SPF, DKIM and DMARC, without the jargon
The short answer
SPF, DKIM and DMARC are three DNS records that prove your email is really from you. Without them, mailbox providers treat you as suspicious and cold email lands in spam. They are a one-time setup and completely non-negotiable: no authentication, no inbox, no matter how good the email is.
On this page
- What authentication proves
- SPF: who is allowed to send
- DKIM: proof it was not tampered with
- DMARC: what to do if checks fail
- This is non-negotiable for cold email
- How to check yours
- Setting up SPF, DKIM and DMARC, step by step
- Common authentication mistakes
- If you are thinking you can skip DMARC
- Authentication and the cold email stack in Europe
- What authentication does not do
Authentication is the least glamorous part of outbound and one of the most decisive. Get it wrong and nothing else you do about deliverability matters, because you never reach the inbox to begin with.

What authentication proves
Email was built without a way to verify the sender, so anyone could claim to be anyone. Authentication is the retrofit that fixes this: a set of DNS records that let a receiving server check that mail claiming to be from your domain actually is.
Mailbox providers now expect it. Unauthenticated mail looks like the forgeries authentication was invented to stop, so it gets filtered or rejected on sight.
SPF: who is allowed to send
SPF (Sender Policy Framework) is a DNS record listing which servers are allowed to send email for your domain. When mail arrives, the receiver checks the sending server against that list. If it is not on the list, the mail looks unauthorised.
DKIM: proof it was not tampered with
DKIM (DomainKeys Identified Mail) adds a cryptographic signature to each message. The receiver uses a public key in your DNS to verify the signature, which proves the mail really came from your domain and was not altered in transit.
DMARC: what to do if checks fail
DMARC (Domain-based Message Authentication) ties the two together and tells receivers what to do when a message fails SPF or DKIM: nothing, quarantine, or reject. It also sends you reports on who is sending as your domain.
Without DMARC, SPF and DKIM have no enforcement policy behind them. With it, you control what happens to mail that fails the checks.
This is non-negotiable for cold email
For cold outreach, where you have no prior relationship to lean on, authentication is the price of entry. Missing or broken records are one of the most common reasons good cold email lands in spam, and it is entirely preventable with a one-time setup.
How to check yours
Free tools let you look up a domain and see whether SPF, DKIM and DMARC are present and valid. Check every sending domain before a campaign, and again if deliverability drops. Authentication is table stakes; once it is right, the rest of deliverability, reputation and relevance, is where the ongoing work lives, covered alongside sender reputation.
Setting up SPF, DKIM and DMARC, step by step
- List every tool that sends as your domain. Your mail provider, your sequencer, your CRM, your invoicing tool. Anything not on the list will fail the checks later.
- Publish one SPF record that includes every legitimate sender. One record, not several: a second SPF record invalidates both.
- Enable DKIM in each sending tool and add the keys it gives you to your DNS. Each platform signs with its own key, so this step repeats per tool.
- Publish DMARC in monitoring mode first, with a none policy and a reporting address. This changes nothing about delivery yet; it starts the reports flowing.
- Read the reports for two to four weeks. They show every source sending as your domain, including tools you forgot and forgers you did not know about.
- Tighten the policy to quarantine, then reject, once the reports show only legitimate mail passing. Verify the whole chain with a lookup tool before the first campaign.
Common authentication mistakes
- Two SPF records on one domain. A common leftover from switching providers, and it fails validation entirely. Merge them into one.
- Too many DNS lookups in SPF. The standard allows ten; every include statement spends some. Past the limit, SPF silently breaks. Flatten or prune the record.
- DKIM enabled on the main tool only. The mail provider signs, but the sequencer or CRM sends unsigned. Every sender needs its own key.
- DMARC left on none forever. Monitoring mode proves nothing to receivers. A domain that never tightens its policy gets less trust than one that enforces.
- Records set once and never rechecked. A provider migration or a colleague's DNS edit can break authentication months later. Recheck after any DNS change and on a regular schedule.
If you are thinking you can skip DMARC
The era when SPF and DKIM alone were enough is over. Since the major mailbox providers tightened their bulk sender rules in 2024, senders of any meaningful volume are expected to have all three records in place, and cold senders are exactly the category the rules were aimed at. A missing DMARC record does not just cost you a few points of trust; at Gmail and Yahoo scale it can mean outright rejection. The setup is a one-off job, not an ongoing burden. The alternative is explaining to your team why an entire campaign went to spam.
Authentication and the cold email stack in Europe
For European cold senders the standard setup goes one step further: authenticate a separate sending domain, not your main company domain, so outreach reputation never touches the domain your invoices and support mail depend on. Each sending domain gets its own SPF, DKIM and DMARC, then a proper warm-up period before real volume. We run campaigns for clients across the DACH, Baltic and wider European markets, and authentication problems remain among the most common faults we find when auditing a domain that "suddenly stopped working". The pattern is always the same: records were set up once, something changed, nobody was watching. Ongoing deliverability monitoring catches this in days instead of months.
What authentication does not do
Valid records get you considered, not delivered. They prove identity, and identity is only the first filter. Content, volume, list quality and recipient engagement decide the rest. A perfectly authenticated domain sending unwanted mail to a stale list will still end up in spam, just with a verified signature on it. Treat SPF, DKIM and DMARC as the foundation under the deliverability work, not a substitute for it.
Frequently asked
What are SPF, DKIM and DMARC?
Do I need email authentication for cold email?
How do I check if my email authentication is set up correctly?
Rather not build this yourself?
We run the targeting, data, copy and follow-up as a done-for-you service, and send the interested replies straight to your inbox. You bring the close.
Book a strategy call