SPF, DKIM and DMARC are three DNS records that prove your cold emails really come from your domain. SPF lists the servers allowed to send for it, DKIM signs each message, and DMARC tells inbox providers what to do when a message fails.
A cold email domain needs all three before it sends anything, including warm-up mail. This page gives the exact records for a sending domain on Google Workspace, the order to add them, and how to check they work. It is part of our cold email deliverability guide.
What are SPF, DKIM and DMARC in cold email?
In cold email, SPF, DKIM and DMARC are how Gmail, Outlook and Yahoo decide whether a message from your sending domain is genuine. Without them, mail from a new domain looks the same as mail from someone faking it.
| Record | What it does | Where it lives | Example for Google Workspace |
|---|---|---|---|
| SPF | Lists the mail servers allowed to send for the domain | TXT record on the domain itself | v=spf1 include:_spf.google.com ~all |
| DKIM | Adds a signature to each email that proves it was not changed | TXT record at google._domainkey | A long public key generated in Google Workspace |
| DMARC | Says what to do if SPF and DKIM fail, and where to send reports | TXT record at _dmarc | v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com |
DMARC passes when either SPF or DKIM passes and matches the domain in the "From" address. That match is called alignment, and it is why all three are set up together.
Why do cold email domains need SPF, DKIM and DMARC?
Cold email domains need all three because inbox providers require them and because a new domain has no reputation to fall back on. A missing record is one of the fastest ways to land in spam.
Google requires every sender to Gmail to have SPF or DKIM, and senders of more than 5,000 messages a day to have SPF, DKIM and DMARC, according to its email sender guidelines. Yahoo has the same rules, and Microsoft added them for Outlook.com in May 2025.
Most cold email setups send far fewer than 5,000 a day per domain. Set up all three anyway. Providers treat full authentication as the sign of a careful sender, and a cold email domain needs every trust signal it can get.
How do you set up SPF for a cold email domain?
Set up SPF by adding one TXT record to the domain that lists Google as an allowed sender. For a domain that only sends through Google Workspace, the record is:
v=spf1 include:_spf.google.com ~all
Add it as a TXT record with the host set to @, meaning the domain itself. The ~all at the end tells receiving servers to treat mail from any other server as suspicious. Google recommends ~all in its SPF setup guide.
Three rules keep SPF working:
- One SPF record per domain. Two records starting with
v=spf1make SPF fail. Add new senders to the existing record. - Ten DNS lookups at most. Each
include:,a,mxorexistsin the record costs at least one lookup, and most added senders useinclude:. Going over the limit set in RFC 7208 breaks SPF for every message. - Allow up to 48 hours. Google says SPF can take that long to start working.
If you also send through a separate cold email tool's own servers, add its include: to the same record. If the tool sends through your Google mailboxes, the Google record alone is enough. Our cold email SPF record guide covers every mechanism, the 10-lookup limit and the common errors.
How do you set up DKIM for a cold email domain?
Set up DKIM by generating a key in Google Workspace and publishing it as a TXT record. Google then signs every email from that domain.
- In the Google Admin console, go to Apps, then Google Workspace, then Gmail, then Authenticate email.
- Pick the sending domain and click Generate new record.
- Choose a 2048-bit key if your DNS host supports it, and keep the default selector, google.
- Copy the TXT record value and add it to your DNS with the host
google._domainkey. - Back in the Admin console, click Start authentication.
Google's DKIM setup guide notes it can take up to 48 hours to start working. Do the same for every sending domain; DKIM is set per domain, not per account. For how signing works, what a selector is and how to read a DKIM-Signature header, see what DKIM is.
How do you set up a DMARC record for a cold email domain?
Set up DMARC by adding one TXT record at _dmarc on the domain, once SPF and DKIM have been working for 48 hours. Google recommends that wait in its DMARC setup guide.
A good starting DMARC record for a cold email domain is:
v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com
Add it as a TXT record with the host _dmarc. Each part has one job:
| Tag | Meaning | Value for a new cold email domain |
|---|---|---|
v | DMARC version, required and listed first | DMARC1 |
p | What to do with mail that fails | none to start |
rua | Where daily summary reports go | A mailbox or group you read |
pct | Share of failing mail the policy applies to | Removed from the current standard; leave it out |
adkim, aspf | How strictly the domains must match | Optional; the default relaxed setting is fine |
Pipefire publishes this kind of record automatically on every sending domain it sets up, with p=none and a reports address. Our guide to reading DMARC reports shows what those reports contain and what to look for, and our cold email DMARC policy guide covers when to move from none to quarantine and reject. Our setup page shows what else it configures and checks before a mailbox can send.
For the DMARC tags and alignment in depth, see what is DMARC.
Three related records sit on top of these: BIMI for inbox logos, MTA-STS for inbound TLS, and the PTR record that maps an IP back to a name.
Which DMARC policy should a cold email domain use?
A cold email domain should start on p=none and move to p=quarantine once reports show all its mail passing. There is little reason to rush to p=reject on a sending domain.
| Policy | What receivers do with failing mail | When to use it |
|---|---|---|
p=none | Deliver it and send you a report | A new domain, while you confirm everything passes |
p=quarantine | Treat it as suspicious, usually spam | Once reports show only your own mail, all passing |
p=reject | Refuse it | Your main business domain, after a careful rollout |
The policy only affects mail that fails. Your own correctly signed cold emails pass whatever the policy says. A stricter policy protects the domain from people faking it, which matters more for your main domain than for a sending domain.
How do you check SPF, DKIM and DMARC are working on a cold email domain?
Check by sending a test email to a Gmail account you own and reading the authentication results. All three should say "PASS".
- Send an email from the sending mailbox to a Gmail address you control.
- Open it, click the three-dot menu and choose Show original.
- Look at the SPF, DKIM and DMARC lines at the top. Each should show "PASS" and your sending domain.
If one fails, check the DNS record for typos, a second SPF record, or a missing include:. A free online DNS lookup tool will show exactly what the domain publishes. Remember that new records can take up to 48 hours to work.
Check again whenever you change DNS on the domain. A broken SPF record is one of the common reasons cold emails suddenly go to spam.
Common SPF, DKIM and DMARC mistakes in cold email
Most authentication problems on cold email domains come from five mistakes. All of them are easy to fix once spotted.
- Two SPF records. Adding a new tool by creating a second record instead of editing the first.
- Too many SPF includes. Stacking tools until SPF passes ten lookups.
- DKIM generated but never turned on. The record is published, but Start authentication was never clicked.
- DMARC added on day one. Before SPF and DKIM are working, so early mail fails DMARC.
- Setting up only the first domain. Every sending domain needs its own three records.
When you run several sending domains, check each one before its mailboxes start warm-up. Our guide to cold email domains covers the full setup order, from buying the domain to the first send. If a check shows dmarc=fail, our guide to fixing DMARC fail walks through each cause.
SPF, DKIM and DMARC for cold email FAQ
Do cold email domains need DMARC?
Yes. Gmail and Yahoo require DMARC for high-volume senders, and a sending domain without it looks less trustworthy. A p=none record is enough to start.
Does DMARC require DKIM for cold email?
No. DMARC passes if either SPF or DKIM passes and matches the "From" domain. Set up both anyway, because DKIM survives forwarding and SPF does not.
What is a DKIM selector in cold email setup?
The selector is the name that tells receivers where to find your DKIM key. Google Workspace uses google by default, so the record lives at google._domainkey.yourdomain.com.
Should a cold email domain use p=reject?
Not at first. Start with p=none, then move to p=quarantine once reports show everything passing. p=reject mainly protects against spoofing, which matters most on your main business domain.
How long do SPF, DKIM and DMARC take to work for a cold email domain?
Up to 48 hours each, according to Google. Allow two days after SPF and DKIM before adding DMARC, and start warm-up only after all three pass.