Cold Email Deliverability Checklist: SPF, DKIM and DMARC
SPF, DKIM and DMARC are three DNS-based checks that prove your email really comes from your domain. For cold email, all three should pass before you send. SPF lists which servers may send for you, DKIM adds a signature to each message, and DMARC tells receiving servers what to do when a message fails and sends you reports.
Passing authentication doesn't guarantee inbox placement, but failing it makes trouble certain. Major mailbox providers publish sender requirements that expect authentication, so set it up first.
Vendors Covered in this Article
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
What does each of the three records do?
Understand each one so you can fix it when it breaks:
- SPF (Sender Policy Framework): a DNS record listing the mail servers and services allowed to send on behalf of your domain. Receiving servers check the sending server against it.
- DKIM (DomainKeys Identified Mail): your sending service signs each message with a private key, and receivers verify the signature using a public key you publish in DNS. It shows the message wasn't altered and came from an authorized sender.
- DMARC (Domain-based Message Authentication, Reporting and Conformance): a policy that requires SPF or DKIM to pass and align with the visible From domain, and says what receivers should do with failures: nothing, quarantine or reject. It also sends aggregate reports.
Alignment is the part people miss. The domain in your From address has to match the domain that passes SPF or DKIM, otherwise DMARC fails even when the other two pass.
How to set up authentication, step by step
Work through this list for each sending domain:
- List every service that sends email from the domain, including your mailbox provider and any sending or outreach tools.
- Publish one SPF record that includes all of them. A domain can have only one SPF record, and multiple records make SPF fail.
- Turn on DKIM in your mailbox provider and in each sending tool, then add the public keys they give you as DNS records.
- Publish a DMARC record starting in monitoring mode, with a policy of none and an address for reports.
- Send tests to accounts at several providers and read the message headers to confirm SPF, DKIM and DMARC show as pass.
- Review the DMARC reports for a few weeks, fix any legitimate sender that fails, then tighten the policy step by step.
- Recheck after any change to your sending tools, since adding a service can break SPF.
Which DNS mistakes break authentication most often?
These are the usual culprits when tests fail:
- Two SPF records. Combine them into one.
- Too many lookups. SPF allows a limited number of DNS lookups, and including many services can exceed it. Remove services you no longer use.
- Wrong record type or host name. DKIM and DMARC records sit on specific host names, and a typo means receivers never find them.
- DNS provider quirks, such as automatically adding the domain name to the host field, or splitting long DKIM keys incorrectly.
- Old tools still listed. Sending services you canceled can stay in SPF and create risk.
- No DMARC record at all, which some large providers treat as a warning sign.
- Changes not yet propagated. Records can take time to be visible everywhere, so recheck before assuming they're wrong.
What else affects deliverability beyond authentication?
Authentication proves who you are. It doesn't prove you're worth reading. Once it passes, look at:
- List quality: verify addresses and remove role accounts and known bounces. High bounce rates damage reputation quickly.
- Volume and pacing: keep daily sending per mailbox modest and steady, as covered in how many cold emails per day per inbox.
- Domain history: a new domain needs warm-up, described in warming up a new domain.
- Content: avoid spammy wording, many links or images and misleading subject lines.
- Unsubscribe and identity: include your company details and an easy way to opt out.
- Provider requirements: large mailbox providers publish sender requirements, including authentication and low complaint rates, and the Google and Yahoo bulk sender requirements guide covers how they apply to cold outreach. Check current wording on their sites.
Even once a delivered email turns into an opportunity, the average B2B new-logo win rate is 19 percent1, so most won't close. Reaching the inbox is only the first step, but without it none of the rest can happen.
How do you monitor deliverability over time?
Set a monthly routine, using the cold email deliverability audit checklist as a template:
- Recheck SPF, DKIM and DMARC after any tool change.
- Read the DMARC reports for unknown senders.
- Send placement tests to seed addresses at major providers.
- Review bounce and complaint patterns by domain and mailbox.
Tools can help. MailReach fits teams that want to warm up inboxes and watch spam scores continuously. InboxAlly fits teams with a domain whose placement has slipped and needs repair using seed lists. Neither replaces correct DNS records, so fix authentication first. Compare them in InboxAlly vs MailReach vs Warmup Inbox.
What Good Looks Like
Every sending domain has one SPF record, DKIM keys for each sending service and a DMARC record that has moved from monitoring to enforcement, with headers checked after any tool change.
Building The Capability (5-Stage Skill Ladder)
How to Get Started
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
Frequently Asked Questions
What are SPF, DKIM and DMARC?
They're three DNS-based email authentication methods. SPF lists the servers allowed to send for your domain, DKIM adds a verifiable signature to each message and DMARC sets a policy for failures and sends reports. Together they help receiving servers confirm that email really comes from you.
Should I set up all three for cold email?
Yes, set up all three before you send. Authentication is expected by major mailbox providers, and missing or failing records raise the chance that your messages go to spam. DMARC also gives you reports that show who is sending mail using your domain, which helps you catch problems.
What DMARC policy should I start with?
Start with a policy of none, which monitors without affecting delivery, and collect reports for a few weeks. Fix any legitimate sender that fails, then move to quarantine and later reject if you're confident everything passes. Tightening too soon can block your own legitimate email.
Why is my SPF failing even though I added the record?
Common causes are more than one SPF record on the domain, too many DNS lookups, a service missing from the record or a mistake in the host name. DNS changes can also take time to propagate. Check the record with a lookup tool and test again after a short wait.
Sources
Where we quote a benchmark, we show its source. Other figures in this guide are estimates or general guidance, so check them against your own numbers.
- Average B2B new-logo win rate. Ebsta x Pavilion 2025 GTM Benchmarks Report, 2025.
Related Guides
Safe Cold Email Volume: How Many Emails Can One Inbox Send a Day?
There's no universal safe number. Learn how to set a per-inbox daily cap, ramp it by domain age and list quality, and scale with more inboxes instead.
How to Warm Up a New Domain for Cold Email, Step by Step
Set up authentication, ramp volume gradually and monitor placement so a new sending domain builds a reputation before you send real cold outreach.
Google and Yahoo Bulk Sender Rules for Cold Email
What Gmail and Yahoo's bulk sender rules require, how to set up SPF, DKIM and DMARC, and how cold email teams stay under spam thresholds.
The Monthly Check That Keeps a Sending Domain Healthy
A short monthly checklist covering authentication records, blocklist status, and inbox placement so a sending domain's reputation problem gets caught early.
InboxAlly vs Mailreach vs Warmup Inbox: Deliverability Guide
Compare InboxAlly, Mailreach, and Warmup Inbox for sales outreach. Evaluate spam repair, inbox placement, seed networks, and deliverability analytics.
Cold Email Reply Rates by Industry: Build Your Own Benchmark
Why published cold email reply rates by industry disagree, how to define and measure a reply, and how to build your own benchmark table by segment.