Short answer: DMARC (Domain-based Message Authentication, Reporting and Conformance) is a DNS record that tells receiving mail servers how to handle email that claims to come from your domain but fails authentication. A message passes DMARC when SPF or DKIM passes and that passing domain aligns with the visible From domain. Gmail requires it for bulk senders.
Key takeaways
- DMARC passes when SPF or DKIM passes and is aligned with the From domain. Passing alone is not enough.
- Google requires SPF, DKIM and DMARC for anyone sending 5,000+ messages a day to Gmail; p=none is the minimum policy.
- The most common cold email failure is alignment: the sending tool signs or bounces with its own domain, not yours.
- Roll out in steps: p=none with reports, fix every source, then quarantine, then reject.
Contents
DMARC is a DNS record that tells receiving mail servers what to do with email that uses your domain in the From address but cannot prove it came from you. It does that by checking two older standards, SPF and DKIM, and adding one rule they lack: the domain that passed must match the domain the reader sees.
Before reading further, run your sending domain through our free email DNS checker. It shows your SPF, DKIM and DMARC records in one place, so the rest of this page will be about your own domain, not a hypothetical one.
SPF, DKIM and DMARC in one sentence each
| Standard | What it proves | Where it lives | What it checks against |
|---|---|---|---|
| SPF | This server is allowed to send for this domain | TXT record on the domain | The hidden envelope sender (Return-Path), not the visible From |
| DKIM | This message was signed by this domain and not altered | TXT record at selector._domainkey | The d= domain in the signature, which can be any domain |
| DMARC | SPF or DKIM passed for the same domain the reader sees | TXT record at _dmarc.domain | The visible From domain |
The gap DMARC closes is in the last column. SPF and DKIM can both pass for some other domain while a scammer, or a misconfigured tool, shows your name in the From line. DMARC's job is to catch that mismatch.
Read a DMARC record, left to right
Here is a typical record for an outreach domain:
v=DMARC1; p=quarantine; sp=quarantine; rua=mailto:dmarc@yourdomain.com; adkim=r; aspf=r
- v=DMARC1: the version. It must come first and is still the only valid value.
- p=quarantine: the policy for mail that fails. none = just report, quarantine = treat as suspicious (usually spam folder), reject = refuse it.
- sp=: the policy for subdomains, if you want it to differ from p.
- rua=: where receivers send daily aggregate reports (XML) listing every IP that sent mail as your domain and whether it passed.
- adkim / aspf: alignment mode. r (relaxed, the default) accepts the same organizational domain, so mail.yourdomain.com aligns with yourdomain.com. s (strict) demands an exact match.
The formula DMARC applies to every message is short:
DMARC pass = (SPF pass AND SPF domain aligned with From)
OR
(DKIM pass AND DKIM d= domain aligned with From)Worked example: the cold email alignment trap
This is one of the most common reasons a new outreach domain fails DMARC. A team buys a new domain, connects inboxes to a sending tool, publishes SPF and a DMARC record, and starts sending. Every message shows:
- From: alex@getacme.com
- SPF: pass for bounces.sendingtool.com (the tool's envelope domain)
- DKIM: pass for sendingtool.com (the tool's default signature)
- DMARC: fail, because neither passing domain is getacme.com
Everything "passes" on the surface, yet the domain the reader sees is not authenticated. The fix: in the sending platform (or Google Workspace / Microsoft 365 admin), set up a custom DKIM key on getacme.com and, where offered, a custom return-path on a subdomain such as bounce.getacme.com. Then both checks pass for your own domain and DMARC passes. We cover the wider setup in how deliverability works: domains, inboxes and warmup, and the tool side in Smartlead vs Instantly.
Not sure your outreach domains pass DMARC?
Book a call with Shawn. We will look at your sending domains, show you where SPF, DKIM or alignment is failing, and explain how we set up infrastructure for campaigns in the US, UK and Europe, Middle East and India.
30-minute call · no obligation
Why mailbox providers now require it
Since February 2024, Google's sender guidelines require every sender to Gmail to set up SPF or DKIM, and anyone sending more than 5,000 messages a day to Gmail accounts to set up SPF, DKIM and DMARC, with a DMARC policy that can be p=none and a From domain aligned with SPF or DKIM. Google also asks bulk senders to keep their spam rate in Postmaster Tools below 0.3%. Yahoo publishes similar bulk-sender rules, and Microsoft's requirements for high-volume senders to Outlook.com consumer addresses took effect in May 2025.
Cold email teams usually stay below 5,000 a day per domain, but the threshold counts all mail from your domain, and spam filters reward authenticated, aligned mail at any volume. Treat the bulk-sender rules as the minimum. Our email deliverability basics post covers the rest of the checklist, and the cold email infrastructure calculator shows how many domains and inboxes your volume needs.
A safe rollout: none, then quarantine, then reject
- Week 0: publish SPF (one record, under the 10 DNS-lookup limit) and DKIM for every tool that sends as the domain.
- Week 0: publish
p=nonewith an rua address. - Weeks 1-4: read the aggregate reports. Every legitimate source (Google Workspace, your sequencer, your CRM, invoicing) must show aligned passes. Fix the ones that do not.
- Then: move to
p=quarantine, watch for a week or two, thenp=rejecton domains where you control every sender.
On a brand-new outreach domain with one or two senders, this can be quick. On your main company domain, where marketing, billing and support tools all send, take your time. This is why we keep cold outreach on separate domains, as described on our outbound infrastructure page.
Common mistakes
- Two SPF records on one domain. Receivers treat that as an error; merge them into one.
- Too many SPF lookups. More than 10 includes causes a permanent error and SPF fails.
- Leaving the tool's default DKIM instead of a custom key on your domain (the alignment trap above).
- Jumping straight to p=reject on the main domain and silently losing invoices or password resets.
- No rua address, so you never see which servers fail.
- Thinking DMARC fixes bad content. It proves who sent the email; it does not make an unwanted email wanted. Targeting, copy and the law still matter: see is cold email legal?
Is the standard changing?
Yes, gently. In 2026 the IETF published RFC 9989, which obsoletes the original DMARC specification, RFC 7489 from 2015, and puts DMARC on the standards track, with aggregate and failure reporting split into companion documents (RFC 9990 and 9991). According to industry summaries, the pct tag is replaced by a simple test flag and a new np tag sets policy for non-existent subdomains. Records starting with v=DMARC1 keep working, so there is no emergency; review your records next time you touch DNS.
Related terms
- Return-Path / envelope sender: the bounce address SPF checks.
- DKIM selector: the label that tells receivers where to find your public key.
- BIMI: shows your logo in some inboxes; requires DMARC at enforcement.
- Email warm-up: building sending reputation gradually on a new inbox.
- Sender reputation: how mailbox providers score your domain and IPs over time; see the outreach mistakes that damage it.
- Outbound infrastructure as a service: having a lead generation partner set up and monitor domains, inboxes and authentication for you.
Authenticated, warmed up, and replying?
Once your domains pass DMARC and replies start coming in, Tailr CRM turns positive replies from Smartlead, Instantly, lemlist and Apollo into assigned leads with follow-up tasks. 14 days free, no card.
14 days free · no card · no setup fee
Bottom line
SPF and DKIM prove a server and a signature; DMARC proves they belong to the domain your prospect sees. For cold email, the setting that matters most is aligned DKIM on your own domain, plus a DMARC record that starts at p=none and moves toward enforcement once the reports are clean. Check yours with the free DNS checker, and find more guides in the cold email hub.
Sources
- Google, Email sender guidelines (accessed October 2026)
- RFC 7489, DMARC (2015) and RFC 9989, DMARC (2026, obsoletes RFC 7489)
- dmarc.org, DMARC overview
- RFC 7208, SPF (10 DNS-lookup limit) and RFC 6376, DKIM
- Yahoo Sender Hub, best practices
- Microsoft, Outlook's new requirements for high-volume senders (2025)
- DMARCbis tag changes: Red Sift, DMARC RFC 9989
What Is DMARC?
Get this guide as a printable PDF cheat sheet: the short answer and key takeaways, 1 comparison table, 2 copy-ready templates, 6 quick answers.
Frequently asked questions
What is the difference between SPF, DKIM and DMARC?
SPF lists the servers allowed to send mail for a domain. DKIM adds a cryptographic signature that proves a message was not changed and names the signing domain. DMARC sits on top: it checks that SPF or DKIM passed for a domain that matches the visible From address, and tells receivers whether to deliver, quarantine or reject mail that fails.
Do I need DMARC for cold email?
Yes. Gmail requires SPF, DKIM and DMARC from bulk senders, Yahoo and Outlook.com have similar rules for high-volume senders, and an unauthenticated domain looks suspicious to every spam filter. Even if each inbox sends far below 5,000 a day, a DMARC record with aligned DKIM is the baseline for reaching the primary inbox.
What DMARC policy should a cold email domain use?
Start with p=none and a rua address so you receive reports for two to four weeks. Once every legitimate source passes aligned SPF or DKIM, move to p=quarantine and later p=reject. A secondary outreach domain with only one or two sending tools can usually reach enforcement faster than your main company domain.
Does DMARC p=none do anything?
It does not change delivery: receivers treat failing mail as they would without DMARC. But it publishes that you have a policy, which Gmail, Yahoo and Outlook.com require from bulk senders, and the rua tag gets you daily aggregate reports showing every server sending as your domain. That visibility is what makes enforcement safe later.
Why does DMARC fail when SPF and DKIM pass?
Because of alignment. SPF may pass for your sending tool's bounce domain and DKIM may pass for the tool's own signing domain, while the From address shows your domain. Neither passing domain matches yours, so DMARC fails. The fix is a custom return-path and custom DKIM key on your own domain in the sending tool.
What changed with RFC 9989 (DMARCbis)?
In 2026 the IETF published RFC 9989, which obsoletes the original DMARC specification, RFC 7489, and moves DMARC onto the standards track. Industry summaries say the pct tag is replaced by a simple test flag, and reporting moved into separate documents. Existing v=DMARC1 records keep working, so nobody needs to rush a change.




