Deliverability

SPF, DKIM and DMARC, without the jargon

Published 1 September 2026 · 6 min read · By Ripe Leads

The short answer

SPF, DKIM and DMARC are three DNS records that prove your email is really from you. Without them, mailbox providers treat you as suspicious and cold email lands in spam. They are a one-time setup and completely non-negotiable: no authentication, no inbox, no matter how good the email is.

On this page
  1. What authentication proves
  2. SPF: who is allowed to send
  3. DKIM: proof it was not tampered with
  4. DMARC: what to do if checks fail
  5. This is non-negotiable for cold email
  6. How to check yours
  7. Setting up SPF, DKIM and DMARC, step by step
  8. Common authentication mistakes
  9. If you are thinking you can skip DMARC
  10. Authentication and the cold email stack in Europe
  11. What authentication does not do

Authentication is the least glamorous part of outbound and one of the most decisive. Get it wrong and nothing else you do about deliverability matters, because you never reach the inbox to begin with.

What authentication proves

Email was built without a way to verify the sender, so anyone could claim to be anyone. Authentication is the retrofit that fixes this: a set of DNS records that let a receiving server check that mail claiming to be from your domain actually is.

Mailbox providers now expect it. Unauthenticated mail looks like the forgeries authentication was invented to stop, so it gets filtered or rejected on sight.

SPF: who is allowed to send

SPF (Sender Policy Framework) is a DNS record listing which servers are allowed to send email for your domain. When mail arrives, the receiver checks the sending server against that list. If it is not on the list, the mail looks unauthorised.

DKIM: proof it was not tampered with

DKIM (DomainKeys Identified Mail) adds a cryptographic signature to each message. The receiver uses a public key in your DNS to verify the signature, which proves the mail really came from your domain and was not altered in transit.

DMARC: what to do if checks fail

DMARC (Domain-based Message Authentication) ties the two together and tells receivers what to do when a message fails SPF or DKIM: nothing, quarantine, or reject. It also sends you reports on who is sending as your domain.

Without DMARC, SPF and DKIM have no enforcement policy behind them. With it, you control what happens to mail that fails the checks.

This is non-negotiable for cold email

For cold outreach, where you have no prior relationship to lean on, authentication is the price of entry. Missing or broken records are one of the most common reasons good cold email lands in spam, and it is entirely preventable with a one-time setup.

3Three records, set up once. SPF, DKIM and DMARC are the price of entry to the inbox for any cold sender.

How to check yours

Free tools let you look up a domain and see whether SPF, DKIM and DMARC are present and valid. Check every sending domain before a campaign, and again if deliverability drops. Authentication is table stakes; once it is right, the rest of deliverability, reputation and relevance, is where the ongoing work lives, covered alongside sender reputation.

Setting up SPF, DKIM and DMARC, step by step

  1. List every tool that sends as your domain. Your mail provider, your sequencer, your CRM, your invoicing tool. Anything not on the list will fail the checks later.
  2. Publish one SPF record that includes every legitimate sender. One record, not several: a second SPF record invalidates both.
  3. Enable DKIM in each sending tool and add the keys it gives you to your DNS. Each platform signs with its own key, so this step repeats per tool.
  4. Publish DMARC in monitoring mode first, with a none policy and a reporting address. This changes nothing about delivery yet; it starts the reports flowing.
  5. Read the reports for two to four weeks. They show every source sending as your domain, including tools you forgot and forgers you did not know about.
  6. Tighten the policy to quarantine, then reject, once the reports show only legitimate mail passing. Verify the whole chain with a lookup tool before the first campaign.

Common authentication mistakes

If you are thinking you can skip DMARC

The era when SPF and DKIM alone were enough is over. Since the major mailbox providers tightened their bulk sender rules in 2024, senders of any meaningful volume are expected to have all three records in place, and cold senders are exactly the category the rules were aimed at. A missing DMARC record does not just cost you a few points of trust; at Gmail and Yahoo scale it can mean outright rejection. The setup is a one-off job, not an ongoing burden. The alternative is explaining to your team why an entire campaign went to spam.

Authentication and the cold email stack in Europe

For European cold senders the standard setup goes one step further: authenticate a separate sending domain, not your main company domain, so outreach reputation never touches the domain your invoices and support mail depend on. Each sending domain gets its own SPF, DKIM and DMARC, then a proper warm-up period before real volume. We run campaigns for clients across the DACH, Baltic and wider European markets, and authentication problems remain among the most common faults we find when auditing a domain that "suddenly stopped working". The pattern is always the same: records were set up once, something changed, nobody was watching. Ongoing deliverability monitoring catches this in days instead of months.

What authentication does not do

Valid records get you considered, not delivered. They prove identity, and identity is only the first filter. Content, volume, list quality and recipient engagement decide the rest. A perfectly authenticated domain sending unwanted mail to a stale list will still end up in spam, just with a verified signature on it. Treat SPF, DKIM and DMARC as the foundation under the deliverability work, not a substitute for it.

Frequently asked

What are SPF, DKIM and DMARC?
They are three DNS records that authenticate your email. SPF lists which servers may send for your domain, DKIM adds a cryptographic signature proving the message really came from you and was not altered, and DMARC ties them together and tells receivers what to do when a message fails the checks. Together they prove your mail is genuinely from you.
Do I need email authentication for cold email?
Absolutely. For cold outreach you have no prior relationship to rely on, so mailbox providers lean heavily on authentication to decide whether to trust you. Missing or broken SPF, DKIM or DMARC is one of the most common reasons good cold email lands in spam. It is a one-time setup and completely non-negotiable: no authentication, no inbox.
How do I check if my email authentication is set up correctly?
Use a free authentication lookup tool to check a domain for valid SPF, DKIM and DMARC records. Do this for every sending domain before you run a campaign, and again if deliverability drops. Once authentication is correct, the ongoing deliverability work shifts to sender reputation and sending relevant mail people actually want.

Rather not build this yourself?

We run the targeting, data, copy and follow-up as a done-for-you service, and send the interested replies straight to your inbox. You bring the close.

Book a strategy call