WP Finder

Cold Email Deliverability: SPF, DKIM & DMARC Setup Guide

By WP Finder · Updated · 7 min read

Cold Email Deliverability: SPF, DKIM & DMARC Setup Guide

The best-written pitch in the world is useless if it lands in spam. Cold email deliverability is the set of technical and behavioural habits that decide whether your messages reach the inbox, and the foundation is a correct SPF, DKIM and DMARC setup on your sending domain. This guide explains what each record does, shows example DNS values, and then covers the parts people often skip: warming up a mailbox, sensible sending limits, content, list hygiene and monitoring.

All examples use example.com. Replace it with your own domain, and always copy the exact values your email provider gives you.

How cold email deliverability is decided

Mailbox providers such as Gmail and Outlook look at two big questions for every message:

  1. Is this sender who they claim to be? That’s what SPF, DKIM and DMARC answer.
  2. Do recipients want mail from this sender? That’s judged on reputation: bounces, spam complaints, replies, how quickly volume grows and how people interact with your messages.

Authentication alone won’t rescue a bad campaign, but missing authentication can sink a good one. Google and Yahoo both publish sender guidelines (see Gmail’s email sender guidelines) that expect authenticated mail, so treat this setup as essential.

SPF, DKIM and DMARC setup, step by step

SPF (Sender Policy Framework)

SPF is a TXT record on your domain that lists which servers are allowed to send email for it. When a message arrives, the receiving server checks whether the sending server is on your list.

Example SPF record for a domain using Google Workspace, added as a TXT record on the root of example.com:

v=spf1 include:_spf.google.com ~all

If you use Microsoft 365 instead, the include is usually include:spf.protection.outlook.com. If you send from more than one service, combine them into a single record:

v=spf1 include:_spf.google.com include:spf.protection.outlook.com ~all

Key rules for SPF:

  • Only one SPF record per domain. Two separate v=spf1 records cause SPF to fail.
  • Stay under the 10 DNS lookup limit. Each include can trigger further lookups. Too many and SPF returns an error.
  • ~all versus -all. ~all (soft fail) tells receivers that unlisted servers are suspicious; -all (hard fail) says they’re not allowed. Many senders start with ~all and rely on DMARC for enforcement.

DKIM (DomainKeys Identified Mail)

DKIM adds a digital signature to every email you send. Your provider signs the message with a private key, and receivers check it against a public key published in your DNS. If the message was altered in transit, or wasn’t signed by your provider, the check fails.

You don’t write DKIM keys by hand. Your email provider generates them in its admin panel, and you add the record it gives you. It’s published under a selector, for example:

  • Host/name: google._domainkey.example.com (here google is the selector)
  • Type: TXT
  • Value: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...

The p= value is a long public key; paste it exactly as provided. Some providers, including Microsoft 365, use CNAME records for DKIM instead of TXT. After adding the record, return to your provider’s panel and switch DKIM signing on, since many don’t start signing until you do. Use a 2048-bit key if your provider and DNS host support it.

DMARC (Domain-based Message Authentication, Reporting and Conformance)

DMARC ties SPF and DKIM together. It tells receivers what to do when a message fails authentication and where to send reports. Crucially, DMARC checks alignment: the domain in the visible “From” address must match the domain that passed SPF or DKIM.

Example DMARC record, added as a TXT record at _dmarc.example.com:

v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com

  • p=none means “monitor only, don’t block anything”. Start here.
  • rua= is where aggregate reports are sent, so you can see who is sending mail as your domain.

Once reports show that all your legitimate email passes, you can tighten the policy:

v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@example.com

and later, if you’re confident:

v=DMARC1; p=reject; rua=mailto:dmarc-reports@example.com

Move slowly: a strict policy set too early can block your own invoices or newsletter tools if they aren’t authenticated.

Checking your records

Once DNS changes have spread, check them from a terminal:

  • dig TXT example.com (SPF)
  • dig TXT google._domainkey.example.com (DKIM, using your selector)
  • dig TXT _dmarc.example.com (DMARC)

On Windows, nslookup -type=TXT example.com does the same job. Even simpler: send an email to a Gmail account, open it, choose “Show original” and look for SPF: PASS, DKIM: PASS and DMARC: PASS.

Warm up mailboxes for better cold email deliverability

A brand-new domain or mailbox has no sending history, and a sudden burst of cold email from it looks suspicious. Warming up means building a reputation gradually:

  • Use the mailbox normally for a while first, with real conversations and replies.
  • Start cold sending at a low daily volume and increase it slowly over several weeks.
  • Watch bounces and replies closely in the early days, and pause if problems appear.

Many people send cold outreach from a separate domain or subdomain (for example mail.example.com) so reputation problems don’t affect the main business domain. If you do, set up SPF, DKIM and DMARC on it too.

Sending limits and cold email deliverability

Every mailbox provider sets daily sending limits that differ by provider and account type, so check your provider’s current documentation. For cold email, stay well below the official limit, because reputation suffers long before you hit a hard cap.

  • Set a daily limit per mailbox and stick to it.
  • Add delays between emails rather than sending them all at once.
  • Spread sending through the recipient’s working day.
  • If you need more volume, add more properly warmed mailboxes rather than pushing one harder.

Cold email content that helps deliverability

  • Write like a person. Plain text or very light formatting works best.
  • Keep links to a minimum. One link, or none in the first email, is plenty. Avoid link shorteners.
  • Skip attachments and images in cold emails. Send files once someone asks for them.
  • Use honest subject lines. Clickbait and misleading subjects hurt trust and can break the law.
  • Personalise properly. One specific line about the recipient’s website beats any template trick.
  • Include a clear opt-out, such as an unsubscribe link or a line inviting people to reply “no thanks”. It reduces spam complaints and is required under laws like CAN-SPAM.

List hygiene: the most overlooked deliverability factor

Sending to bad addresses is one of the quickest ways to damage your reputation. Keep your list clean:

  • Use public, relevant addresses taken from the business’s own website, not bought lists.
  • Remove duplicates and obviously broken addresses before sending.
  • Remove hard bounces immediately and never retry them.
  • Keep a permanent do-not-email list of anyone who unsubscribes or asks not to be contacted.
  • Target tightly. A small, well-matched list beats a huge list of strangers.

Our guide on how to extract emails from websites explains how to build a list from public contact pages, and building a B2B lead list covers targeting.

Monitor your cold email deliverability

  • Bounce rate: a rising bounce rate means your list needs cleaning.
  • Spam complaints: keep them as close to zero as possible. Google Postmaster Tools shows complaint rates and domain reputation for mail sent to Gmail once you have enough volume.
  • DMARC reports: review them to catch unauthenticated senders using your domain.
  • Replies: real replies are a strong positive signal. If nobody replies, rethink targeting and copy.

Where WP Finder fits in

WP Finder helps with the list-building and sending side. It collects public emails from websites’ homepage, contact and about pages, skips duplicate domains, and exports to Excel or CSV. Its built-in sender uses your own Gmail, Outlook, Zoho or Hostinger mailbox, so your SPF, DKIM and DMARC setup applies to every email, and it supports daily limits, delays, automatic follow-ups, unsubscribe links and a do-not-email list. Once your domain is set up, read our guide to building a cold email follow-up sequence.

Final thoughts

Good cold email deliverability comes down to a correct SPF, DKIM and DMARC setup, a warmed-up mailbox, modest volume, human content, a clean list and regular monitoring. Always respect opt-outs and the rules in the countries you email; see is cold email legal? for an overview (not legal advice).

FAQ

Do I need SPF, DKIM and DMARC for cold email deliverability?

Yes. Major mailbox providers expect authenticated email, and missing records make it much more likely your messages are filtered or rejected. Set up all three on any domain you send from.

Can I have more than one SPF record?

No. A domain should have exactly one SPF TXT record. If you use several sending services, combine their include values into a single record and keep within the 10 DNS lookup limit.

Which DMARC policy should I start with?

Start with p=none and a reporting address so you can see what’s sending as your domain. Move to p=quarantine and then p=reject only once your reports show all legitimate mail passing.

How long should I warm up a new mailbox?

There’s no fixed rule. Use the mailbox normally first, then start cold sending at a low daily volume and increase gradually over several weeks while watching bounces, complaints and replies.