SPF DKIM DMARC Setup for Cold Email

Clara Monroe · Head of Deliverability, ColdMail
2026-10-06 · 10 min read

What each record does, in one line

MX tells the world where mail for the domain is received. Without it, replies and bounces have nowhere to go, and the domain looks unfinished.

SPF lists which servers are allowed to send mail for the domain.

DKIM adds a cryptographic signature that proves the message was not altered and came from your domain.

DMARC tells receivers what to do when SPF or DKIM fail, and where to send reports. It also requires the visible From domain to align with SPF or DKIM.

Before you start

You have a dedicated outbound domain (not your primary company domain). The domain is added and verified in Google Workspace. You have access to the DNS provider for the domain. You have super admin access to the Workspace Admin console.

Step 1: MX

Add Google's MX record at your DNS provider. Google's current guidance for new setups is a single MX record pointing to smtp.google.com with priority 1. Older setups use the five aspmx records; either works if it matches Google's documentation. Remove any MX records from a previous mail host.

Step 2: SPF

Create one TXT record at the root of the domain:

v=spf1 include:_spf.google.com ~all

Rules: Only one SPF record per domain. Two SPF records is an automatic fail. Only add other includes if another service genuinely sends mail from this domain. Cold email domains usually need nothing else; your sequencer sends through the Google mailbox. Stay under the limit of 10 DNS lookups. Plain Google only setups are far below it.

Step 3: DKIM

  1. In the Admin console go to Apps, Google Workspace, Gmail, Authenticate email.
  2. Select the domain and generate a new record. Choose a 2048 bit key if your DNS provider supports it.
  3. Copy the host name (usually google._domainkey) and the TXT value.
  4. Publish it at your DNS provider exactly as given. Some providers split long values; follow their instructions.
  5. Wait for DNS to propagate, then return to the Admin console and click Start authentication.

The most common DKIM mistake in cold email is step 5: the record is published but authentication was never started, so mail goes out unsigned.

Step 4: DMARC

Create a TXT record at host _dmarc:

v=DMARC1; p=none; rua=mailto:dmarc@yourbrand.com

p=none monitors without enforcing. Good for the first weeks. rua is where aggregate reports go. Use an address you actually read, or a DMARC report service. Once reports show SPF and DKIM passing consistently, consider moving to p=quarantine. Many cold email teams stay at p=none on outbound domains; what matters most is that a valid record exists and mail aligns.

Step 5: Verify

  1. Send a plain test from the new mailbox to a personal Gmail address.
  2. Open it, choose Show original, and confirm SPF PASS, DKIM PASS, DMARC PASS.
  3. Repeat to an Outlook address and check the message headers there too.
  4. Use a DNS lookup tool to confirm there is exactly one SPF record and the DKIM and DMARC records resolve.

Only start warmup after all three pass.

Common mistakes

Two SPF records after adding a tool's include as a separate record. Merge them into one. DKIM never activated in the Admin console. DKIM published under the wrong host, for example google._domainkey.yourdomain.com.yourdomain.com because the DNS provider appended the domain automatically. No DMARC at all. Leftover MX records from a parking page or previous host. Changing records mid campaign without testing. Recheck after every DNS change. Copying records across domains without regenerating DKIM. Each domain needs its own DKIM key.

Other pieces worth doing

Domain forwarding to your main website so the domain looks real. Custom tracking domain if you use link tracking. Google Postmaster Tools for domains sending meaningful volume to Gmail users. A simple opt out in every email.

Doing this at scale

Four records per domain is fine for one domain. For 20 domains it is 80 records, 20 DKIM activations, and 20 sets of tests, and one typo can quietly hurt a whole slice of a campaign. Agencies typically either build a checklist and spreadsheet per domain, script DNS through their registrar's API, or use infrastructure that publishes the records automatically.

When ColdMail fits

ColdMail publishes SPF, DKIM, DMARC, and MX automatically when it provisions official Google Workspace mailboxes on dedicated domains, so the steps above happen without you copying keys between tabs. You still get an official admin panel per domain with 2FA, so every record and setting stays visible and yours. AI warmup is available as an add on once authentication passes, and mailboxes are ready to connect in Instantly and Smartlead using the methods those tools support, and also work with n8n and other tools.

See it at coldmail.app.

#spf#dkim#dmarc#dns#authentication