For every domain you send cold email from, publish one SPF record that lists your sending sources, enable DKIM signing with a key under that same domain, and add a DMARC record that starts at p=none with a reporting address. Then send a test message and confirm that spf, dkim and dmarc all pass with the From domain aligned. Authentication does not guarantee inbox placement; it removes a reason to be rejected.
This is the working setup, not the theory. Each section gives the record, a provider note and a way to check it.
What each record does
| Record | Question it answers | Where it lives |
|---|---|---|
| SPF | Is this server allowed to send mail for the envelope domain? | TXT on the domain |
| DKIM | Was this message signed by the domain and left unmodified? | TXT (or CNAME) at selector._domainkey.domain |
| DMARC | Does the From domain align with an SPF or DKIM pass, and what should a receiver do if not? | TXT at _dmarc.domain |
Who requires them: Google asks all senders for SPF or DKIM and bulk senders for all three; Yahoo asks for SPF or DKIM from everyone and all three from bulk senders; Microsoft requires SPF, DKIM and DMARC (at least p=none) from domains sending more than 5,000 emails a day. Bulk thresholds differ by provider, as covered in cold email deliverability. Set up all three on every sending domain regardless of volume.
Step 1: SPF
SPF is a TXT record that lists the sources allowed to send for the domain. Examples below use example.com.
; Google Workspace only
example.com. TXT "v=spf1 include:_spf.google.com ~all"
; Microsoft 365 only
example.com. TXT "v=spf1 include:spf.protection.outlook.com -all"
; Microsoft 365 plus one other service that documents its own include
example.com. TXT "v=spf1 include:spf.protection.outlook.com include:send.provider.example -all"
Rules that cause most failures:
- One record per domain. RFC 7208 forbids multiple records that would both be selected. Microsoft documents that multiple SPF TXT records cause
permerror. If you add a second sending service, add itsinclude:to the existing record instead of creating another. - At most 10 DNS lookups.
include,a,mx,existsandredirecteach count, and nested includes count too. Individualip4andip6values do not. Over 10 returnspermerror(RFC 7208, Microsoft’s SPF guide). -allor~all. Google’s Workspace guide recommends~all. Microsoft recommends-allwhen DKIM and DMARC are also configured, and notes that DMARC policy is effectively ignored for~allfailures if the message has no DKIM signature. Pick one and be consistent; either way, DKIM does the real work for DMARC.- Each subdomain needs its own record. The record for
example.comdoes not covermail.example.com. - Typos. Microsoft lists a trailing dot,
include=instead ofinclude:and a space after the colon as common syntax errors.
Step 2: DKIM
DKIM signs outgoing mail with a private key; receivers fetch the public key from DNS.
; Public key published as TXT under a selector you choose
s1._domainkey.example.com. TXT "v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQ..."
; Microsoft 365 uses two CNAME records instead
selector1._domainkey.example.com. CNAME selector1-example-com._domainkey.<tenant>.<region>.dkim.mail.microsoft.
selector2._domainkey.example.com. CNAME selector2-example-com._domainkey.<tenant>.<region>.dkim.mail.microsoft.
(The Microsoft CNAME targets are shown in a generic form; use the exact values that the Defender portal gives you.)
Practical points:
- Key length. RFC 6376 says signers must use RSA keys of at least 1024 bits. Yahoo asks for a minimum of 1024 bits. Google’s admin guide recommends 2048 bits if your DNS host supports them. Use 2048 where you can.
- Selector. Google Workspace defaults to a selector named
google. Microsoft usesselector1andselector2. A platform that signs for you will tell you which selector to publish. - Order of operations in Google Workspace. Add the TXT record first, then start authentication in the Admin console. Google says it can take up to 48 hours for DKIM authentication to start working.
- Sign with your own domain. The
d=domain in the signature must align with your From domain, or DKIM passes without helping DMARC. See the alignment section.
Step 3: DMARC
; Start here
_dmarc.example.com. TXT "v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com"
; Later, once every legitimate source passes
_dmarc.example.com. TXT "v=DMARC1; p=quarantine; pct=100; rua=mailto:dmarc-reports@example.com"
- Prerequisites. SPF and DKIM first. Google says to allow 48 hours after setting them up before setting up DMARC.
- Policy values.
nonetakes no action and is for monitoring,quarantineasks receivers to treat failures as suspicious,rejectasks them to refuse the message (RFC 7489; Microsoft’s DMARC guide). - Reports.
ruareceives aggregate reports. Use a dedicated mailbox or a reporting service, not a personal inbox, because the volume can be high. An external reporting address needs an authorisation record on the receiving domain (Microsoft’s DMARC guide gives the format). - Rollout. Both Google and Microsoft recommend starting at
p=noneand tightening gradually. Microsoft describes moving toquarantine, usingpctto raise coverage step by step, then toreject. - Cold sending domains. A domain that only sends your outreach has few legitimate sources, so moving to
quarantineorrejectcan be quick. That is a choice, not a requirement; the minimum accepted by Google, Yahoo and Microsoft for bulk senders isp=none. - Subdomains. A DMARC record applies to subdomains without their own record. Each subdomain still needs its own SPF and DKIM.
Alignment: why DMARC fails when SPF and DKIM pass
DMARC passes if either SPF or DKIM passes and aligns with the domain in the visible From address. Alignment is relaxed by default: the organisational domain must match, so a subdomain can align with its parent. Strict alignment requires an exact match.
| From domain | SPF envelope domain or DKIM d= | Relaxed | Strict |
|---|---|---|---|
example.com | example.com | Pass | Pass |
example.com | bounces.example.com | Pass | Fail |
example.com | sender-service.example | Fail | Fail |
The third row is the usual cold-email failure: a sending service signs and uses its own domain for the envelope, so SPF and DKIM both pass for the service’s domain and DMARC fails for yours. The fix is to have the service sign with d=example.com (custom DKIM), or to use your domain in the envelope address. Google states the same requirement for bulk senders: the From domain must align with the SPF domain or the DKIM domain.
Test before you send
- Send a message from the new mailbox to an address you control at Gmail and at Outlook.
- Open the original message and find
Authentication-Results. - Confirm
spf=pass,dkim=passanddmarc=pass, and thatheader.fromis your sending domain. - If DMARC fails, compare
smtp.mailfromandheader.dwithheader.from; at least one of them should be your domain. - After the first week, read the aggregate reports for sources you did not expect.
Checklist
- One SPF record, fewer than 10 lookups, no typos.
- DKIM key published and a test message shows a pass with your domain in
d=. - DMARC at
_dmarcwithruato a mailbox you actually read. - Each sending subdomain has its own SPF and DKIM.
- A parked domain you do not send from can say so:
v=spf1 -alland a DMARC record withp=reject(Microsoft’s guidance). - Re-check the records after any provider or platform change.
How Dooxout handles this
Dooxout provisions sending domains and mailboxes. The preflight check before a campaign launch looks at the SPF, DKIM and DMARC records, the verified sending identity and the suppression list. You can also connect your own mailboxes and sending services; then the records are yours to publish, and the platform warns when something looks wrong and leaves the decision to you.
Authentication is one part of the picture. Dooxout also applies caps, a kill switch and a suppression list that cannot be disabled. See cold email infrastructure and email deliverability.
Frequently asked questions
Do I need SPF, DKIM and DMARC for cold email?
Yes, for any domain you send from. Google requires SPF or DKIM from all senders and SPF, DKIM and DMARC from bulk senders. Yahoo and Microsoft set similar requirements for bulk or high-volume senders. Even if you send far less than the thresholds, set all three up, because authentication is the baseline for being trusted at all.
Which DMARC policy should I start with?
Start with p=none and a reporting address, read the reports, then move to quarantine and reject once every legitimate source passes. Google, Yahoo and Microsoft accept p=none as the minimum for bulk senders. Microsoft and Google both describe a gradual move to stricter policies.
Why does DMARC fail when SPF and DKIM both pass?
Because of alignment. DMARC needs the domain in the visible From address to match the domain that passed SPF or the domain that signed DKIM. If a sending service uses its own domain for both, the checks pass individually and DMARC still fails. Configure DKIM signing with your own domain at the service.
Can I have two SPF records on one domain?
No. RFC 7208 says a domain must not have multiple records that would cause an authorisation check to select more than one record, and Microsoft documents that multiple SPF TXT records cause a permanent error. Merge the includes into a single record and keep it under 10 DNS lookups.
Sources
The external facts in this article were checked against these pages on . Provider limits and rules change, so check the current page before you rely on a number.
- www.rfc-editor.org/rfc/rfc7208.html
- www.rfc-editor.org/rfc/rfc6376.html
- www.rfc-editor.org/rfc/rfc7489.html
- learn.microsoft.com/en-us/defender-office-365/email-authentication-spf-configure
- learn.microsoft.com/en-us/defender-office-365/email-authentication-dkim-configure
- learn.microsoft.com/en-us/defender-office-365/email-authentication-dmarc-configure
- knowledge.workspace.google.com/admin/security/set-up-spf
- knowledge.workspace.google.com/admin/security/set-up-dkim
- knowledge.workspace.google.com/admin/security/set-up-dmarc
- support.google.com/a/answer/81126
- senders.yahooinc.com/best-practices
- techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/strengthening-email-ecosystem-outlook%e2%80%99s-new-requirements-for-high%e2%80%90volume-senders/4399730