Menu

What is DMARC? How it works for cold email, with record tags and examples

Rather not build this yourself? Pipefire runs your cold email end to end.See how it works →

DMARC stands for Domain-based Message Authentication, Reporting and Conformance, and it is the DNS record that tells Gmail, Outlook and Yahoo what to do with mail claiming to be from your domain that fails authentication. It reads the results of SPF and DKIM, checks whether either one lines up with your visible "From" address, and applies the policy you chose to anything that does not.

This page explains what DMARC is, how alignment works, the tags inside a DMARC record, and why Gmail and Yahoo require it from bulk senders. It builds on our SPF, DKIM and DMARC setup guide, which covers the exact click-path for adding all three records; this page goes deeper on what DMARC itself does and does not check.

What does DMARC mean for cold email authentication?

DMARC means a domain can publish one record that tells receiving mail servers what to do with messages that fail its authentication checks, instead of leaving every receiver to guess. The original specification is RFC 7489, published in March 2015 by an industry group that included Google, Microsoft, PayPal and Yahoo among its contributors.

DMARC itself runs no authentication. It is a policy layer sitting on top of SPF and DKIM, reading whether either one passed and whether the passing domain matches the one shown in the message's "From" address. That second check, called alignment, is the part that makes DMARC more than just "SPF or DKIM, but stricter."

For a new cold email sending domain, DMARC is the last of the three records to add, after SPF and DKIM are already working. Our SPF, DKIM and DMARC guide covers the order and timing for all three.

How does DMARC alignment work for a cold email domain?

DMARC alignment is the check that compares the domain SPF or DKIM actually verified against the domain shown in a message's visible "From" address, and it passes a message only when at least one of them matches. A message can pass SPF and DKIM individually and still fail DMARC if neither one was checked against the From domain.

Alignment comes in two strictness levels, set by the adkim and aspf tags:

Alignment modeWhat it requiresExample
Relaxed (the default)The organizational domain matches; a subdomain is finemail.examplecold.com aligns with examplecold.com
StrictThe exact domain must match, including subdomainmail.examplecold.com does not align with examplecold.com under strict mode

The example below is invented, using a fictional domain, to show how relaxed alignment passes where strict alignment would fail:

From: sales@examplecold.com
DKIM d= tag: d=mail.examplecold.com

Under relaxed alignment, this passes DKIM alignment because mail.examplecold.com and examplecold.com share the same organizational domain. Under strict alignment, it fails, because the subdomain in the DKIM signature does not exactly match the From domain. Most cold email setups should stay on relaxed alignment, the default, unless a specific reason calls for tightening it.

What are the DMARC record tags for a cold email domain?

A DMARC record is a single TXT record published at _dmarc.yourdomain.com, written as semicolon-separated tag-value pairs. Nine tags cover almost everything a cold email domain needs to know:

TagMeaningTypical value for cold email
vRecord version, required and listed firstDMARC1
pPolicy for mail that fails: none, quarantine or rejectnone on a new domain
spPolicy applied to subdomains, when different from pLeft out unless subdomains send separately
ruaMailbox that receives the daily aggregate reportA mailbox or group you actually read
rufMailbox that receives per-message failure reportsUsually left out; most domains run on rua alone
pctShare of failing mail the policy applies toNot part of the current standard; leave it out
adkimDKIM alignment strictness, relaxed or strictRelaxed (the default)
aspfSPF alignment strictness, relaxed or strictRelaxed (the default)
foForensic options controlling when failure reports are sent1, to get a report on any failure, if ruf is set

A minimal record for a brand-new sending domain looks like v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com. The pct tag deserves a note: it was part of the original 2015 specification. A cold email domain starting out today does not need it, since the default behavior without it already applies the policy to all failing mail.

What is a DMARC policy, and which value should a cold email domain use?

A DMARC policy is the p tag's value, and it only ever affects mail that already failed the alignment check: your own correctly signed cold email passes regardless of which policy you choose.

PolicyWhat receivers do with failing mailTypical use on a cold email domain
p=noneDeliver it as normal, and send a reportEvery new sending domain, from day one
p=quarantineTreat it as suspicious, usually routing it to spamOnce reports show only your own mail, all passing
p=rejectRefuse the message outrightRarely needed on a domain used only for cold outreach

A cold email domain should start on p=none, read its reports, and move to p=quarantine only once those reports show every message passing cleanly. Our DMARC policy guide covers the full rollout path and when, if ever, to consider p=reject. Our guide to reading DMARC reports covers what the daily aggregate report actually contains and how to tell a clean domain from one still needing fixes.

Once DMARC is enforced you can add a logo with BIMI.

DMARC vs SPF vs DKIM: what does each one actually check for cold email?

DMARC, SPF and DKIM check three different things, and DMARC is the only one of the three that decides what happens to mail that fails.

RecordWhat it checksWhat it cannot do alone
SPFWhich mail servers are allowed to send for the domainDoes not survive most forwarding, and does not check the From address itself
DKIMWhether a message was signed with the domain's private key and unaltered in transitSays nothing about whether the signing domain matches the visible From address
DMARCWhether SPF or DKIM passed in alignment with the From domain, and what to do if neither didDoes nothing without working SPF or DKIM underneath it

DMARC passes a message when either SPF or DKIM passes and aligns with the From domain; it does not require both. For the deeper mechanics of each underlying check, see our guide to SPF, DKIM and DMARC setup and our dedicated page on what DKIM is. Our guide to why cold emails fail DMARC covers what happens when SPF and DKIM each look fine on their own.

Why do Gmail and Yahoo require DMARC for cold email senders?

Gmail and Yahoo both require a published DMARC record from bulk senders because it is the only one of the three checks that tells them what to do with mail that fails. Both providers tie that requirement to sending volume rather than sender type.

Google's email sender guidelines set two tiers. Every sender to Gmail accounts needs SPF or DKIM at minimum. Senders of more than 5,000 messages a day to Gmail accounts must additionally have:

  1. SPF and DKIM, plus a DMARC record, where the policy is allowed to be p=none.
  2. An aligned From address, so the authenticated domain matches what the recipient sees.
  3. A spam rate under 0.3% as reported in Postmaster Tools.
  4. One-click unsubscribe on marketing and bulk mail.

Yahoo's sender best practices set close to the same bar for bulk senders. SPF and DKIM must both be implemented, and a DMARC policy of at least p=none must be published and passing, with a working rua address strongly recommended so results can be monitored from the start. Yahoo also caps spam complaint rates at 0.3% for bulk senders, matching Google's threshold.

Most cold email sending stays under the 5,000-a-day Gmail threshold per domain, especially once volume is spread across several sending domains during warm-up. Publish full authentication anyway: both providers' guidelines treat a fully authenticated sender as more trustworthy than one meeting only the bare minimum, and a brand-new domain needs every trust signal it can get.

How do you check whether a cold email domain's DMARC record is set up correctly?

Check a DMARC record by looking it up directly and confirming the tags match what you intended to publish, then sending a test message to confirm it actually passes.

  1. Look up the TXT record at _dmarc.yourdomain.com using our free DMARC checker, which reads the published record and flags missing or malformed tags.
  2. Confirm the p, rua and alignment tags match what you meant to publish; a typo in the host name is the most common reason a lookup finds nothing at all.
  3. Send a test email to a Gmail account you control, open it, and check the Authentication-Results header for a DMARC pass.
  4. If you have not published a record yet, our free DMARC record generator builds a correctly formatted TXT record from your domain, policy and reporting address.

We write and publish SPF, DKIM and DMARC for every sending domain as part of getting a domain ready to send, so a domain built through Pipefire has all three records in place before its mailboxes start warming up.

What is DMARC for cold email FAQ

What does DMARC stand for in cold email?

Domain-based Message Authentication, Reporting and Conformance. It is a DNS TXT record that tells receiving mail servers what to do with messages claiming to be from your domain that fail SPF or DKIM in alignment with your visible From address.

What is the difference between DMARC and DKIM for cold email?

DKIM is a cryptographic signature that proves a message was sent by someone holding your domain's private key and was not altered in transit. DMARC reads the result of DKIM, and of SPF, then checks whether the passing domain aligns with your From address before deciding what happens to mail that fails. Our guide to DKIM covers the signing mechanics in full.

What is a DMARC record on a cold email domain, in simple terms?

It is one TXT record published at _dmarc.yourdomain.com that combines a policy for failing mail, a reporting address, and optional alignment settings into a single line starting with v=DMARC1.

Does a cold email domain need a strict DMARC policy like p=reject?

No. Most cold email sending domains should stay on p=none while warming up, then move to p=quarantine once reports confirm every message is passing. p=reject mainly protects a brand's main business domain against impersonation, which matters less for a domain used only for sending.

What is DMARC used for beyond cold email?

DMARC protects any domain against impersonation in phishing and spoofing attempts, which is why it matters for a company's main business domain as much as for a cold email sending domain. The policy and reporting mechanism are the same in both cases; only the recommended policy value differs.