Sales Methodology & Revenue OperationsChecklist4 min readUpdated September 2026

Cold Email Deliverability Checklist: SPF, DKIM and DMARC

SPF, DKIM and DMARC are three DNS-based checks that prove your email really comes from your domain. For cold email, all three should pass before you send. SPF lists which servers may send for you, DKIM adds a signature to each message, and DMARC tells receiving servers what to do when a message fails and sends you reports.

Passing authentication doesn't guarantee inbox placement, but failing it makes trouble certain. Major mailbox providers publish sender requirements that expect authentication, so set it up first.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

What does each of the three records do?

Understand each one so you can fix it when it breaks:

  • SPF (Sender Policy Framework): a DNS record listing the mail servers and services allowed to send on behalf of your domain. Receiving servers check the sending server against it.
  • DKIM (DomainKeys Identified Mail): your sending service signs each message with a private key, and receivers verify the signature using a public key you publish in DNS. It shows the message wasn't altered and came from an authorized sender.
  • DMARC (Domain-based Message Authentication, Reporting and Conformance): a policy that requires SPF or DKIM to pass and align with the visible From domain, and says what receivers should do with failures: nothing, quarantine or reject. It also sends aggregate reports.

Alignment is the part people miss. The domain in your From address has to match the domain that passes SPF or DKIM, otherwise DMARC fails even when the other two pass.

How to set up authentication, step by step

Work through this list for each sending domain:

  1. List every service that sends email from the domain, including your mailbox provider and any sending or outreach tools.
  2. Publish one SPF record that includes all of them. A domain can have only one SPF record, and multiple records make SPF fail.
  3. Turn on DKIM in your mailbox provider and in each sending tool, then add the public keys they give you as DNS records.
  4. Publish a DMARC record starting in monitoring mode, with a policy of none and an address for reports.
  5. Send tests to accounts at several providers and read the message headers to confirm SPF, DKIM and DMARC show as pass.
  6. Review the DMARC reports for a few weeks, fix any legitimate sender that fails, then tighten the policy step by step.
  7. Recheck after any change to your sending tools, since adding a service can break SPF.

Which DNS mistakes break authentication most often?

These are the usual culprits when tests fail:

  • Two SPF records. Combine them into one.
  • Too many lookups. SPF allows a limited number of DNS lookups, and including many services can exceed it. Remove services you no longer use.
  • Wrong record type or host name. DKIM and DMARC records sit on specific host names, and a typo means receivers never find them.
  • DNS provider quirks, such as automatically adding the domain name to the host field, or splitting long DKIM keys incorrectly.
  • Old tools still listed. Sending services you canceled can stay in SPF and create risk.
  • No DMARC record at all, which some large providers treat as a warning sign.
  • Changes not yet propagated. Records can take time to be visible everywhere, so recheck before assuming they're wrong.

What else affects deliverability beyond authentication?

Authentication proves who you are. It doesn't prove you're worth reading. Once it passes, look at:

  • List quality: verify addresses and remove role accounts and known bounces. High bounce rates damage reputation quickly.
  • Volume and pacing: keep daily sending per mailbox modest and steady, as covered in how many cold emails per day per inbox.
  • Domain history: a new domain needs warm-up, described in warming up a new domain.
  • Content: avoid spammy wording, many links or images and misleading subject lines.
  • Unsubscribe and identity: include your company details and an easy way to opt out.
  • Provider requirements: large mailbox providers publish sender requirements, including authentication and low complaint rates, and the Google and Yahoo bulk sender requirements guide covers how they apply to cold outreach. Check current wording on their sites.

Even once a delivered email turns into an opportunity, the average B2B new-logo win rate is 19 percent1, so most won't close. Reaching the inbox is only the first step, but without it none of the rest can happen.

How do you monitor deliverability over time?

Set a monthly routine, using the cold email deliverability audit checklist as a template:

  • Recheck SPF, DKIM and DMARC after any tool change.
  • Read the DMARC reports for unknown senders.
  • Send placement tests to seed addresses at major providers.
  • Review bounce and complaint patterns by domain and mailbox.

Tools can help. MailReach fits teams that want to warm up inboxes and watch spam scores continuously. InboxAlly fits teams with a domain whose placement has slipped and needs repair using seed lists. Neither replaces correct DNS records, so fix authentication first. Compare them in InboxAlly vs MailReach vs Warmup Inbox.

Executive Capability Standard

What Good Looks Like

Every sending domain has one SPF record, DKIM keys for each sending service and a DMARC record that has moved from monitoring to enforcement, with headers checked after any tool change.

Building The Capability (5-Stage Skill Ladder)

1. Learn:Learn what SPF, DKIM and DMARC do, and what alignment means.
2. Do Manually:List your sending services, publish the DNS records and read the headers of a test email at several providers.
3. Delegate:Assign one owner to review DMARC reports and recheck authentication whenever a sending tool changes.
4. Automate:Set up automated monitoring of DNS records and placement tests with alerts on failure.
5. Buy:Add a warm-up and reputation monitoring tool after authentication is correct, and a repair service if placement has slipped.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

InboxAlly

Fits when a domain's inbox placement has slipped and you want seed-list based repair on top of correct authentication.

Visit InboxAlly→
MailReach

Fits when you want inbox warm-up and continuous spam score monitoring once authentication passes.

Visit MailReach→

Frequently Asked Questions

What are SPF, DKIM and DMARC?

They're three DNS-based email authentication methods. SPF lists the servers allowed to send for your domain, DKIM adds a verifiable signature to each message and DMARC sets a policy for failures and sends reports. Together they help receiving servers confirm that email really comes from you.

Should I set up all three for cold email?

Yes, set up all three before you send. Authentication is expected by major mailbox providers, and missing or failing records raise the chance that your messages go to spam. DMARC also gives you reports that show who is sending mail using your domain, which helps you catch problems.

What DMARC policy should I start with?

Start with a policy of none, which monitors without affecting delivery, and collect reports for a few weeks. Fix any legitimate sender that fails, then move to quarantine and later reject if you're confident everything passes. Tightening too soon can block your own legitimate email.

Why is my SPF failing even though I added the record?

Common causes are more than one SPF record on the domain, too many DNS lookups, a service missing from the record or a mistake in the host name. DNS changes can also take time to propagate. Check the record with a lookup tool and test again after a short wait.

Sources

Where we quote a benchmark, we show its source. Other figures in this guide are estimates or general guidance, so check them against your own numbers.

  1. Average B2B new-logo win rate. Ebsta x Pavilion 2025 GTM Benchmarks Report, 2025.

Related Guides