Volume and setup

Do I Need SPF, DKIM and DMARC for Cold Email?

Outreach2dayPublished 2 min read
On this page

Short answer

Yes. Set up SPF, DKIM and DMARC on every domain you send cold email from. Gmail and Yahoo require SPF or DKIM from all senders and all three from bulk senders, and Outlook.com rejects high-volume mail that fails them. A DMARC policy of p=none is enough, but the From: domain must align with SPF or DKIM. Authentication is the minimum, not a guarantee of the inbox.

What each record does

  • SPF lists the servers allowed to send for your domain. Google: "SPF prevents spammers from sending unauthorized messages that appear to be from your domain."

  • DKIM signs each message so the receiver can check it came from your domain and wasn't changed.

  • DMARC tells the receiver what to do with mail that fails SPF and DKIM, and requires that the domain in the From: header matches the domain that passed.

What the providers require

Gmail

Yahoo

Outlook.com

All senders

SPF or DKIM

SPF or DKIM

Recommended

Bulk senders

SPF, DKIM and DMARC

SPF, DKIM and DMARC

SPF, DKIM and DMARC for domains over 5,000 a day

DMARC policy

p=none is enough

At least p=none

At least p=none

Alignment

From: aligned with SPF or DKIM

From: aligned with SPF or DKIM

Aligned with SPF or DKIM, preferably both

DKIM key

1024 bits or longer; 2048 recommended

At least 1024 bits

Not specified

Sources: Google's sender guidelines, Yahoo's sender requirements and Microsoft's announcement. Google counts a bulk sender as one that sends close to 5,000 messages or more a day to personal Gmail accounts.

Cold email domains usually send far less than 5,000 a day each, but set up all three anyway. Google recommends that you "always set up SPF, DKIM, and DMARC for your domains," and Microsoft says that below 5,000 a day "all senders benefit from these best practices."

What happens without them

Gmail rejects or defers unauthenticated mail with specific codes, listed in its SMTP error reference:

Code

Meaning

550 5.7.26

Neither SPF nor DKIM passed, or the domain's DMARC policy rejected the message

421 4.7.27 / 550 5.7.27

SPF did not pass

421 4.7.30 / 550 5.7.30

DKIM did not pass

421 4.7.40 / 550 5.7.40

No DMARC record, or no policy in it

421 4.7.32 / 421 5.7.32

From: not aligned with the SPF or DKIM domain

Outlook.com uses 550 5.7.515 for domains that don't meet its authentication level. See Outlook blocking cold email.

Setup checklist

  1. One SPF record per domain that includes every service that sends for it. Microsoft notes that more than 10 DNS lookups can make SPF fail.

  2. DKIM turned on for the sending service, with a 2048-bit key if supported.

  3. A DMARC record with at least p=none. Add a reporting address if you want reports.

  4. From: address on the same domain that SPF or DKIM authenticates.

  5. PTR (reverse DNS) on the sending IPs, which Gmail and Yahoo also require. Your mailbox provider controls this.

  6. Send a test message and check the headers for spf=pass, dkim=pass and dmarc=pass.

What authentication doesn't do

Passing SPF, DKIM and DMARC proves who sent the email. It doesn't make the email wanted. Placement still depends on the reputation of the sending IPs and domain, your volume, your list and your copy.

What we recommend at Outreach2day

We set up SPF, DKIM, DMARC and a redirect to your website automatically on every domain, including domains you connect by pointing their nameservers to us. Use separate domains for cold email, never your main company domain.

Sources

See deliverability issues before they kill performance

Monitor mailbox health in real time, spot degradation early, and keep warmup, protection, and sending in one place.