Authentication for Cold Email on Google Workspace
Introduction
Authentication is how receiving servers decide whether mail that claims to be from your domain was allowed to use that domain. On Google Workspace cold email setups, that usually means MX for receiving plus SPF, DKIM, and DMARC for sending policy. Skip or half finish any of them and you will fight spam folders with copy changes that never address the real defect. This page is the overview: what each piece does, how they fit together, and how to verify. For commands and record publishing steps, use the linked how to guides.
Step by step records: SPF DKIM DMARC Setup for Cold Email. Full domain checklist: SPF DKIM DMARC Setup for Cold Email. MX deep dive: MX Records on Dedicated Domains for Cold Email.
Why authentication comes before warmup and campaigns
Google's public sender guidelines, written for mail to personal Gmail accounts, require every sender to set up SPF or DKIM and keep the spam rate reported in Postmaster Tools below 0.3%. Senders of more than 5,000 messages a day to Gmail accounts must set up SPF, DKIM, and DMARC. Cold email is filtered by the same systems. Warmup on a domain that fails DKIM builds the wrong history. See Warmup Myths That Waste Cold Email Teams.
The four pieces (plain language)
MX: MX tells the world where to deliver mail for the domain. On Workspace outbound domains, MX should point at Google so replies and bounces land in your mailboxes. Google's MX help documents the current value (a single smtp.google.com record with priority 1 at the time of writing; confirm on Google's page). Older setups may still use the legacy aspmx records, which Google still supports. MX changes can take up to 72 hours to be recognized.
SPF: SPF is a DNS TXT policy listing which hosts may send for the domain. For Workspace, Google's SPF help describes including Google's sending hosts. Each domain needs its own SPF record, and only one; a second record breaks checks. Copy the exact string from Google's page when you publish. Google notes SPF can take up to 48 hours to start working.
DKIM: DKIM adds a cryptographic signature to messages. In Admin, you generate a key, publish the DNS TXT host Google shows, then start authentication. Google's DKIM help covers timing: new organizations may wait 24 to 72 hours before a key can be generated, and the Admin page can take up to 48 hours to show DKIM working. Publishing the record without clicking Start authentication is a common miss.
DMARC: DMARC tells receivers what to do when SPF or DKIM alignment fails, and where to send reports. Google's DMARC help recommends starting with a policy of none, waiting 48 hours after SPF or DKIM is set up before adding DMARC, and sending reports to a group or dedicated mailbox. Choose tags from Google's page and your own security needs.
How they work together
MX: Can this domain receive mail at Google?
SPF: Is this sending host allowed by DNS policy?
DKIM: Are this message's headers and body signed by a key the domain publishes?
DMARC: Do SPF/DKIM align with the visible From domain, and what should fail do?
Receivers combine these signals with complaint history and engagement. Authentication is necessary. It is not a placement guarantee.
Verification without guessing
- Send a test from the Workspace mailbox to a personal Gmail seed.
- Open Show original (More, Show original) and read SPF, DKIM, and DMARC results.
- Lookup MX, SPF, DKIM host, and DMARC in DNS for the dedicated domain (not only the primary brand domain).
- Fix failures before you raise campaign volume.
If Instantly or Smartlead shows the account connected but Show original fails, the sequencer connection is not proof of auth health.
Failure modes common on cold domains
Wrong domain edited. DNS changed on the apex while mailboxes live on a cousin domain.
Parking MX left in place. Registrar defaults still winning.
Two SPF records. One from Google setup, one from a marketing tool.
DKIM published, not started. TXT exists; Admin still idle.
DMARC on primary only. Outbound dedicated domains forgotten.
Shared SMTP with mismatched From domains. Alignment breaks even when Workspace siblings pass.
Tracking domain confusion. Sequencer tracking CNAMEs are not MX and not SPF. Configure them from Instantly or Smartlead docs; do not invent values here.
Authentication and the rest of outbound infrastructure
Auth sits beside density, isolation, and caps. Two or three mailboxes per domain and roughly 20 to 40 cold sends per warmed mailbox per day still matter after every check is green. See Google Workspace Outbound Infrastructure Explained. Agencies still need separated pools so one client's DMARC experiment does not collide with another. See Cold Email Inboxes for Agencies: Isolation First.
Order of operations (overview)
- Add and verify the dedicated domain in Google Workspace.
- Publish MX; remove stale MX (allow up to 72 hours).
- Publish SPF; keep a single record.
- Generate and publish DKIM; start authentication (new organizations may wait before a key is available).
- Add DMARC once SPF and DKIM are authenticating (Google suggests waiting 48 hours).
- Verify with Show original.
- Only then warm and connect to your sequencer using documented methods.
Exact record strings and Admin labels belong in Google's help and in SPF DKIM DMARC Setup for Cold Email. Recheck those links on publish day.
Auth health after you are already sending
Authentication is not a one time launch task. DNS hosts change plans. Someone adds a second SPF include for a new tool. A domain transfer drops TXT records. Build a recurring check:
Monthly Show original from one mailbox per domain.
Check the Authenticate email page in Admin for each domain and ticket anything not authenticating.
Revisit DMARC reports if you collect them; high failure rates deserve a ticket, not a shrug.
When replies drop, put auth in the first hour of the audit beside list and volume. See Deliverability Dropped After You Scaled: What Changed.
Workspace Admin versus DNS host
Keys are generated in Google Admin. Records live at your DNS host. Cold email teams get stuck when marketing owns DNS and ops owns Admin with no shared checklist. Name an owner for each domain zone and an owner for each Workspace organization. Offboarding should revoke both DNS access and Super Admin roles.
What authentication cannot do
It cannot make a bad list welcome.
It cannot raise a safe cold volume ceiling by itself.
It cannot replace primary domain isolation.
It cannot prevent every suspension; it reduces avoidable trust failures. See Google Workspace Suspended for Cold Email: Recovery Path.
Where ColdMail fits
ColdMail publishes SPF, DKIM, DMARC, and MX automatically when it provisions official Google Workspace mailboxes on dedicated domains. You keep an official admin panel per domain with 2FA so records stay visible. AI warmup is available as an optional add on after authentication is in place; see coldmail.app for current add on pricing. Mailboxes are ready to connect in Instantly and Smartlead using the methods those tools support. Automation removes copy paste errors; it does not remove the need to understand Show original failures.
Set up authenticated mailboxes at coldmail.app, or Book a Strategy Call if you are cleaning auth across many domains.