SPF, DKIM, DMARC Setup Guide for Cold Emailers: A Non-Technical Walkthrough

workerslab ·

You just bought three fresh domains for cold outreach. You’ve got Google Workspace set up, Instantly connected, and a prospect list ready to load. But before you send a single email, there are three DNS records standing between you and the inbox. Get them wrong and Gmail won’t just spam-folder your messages. It’ll reject them outright.

Since November 2025, Gmail rejects non-compliant emails with permanent 550 errors. No second chances. No “try again later.” Your email bounces, your domain takes the hit, and your warmup progress resets.

This guide walks you through SPF, DKIM, and DMARC in plain English. No developer required. If you want the technical deep-dive with terminal commands and DNS lookups, read the SPF, DKIM, DMARC alignment developer guide. This one’s for SDRs and sales ops who just need it done.

What These Three Records Actually Do

Think of your domain like a building. SPF is the guest list at the front door. DKIM is a wax seal on every letter you send. DMARC is the policy that says what to do when someone shows up without an invitation or breaks the seal.

SPF tells email providers which services are allowed to send from your domain. When Gmail receives an email claiming to be from yourdomain.com, it checks your SPF record to see if the sending server had permission. If the server isn’t on the list, the email fails.

DKIM adds a digital signature to every outgoing email. The receiving server checks that signature against a public key you’ve published in DNS. If the signature checks out, the email hasn’t been tampered with and it really came from your domain.

DMARC ties SPF and DKIM together with a policy. It tells Gmail, Yahoo, and Microsoft what to do when an email fails authentication: ignore it, quarantine it, or reject it. DMARC also sends you reports so you can see who’s sending email as your domain.

You need all three. Not two out of three. All three.

Step 1: Set Up SPF

SPF is a single line of text you add to your domain’s DNS settings. Here’s what it looks like for a typical cold outreach setup with Google Workspace:

v=spf1 include:_spf.google.com ~all

That line says: “Google Workspace is authorized to send email from this domain. Soft-fail everything else.”

Here’s an important detail that trips people up. Tools like Instantly, Lemlist, and Smartlead don’t send emails from their own servers. They connect to your email provider (Google Workspace, Microsoft 365) via SMTP and route emails through those servers. That means your SPF record only needs to authorize your email provider, not the cold email platform itself.

Here’s how to add it.

Log into your domain registrar (GoDaddy, Namecheap, Cloudflare, wherever you bought the domain). Find the DNS settings page. Look for a button that says “Add Record” or “New Record.” Choose TXT as the record type. In the “Host” or “Name” field, enter @ (that means the root domain). In the “Value” field, paste your SPF record. Save it.

What goes in your SPF record depends on which services actually deliver email from your domain. Here are the common includes for cold outreach:

  • Google Workspace: include:_spf.google.com
  • Microsoft 365: include:spf.protection.outlook.com
  • SendGrid: include:sendgrid.net
  • Mailgun: include:mailgun.org

Cold email platforms like Instantly, Lemlist, and Smartlead send through your connected email provider, so they don’t need their own SPF include. If you use a dedicated SMTP service like SendGrid or Mailgun for sending, add that service’s include instead.

Only add the services that actually deliver email from your domain. Every include: counts toward a hard limit of 10 DNS lookups. Go over 10 and your entire SPF record breaks. Most cold outreach setups use 1-2 includes, so you’re fine. But if you’re running multiple email providers or dedicated SMTP services, count carefully.

One domain, one SPF record. Don’t create multiple TXT records for SPF. If you have two, receiving servers won’t know which to trust and both fail. Combine everything into a single line.

Step 2: Set Up DKIM

DKIM is slightly different from SPF because you don’t write the record yourself. Your sending platform generates it, and you copy the record into your DNS.

Google Workspace DKIM

Open your Google Admin console (admin.google.com). Go to Apps, then Google Workspace, then Gmail. Click “Authenticate email.” Select your domain. Google shows you a TXT record value and tells you to add it at a specific hostname (usually google._domainkey.yourdomain.com).

Go back to your DNS provider. Add a new TXT record. In the “Host” or “Name” field, enter google._domainkey (some providers want just the prefix, others want the full hostname). Paste the value Google gave you. Save it. Go back to Google Admin and click “Start Authentication.”

DNS changes can take up to 48 hours to spread across the internet. Usually it’s faster, maybe 15-30 minutes. But don’t panic if Google says “DNS record not found” right away. Give it time.

Instantly, Lemlist, and Smartlead DKIM

Here’s something that confuses a lot of people. Instantly, Lemlist, and Smartlead don’t send emails from their own servers. They route emails through your connected email provider (Google Workspace, Microsoft 365, etc.) via SMTP. That means your email provider’s DKIM key signs the outgoing messages, not the cold email platform.

If you’re using Google Workspace with Instantly, for example, your Google DKIM key covers those emails because Google’s servers are doing the actual sending. You don’t need a separate DKIM record for Instantly, Lemlist, or Smartlead.

However, if you use a dedicated SMTP service like SendGrid or Mailgun for sending, that service has its own DKIM key you’ll need to add to your DNS. Check your SMTP provider’s documentation for their specific DKIM setup instructions.

The key principle: DKIM records are needed for whichever servers actually deliver the email. Set up DKIM for your email provider. If you add a dedicated SMTP service, set up DKIM for that too.

Miss a DKIM record for a sending service and those emails fail DKIM. Fail DKIM without SPF alignment, and DMARC fails. DMARC fails and your email bounces. Every. Single. One.

Step 3: Set Up DMARC

DMARC is the policy layer. Here’s the record you’ll start with:

v=DMARC1; p=none; rua=mailto:[email protected]

That tells email providers: “If an email fails both SPF and DKIM alignment, don’t take action yet, but send me reports about authentication results.”

Add it as a TXT record in your DNS. The “Host” or “Name” field should be _dmarc (some providers want _dmarc.yourdomain.com, others just _dmarc). Paste the value. Save.

The DMARC Policy Progression

Gmail’s 2024 bulk sender guidelines require a DMARC record with a minimum policy of p=none. That satisfies compliance. But p=none only monitors. It doesn’t tell receiving servers to do anything with unauthenticated messages. Your domain gets zero protection against spoofing while in monitor mode.

Start with p=none so you can see what’s happening without accidentally blocking legitimate email. Check your DMARC reports for 2-4 weeks to confirm all your sending services pass authentication. Once everything looks clean, move to p=quarantine. That tells receivers to send unauthenticated messages to spam. After you’re confident in your setup, move to p=reject. That’s the strongest policy. Unauthenticated emails get bounced outright.

The progression: p=none (start here for monitoring) then p=quarantine (after confirming everything passes) then p=reject (strongest protection).

DMARC Reports

That rua=mailto: address receives XML reports from email providers. They’re not human-readable. Use a free tool like DMARC Analyzer, Postmark’s DMARC tool, or EasyDMARC to parse them into dashboards you can actually understand.

Check these reports weekly for the first month. They’ll show you every service sending as your domain, whether each one passes or fails SPF and DKIM, and what percentage of your email is authenticated. If you see a legitimate service failing, you missed a DNS record somewhere.

Understanding DMARC Alignment

Most non-technical setups break down right here. Worth a quick explanation.

DMARC doesn’t just check if SPF and DKIM pass. It checks if they align with your From address. Your From address says [email protected]. SPF passes for yourdomain.com. That aligns. But if SPF passes for sendingservice.com instead? SPF passed, but alignment failed. DMARC still fails.

There are two alignment modes: relaxed and strict.

Relaxed alignment (the default) matches on the root domain. So mail.yourdomain.com aligns with yourdomain.com. Good enough for almost everyone.

Strict alignment requires an exact domain match. You won’t need this unless you have a specific security requirement. Stick with relaxed.

The practical takeaway: make sure authentication is tied to your domain, not some other domain. When tools like Instantly and Lemlist send through your Google Workspace account, Google signs emails with your domain’s DKIM key and your domain appears in the SPF check. That’s alignment. But if you add a dedicated SMTP service without configuring its DKIM for your domain, authentication might pass under the SMTP service’s domain instead of yours. SPF or DKIM passed, but alignment failed, and DMARC still fails.

The Five Mistakes That Break Cold Email Authentication

After helping dozens of outreach teams fix their DNS, these are the patterns that come up again and again.

  1. Forgetting DKIM for your email provider. You connected Google Workspace but never set up DKIM in the Admin console. Every email sent through Google, including cold emails from Instantly or Lemlist, fails DKIM authentication. If you add a dedicated SMTP service later, it needs its own DKIM record too.

  2. SPF record over 10 lookups. Each include: triggers DNS lookups. Hit 11 and your entire SPF record breaks. Not just the 11th service. Everything. Count your includes and keep it tight.

  3. Multiple SPF records. Two separate TXT records starting with v=spf1 on the same domain. Receiving servers see both, get confused, fail both. Combine them into one record.

  4. DMARC stuck at p=none forever. You set it for monitoring and forgot it. While p=none satisfies Gmail’s minimum requirement, your domain gets zero protection against spoofing. Move to p=quarantine after confirming your sending services pass authentication, then to p=reject for full protection.

  5. DNS records on the wrong domain. You’re sending cold email from outreach-acme.com but you added the DNS records to acme.com. Every sending domain needs its own complete set of SPF, DKIM, and DMARC records. No exceptions.

How to Verify Everything Works

Don’t just set the records and hope. Verify.

Send a test email from each sending platform to a Gmail address. Open the email in Gmail, click the three dots in the top right, and select “Show original.” You’ll see a panel with authentication results at the top.

You’re looking for three green “PASS” results: SPF, DKIM, and DMARC. If any show “FAIL,” trace it back. Which service sent the email? Does that service have the right DNS records? Did the records propagate?

For ongoing monitoring, set up Google Postmaster Tools. It’s free, it shows your domain reputation, and it flags authentication failures before they become deliverability problems.

Do this for every sending domain you own. Three domains? Three sets of test emails. Five domains? Five sets. Sound tedious? It takes 15 minutes and saves you from burning a domain you spent weeks warming up.

Putting It All Together

Here’s the full checklist for each cold email domain:

  1. Add one SPF TXT record with includes for your email provider (Google Workspace, Microsoft 365) and any dedicated SMTP services
  2. Add DKIM TXT records for Google Workspace (or Microsoft 365)
  3. Add DKIM TXT records for any dedicated SMTP services (SendGrid, Mailgun, etc.)
  4. Add DMARC TXT record at _dmarc starting with p=none, then move to p=quarantine and p=reject
  5. Wait 30-60 minutes for DNS propagation
  6. Send test emails from each platform to Gmail
  7. Check “Show original” for SPF, DKIM, and DMARC pass
  8. Set up DMARC report monitoring

That’s it. No terminal commands. No code. Just DNS records and verification.

Authentication is the foundation. But it’s only the first layer. Your cold email deliverability playbook also needs proper warmup, list validation, and domain rotation to keep you in the inbox long-term. Want to understand how warmup and validation work together? Read email warmup vs validation for the full breakdown.

Get your DNS right. Then get your lists clean. That’s how cold email still works in 2026.