SPF, DKIM and DMARC: the three records that decide whether your cold email arrives

Gmail and Yahoo stopped throttling unauthenticated bulk mail and started rejecting it. Here is what each record does, how to set all three up, and how to prove they work before you send anything.

Most cold email advice starts with subject lines. It should start with DNS, because since February 2024 Gmail and Yahoo have required bulk senders to authenticate. And unauthenticated mail is now rejected outright rather than quietly filtered. A perfect sequence sent from an unauthenticated domain does not land in spam. It does not land at all.

The three records, in plain terms

SPF says which servers are allowed to send mail for your domain. DKIM signs each message cryptographically so the receiver can prove it was not altered in transit. DMARC tells the receiver what to do when one of the first two fails, and asks it to send you reports.

You need all three. SPF alone breaks the moment your mail is forwarded. DKIM alone leaves the receiver guessing about failures. DMARC without the other two has nothing to enforce.

Setting them up

These are DNS records at your registrar. For a domain on Google Workspace, SPF is a single TXT record on the root:

v=spf1 include:_spf.google.com ~all

DKIM is generated inside your mail provider, in Google Workspace it is under Apps, Google Workspace, Gmail, Authenticate email. It gives you a long TXT record with a selector name. This is the step people most often half-finish: adding the DNS record does nothing on its own. You have to return to the admin console and click Start authentication, or your mail continues to go out unsigned.

DMARC is a TXT record at the _dmarc subdomain. Start here:

v=DMARC1; p=none; rua=mailto:you@yourdomain.com

p=none means monitor and report, enforce nothing. That is the correct starting position, because a stricter policy applied before you know which of your legitimate senders are failing will silently destroy real mail. Watch the reports for two weeks, fix whatever is failing, then move to p=quarantine.

One DKIM record, not two

If two DKIM records exist at the same selector, verification fails. The receiver cannot tell which key is authoritative, so it stops rather than guessing. This happens most often when a record is added by hand and then again by an automated setup flow. Check for duplicates before you debug anything else.

Proving it works

Do not trust the green ticks in your provider's dashboard. They tell you a record exists, not that mail is being signed with it. Send a message to a Gmail address, open it, and choose Show original from the three-dot menu. You want three lines:

  • SPF: PASS
  • DKIM: PASS
  • DMARC: PASS

Anything less than three passes is a domain that is not ready to send. This check takes thirty seconds and is the only one that tests the thing you actually care about.

Keep cold email off your real domain

Authenticate your primary domain because your invoices and your replies depend on it. Then do not send cold email from it. Use separate domains for outbound, and a subdomain for automated transactional mail. Reputation is earned and lost per domain, and the failure you are insuring against is the one where a bad outbound week means your customers stop receiving your invoices.

BriefWork checks all three records before it will send anything, and refuses the send rather than proceeding on a domain that would be rejected. That check is not a courtesy. An unlawful or undeliverable send costs a domain that took weeks to warm.

SPF, DKIM and DMARC: the three records that decide whether your cold email arrives, BriefWork