SPF, DKIM, and DMARC Setup Guide for Cold Email 2026
A missing DKIM record can sink reply rates by half. Here's the exact SPF, DKIM, and DMARC setup for 2026, with real records for Google Workspace and 365.
A single missing DKIM selector can drop a 500-email daily campaign into spam entirely, killing every reply before a prospect ever sees the subject line. Teams running cold outreach through Instantly or Smartlead lose 20 to 40 percent of send volume to preventable deliverability failures every month. Fixing SPF, DKIM, and DMARC correctly the first time is the cheapest infrastructure investment you'll make in 2026.
By Rishabh Ambasta, Founder, Modern Inbound.
This guide is for anyone building or fixing cold email infrastructure: founders running their first outbound motion, ops leads who inherited a broken domain, or agencies standardizing DNS setup across client accounts. You don't need networking experience. You need access to your domain registrar's DNS panel and a few focused hours spread across a week while records propagate.
Expect 1 to 2 weeks from your first record to a clean DMARC report, and 2 to 4 hours a month afterward to keep it that way. Get this right and reply rates typically improve 2 to 3x, per internal Modern Inbound data across 3,000+ campaigns. Get it wrong and no amount of good copy will save your inbox placement.
Why DNS Records Decide Whether Your Cold Email Gets Read
Google and Microsoft filter mail before intent ever matters. A cold email with sharp copy and a broken DMARC alignment gets junked before a human opens it. Under Google's bulk sender rules, effective February 2024, senders without valid SPF, DKIM, and DMARC face outright rejection, not just a spam-folder placement.
Most teams treat DNS setup as a formality they'll get to later. That's backwards. It's the single most consequential fix in the entire outbound stack. Doing it right adds up to a 2 to 3x reply-rate lift. Doing it wrong caps your reply rate near zero, no matter how good your copy is.
Here's the part nobody says out loud: most agencies pitching "deliverability optimization" are really just fixing DNS records they should have set up correctly on day one. It's not complicated. It's just unforgiving of shortcuts.
How SPF, DKIM, and DMARC Work Together
SPF tells receiving servers which IPs are allowed to send mail for your domain. DKIM cryptographically signs each message so it can't be altered in transit. DMARC tells receiving servers what to do when SPF or DKIM fails, and sends you reports when it happens. You need all three. None of them work well alone.
Think of it as a chain of custody. SPF answers "did this come from an approved server?" DKIM answers "was this message tampered with?" DMARC answers "what happens if either check fails, and who gets told?" Skip DMARC and you have no visibility into spoofing attempts against your own domain. Skip DKIM and forwarded mail breaks SPF alignment constantly.
| Record | What It Checks | Where It Lives |
|---|---|---|
| SPF | Authorized sending IPs | TXT record on root domain |
| DKIM | Message integrity signature | TXT record on a selector subdomain |
| DMARC | Enforcement policy and reporting | TXT record on _dmarc subdomain |
Step 1: Audit Your Current DNS Setup Before Touching Anything
Before you add a single record, pull your existing DNS zone file and check what's already there. Most teams that "have SPF issues" actually have two conflicting SPF records fighting each other, which is worse than having none. This step takes 15 minutes and prevents hours of confused troubleshooting later.
Run your domain through MXToolbox's SPF and DMARC lookup tools. Note every existing TXT record touching mail, including old marketing platforms nobody uses anymore. Cold senders inherit a lot of DNS debt from whatever tool sent the last company newsletter three years ago.
Pro tip: if you're setting up a new sending subdomain (recommended for cold outreach, keep your primary domain clean), start this audit on the subdomain, not the root. Most DNS mistakes we see at Modern Inbound come from editing the wrong zone.
Common mistake: publishing two SPF TXT records instead of merging includes into one. RFC 7208 explicitly says multiple SPF records cause a permanent error, which some receivers treat as an automatic fail.
Step 2: Configure SPF for Google Workspace and Microsoft 365
SPF setup means adding one TXT record that lists every service allowed to send as your domain, including your cold email tool. Missing a single "include" statement here is the most common reason new sending domains start bouncing in week one.
| Platform | Sample SPF Record | Host |
|---|---|---|
| Google Workspace | v=spf1 include:_spf.google.com include:spf.smartlead.ai ~all | @ (root) |
| Microsoft 365 | v=spf1 include:spf.protection.outlook.com include:spf.instantly.ai ~all | @ (root) |
Swap in whichever sending tool you actually use. Instantly, Smartlead, and Apollo.io's built-in sender each publish their own include string, and you'll find it in their sending domain settings page. Stack every include you need into one record. Never publish two.
Common mistake: using "-all" (hard fail) too early. Start with "~all" (soft fail) while you're still confirming every sending source, then tighten it once volume is stable for two to three weeks.
Step 3: Turn On DKIM Signing
DKIM setup means generating a public/private key pair in your email platform and publishing the public half as a DNS record, so receiving servers can verify your messages weren't altered. Google Workspace and Microsoft 365 both generate this for you. You just have to actually turn it on, which a surprising number of teams skip.
In Google Workspace admin, go to Apps > Google Workspace > Gmail > Authenticate email, generate a 2048-bit key, and publish the resulting TXT record at the selector host it gives you. In Microsoft 365, enable DKIM signing per domain in the Defender portal under Email Authentication Settings.
For your cold sending tool, DKIM works differently. Instantly and Smartlead both generate their own DKIM keys per sending domain when you connect it, separate from your Google or Microsoft signature. Publish both. A domain missing the sending tool's DKIM record will show "DKIM: none" in test reports even if your inbox provider's DKIM is perfect.
Step 4: Publish a DMARC Policy That Actually Protects You
Start every new domain at p=none. This mode only monitors and reports, it doesn't block anything, so you can watch what's passing and failing without risking legitimate mail. After 1 to 2 weeks of clean reports, move to p=quarantine, then p=reject once you trust the setup completely.
A starting record looks like: v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com; pct=100. The rua tag is what sends you daily aggregate reports. Skip it and you're flying blind on whether your policy is even working.
Here's the opinion most guides won't give you: jumping straight to p=reject on a new domain is reckless. We've seen teams do it to "move fast" and instead nuke their own legitimate mail for two weeks while they debug alignment. Walk the ladder. None, then quarantine, then reject.
Step 5: Test Before You Send a Single Cold Email
Send a test message through mail-tester.com and confirm you're scoring 9/10 or higher before any real prospect sees your domain. Anything below that score usually points to a missing SPF include, an unpublished DKIM selector, or a DMARC record that hasn't propagated yet.
Check propagation with MXToolbox or a plain dig TXT yourdomain.com command. DNS changes can take anywhere from a few minutes to 48 hours depending on your registrar's TTL settings. Don't start sending until every record resolves cleanly from at least two different lookup tools.
Expected outcome: a mail-tester score of 9 or higher, a DMARC report showing 100 percent pass on SPF and DKIM alignment, and zero "not aligned" flags in your first weekly report.
Real-World Example: A 30-Person SaaS Company's Spam Folder Problem
A 30-person B2B SaaS company selling to marketing directors came to us sending 400 emails a day through Smartlead with a 0.8 percent reply rate. Their SPF record had two competing entries from a discontinued newsletter tool, and DKIM was never turned on for their sending subdomain.
We consolidated the SPF record into one, enabled DKIM on the subdomain, and published DMARC at p=none with reporting on. Within 12 days, their mail-tester score went from 4/10 to 10/10. Reply rate climbed to 2.1 percent over the following month, a 2.6x improvement, with no changes to copy or targeting.
The fix cost nothing but time. That's what makes bad DNS setup so frustrating to watch: it's not a budget problem, it's an attention problem.
Tools and Setup Requirements
You need four things to run this setup: access to your DNS registrar, an email platform (Google Workspace or Microsoft 365), a cold sending tool, and a way to verify records once published. None of it requires new spend beyond what you're already paying for outbound.
- DNS access: Cloudflare, GoDaddy, or Namecheap, whichever holds your domain's nameservers
- Sending infrastructure: Instantly or Smartlead for campaign delivery
- Data and enrichment: Apollo.io for contacts, Clay for waterfall enrichment before you send
- CRM sync: HubSpot or Salesforce to route replies once inbox placement is fixed
- Verification: mail-tester.com and MXToolbox for pre-send checks
Doing this in-house is entirely possible for a technical founder with a free afternoon. Where teams get stuck is maintenance: watching DMARC reports weekly, rotating sending subdomains as volume scales, and catching alignment breaks before they tank a campaign mid-flight. That ongoing monitoring is exactly the kind of unglamorous work Modern Inbound handles for clients running managed outbound, so nobody has to remember to check a DMARC dashboard every Monday.
Measuring Success: KPIs, Timeline, and ROI
Track three numbers weekly: DMARC pass rate, mail-tester score, and reply rate. A healthy setup holds DMARC pass above 98 percent and mail-tester at 9 or higher consistently, not just on the day you tested it.
| Metric | Target | Check Frequency |
|---|---|---|
| DMARC pass rate | 98%+ | Weekly |
| Mail-tester score | 9/10 or higher | Before every new domain goes live |
| Reply rate | 2-3x baseline within 30 days | Monthly |
Rough ROI math: if your team sends 2,000 emails a month and a broken setup costs you 30 percent of deliverable volume, that's 600 emails a month landing nowhere. At even a 3 percent reply rate on recovered volume, that's 18 extra conversations a month from a fix that took a week and cost nothing.
Advanced Tips: Scaling DNS Across Multiple Sending Domains
Teams sending 500+ emails a day should never run everything through one domain. Split volume across 3 to 5 sending subdomains, each with its own SPF, DKIM, and DMARC records, so a reputation hit on one doesn't take down your whole outbound motion.
Rotate in new subdomains every 60 to 90 days as you scale, warming each one for 2 to 3 weeks before full volume. Keep DMARC reporting centralized to one inbox across all subdomains so you're not checking five separate dashboards.
The bottleneck at scale is never technical, it's operational. Someone has to actually read the weekly DMARC reports and catch drift before it becomes a spam problem. Agencies and in-house teams that skip this step are the ones back in our inbox three months later asking why reply rates cratered again.
About the Author
Rishabh Ambasta is the founder of Modern Inbound, a done-for-you cold email and LinkedIn outbound agency based in Mumbai. His team has run infrastructure and copy across 3,000+ campaigns and booked 3,000+ qualified B2B meetings for clients spanning recruitment, SaaS, finance, healthcare, and real estate, including teams at Yes Bank, PhonePe, Razorpay, Porter, and Ather Energy.
Too Busy to Run Outbound Yourself?
Modern Inbound handles research, infrastructure, warm-up, account lists, copy tests, sending, replies, and routing. The system has booked 2,700+ B2B meetings and influenced $20M+ in pipeline.
FAQ
How long does it take to set up SPF, DKIM, and DMARC? Most domains are fully configured in 1 to 2 weeks, with DMARC held at p=none for the first 7 to 10 days of clean reporting.
Why do cold emails still land in spam even with SPF set up? Because SPF alone doesn't stop spam placement. You need DKIM and DMARC alignment plus a warmed domain working together.
Should I use my primary domain or a subdomain for cold email? A separate sending subdomain, always. It isolates reputation risk from your core business email.
What ROI should I expect from fixing DNS records? A 2 to 3x reply-rate lift within 30 days is typical, per internal Modern Inbound data across 3,000+ campaigns.
What's the most common mistake teams make with DMARC? Jumping straight to p=reject on a new domain instead of monitoring at p=none first.
Next Steps
Once your DNS is clean, the next bottleneck is usually list quality and copy, not infrastructure. Audit your sending volume against your DMARC reports weekly for the first month, then move to monthly checks once pass rates hold steady above 98 percent.
If you'd rather not own the weekly DMARC monitoring, domain rotation, and warmup schedule yourself, that's the operational layer Modern Inbound runs for clients on managed outbound, alongside the data sourcing and copy. See how the full setup works on our contact page.
You Might Also Like
Get the outbound breakdown.
Real campaigns we ran this month. Numbers, copy, what worked, what didn't. Drop your work email.
Ready to fill your pipeline?
We build cold outbound systems that book 20-30 qualified meetings per month. No long-term contracts.
Apply to work with us