
  • Changing providers and forgetting SPF. The old include stays, the new one never gets added; mail from the new provider fails SPF and, if DKIM isn't set up yet, DMARC too.
  • Setting p=reject on day one. If any legitimate source isn't aligned yet, its mail is discarded. none → quarantine → reject, with reports in between.

Do you need DMARC at cold email volume?

Gmail's hard requirement for DMARC applies to senders of 5,000 or more messages a day to Gmail addresses. A single outreach domain rarely reaches that. But three things make it worth two minutes anyway: it is a positive signal receivers weigh; it stops anyone spoofing your domain (and spoofed domains get spam-listed, which hurts your mail); and the reports tell you when authentication breaks before your reply rate does.

One-click unsubscribe belongs in the same conversation

The same 2024 rules require bulk senders to include RFC 8058 one-click unsubscribe headers (List-Unsubscribe and List-Unsubscribe-Post) and to honour requests within two days. Authentication gets you judged fairly; unsubscribe headers keep the complaint rate — which Gmail says to hold below 0.3% and ideally 0.1% — from undoing the judgement. MailFleet adds both headers to every send.

FAQ

Do I need SPF, DKIM and DMARC for cold email?

Yes. Gmail requires SPF or DKIM from every sender and all three (with alignment) from senders of 5,000+ messages a day. At any volume, missing records are the most common cause of cold email landing in spam.

Which is more important, SPF or DKIM?

DKIM, narrowly — it survives forwarding and aligns naturally with your From domain. But set up both; DMARC only needs one to pass, and having two means one can break without your mail failing.

How long do DNS changes take?

Minutes to a few hours for the records to propagate; up to 48 hours for Google to start DKIM-signing after you enable it.

What DMARC policy should cold email use?

Start with p=none to collect reports, move to p=quarantine once everything legitimate passes. p=reject is optional for outreach domains.

Can I check authentication without sending an email?

You can look up the records with dig or an online lookup, but only a real message shows you the evaluated result. Send one to a Gmail inbox and use Show original.

Try MailFleet free for 7 days

2,000 leads and 10,000 emails to test with. Card required — nothing is charged for 7 days.