SPF, DKIM and DMARC, without the jargon
The short answer
SPF, DKIM and DMARC are three DNS records that prove your email is really from you. Without them, mailbox providers treat you as suspicious and cold email lands in spam. They are a one-time setup and completely non-negotiable: no authentication, no inbox, no matter how good the email is.
Authentication is the least glamorous part of outbound and one of the most decisive. Get it wrong and nothing else you do about deliverability matters, because you never reach the inbox to begin with.

What authentication proves
Email was built without a way to verify the sender, so anyone could claim to be anyone. Authentication is the retrofit that fixes this: a set of DNS records that let a receiving server check that mail claiming to be from your domain actually is.
Mailbox providers now expect it. Unauthenticated mail looks like the forgeries authentication was invented to stop, so it gets filtered or rejected on sight.
SPF: who is allowed to send
SPF (Sender Policy Framework) is a DNS record listing which servers are allowed to send email for your domain. When mail arrives, the receiver checks the sending server against that list. If it is not on the list, the mail looks unauthorised.
DKIM: proof it was not tampered with
DKIM (DomainKeys Identified Mail) adds a cryptographic signature to each message. The receiver uses a public key in your DNS to verify the signature, which proves the mail really came from your domain and was not altered in transit.
DMARC: what to do if checks fail
DMARC (Domain-based Message Authentication) ties the two together and tells receivers what to do when a message fails SPF or DKIM: nothing, quarantine, or reject. It also sends you reports on who is sending as your domain.
Without DMARC, SPF and DKIM have no enforcement policy behind them. With it, you control what happens to mail that fails the checks.
This is non-negotiable for cold email
For cold outreach, where you have no prior relationship to lean on, authentication is the price of entry. Missing or broken records are one of the most common reasons good cold email lands in spam, and it is entirely preventable with a one-time setup.
How to check yours
Free tools let you look up a domain and see whether SPF, DKIM and DMARC are present and valid. Check every sending domain before a campaign, and again if deliverability drops. Authentication is table stakes; once it is right, the rest of deliverability, reputation and relevance, is where the ongoing work lives, covered alongside sender reputation.
Frequently asked
What are SPF, DKIM and DMARC?
Do I need email authentication for cold email?
How do I check if my email authentication is set up correctly?
Rather not build this yourself?
We run the targeting, data, copy and follow-up as a done-for-you service, and send the interested replies straight to your inbox. You bring the close.
Book a strategy call