Book a Free Call
Cold Email

What Is DMARC? SPF, DKIM and DMARC Explained for Cold Email

SPF says which servers may send for you. DKIM signs the message. DMARC checks that at least one of them matches the From address people actually see, and tells inboxes what to do when nothing matches.

What Is DMARC? SPF, DKIM and DMARC Explained for Cold Email

Short answer: DMARC (Domain-based Message Authentication, Reporting and Conformance) is a DNS record that tells receiving mail servers how to handle email that claims to come from your domain but fails authentication. A message passes DMARC when SPF or DKIM passes and that passing domain aligns with the visible From domain. Gmail requires it for bulk senders.

Key takeaways

  • DMARC passes when SPF or DKIM passes and is aligned with the From domain. Passing alone is not enough.
  • Google requires SPF, DKIM and DMARC for anyone sending 5,000+ messages a day to Gmail; p=none is the minimum policy.
  • The most common cold email failure is alignment: the sending tool signs or bounces with its own domain, not yours.
  • Roll out in steps: p=none with reports, fix every source, then quarantine, then reject.
Contents
  1. SPF, DKIM and DMARC in one sentence each
  2. Read a DMARC record, left to right
  3. Worked example: the cold email alignment trap
  4. Why mailbox providers now require it
  5. A safe rollout: none, then quarantine, then reject
  6. Common mistakes
  7. Is the standard changing?
  8. Related terms
  9. Bottom line
  10. Sources
  11. FAQs

DMARC is a DNS record that tells receiving mail servers what to do with email that uses your domain in the From address but cannot prove it came from you. It does that by checking two older standards, SPF and DKIM, and adding one rule they lack: the domain that passed must match the domain the reader sees.

Before reading further, run your sending domain through our free email DNS checker. It shows your SPF, DKIM and DMARC records in one place, so the rest of this page will be about your own domain, not a hypothetical one.

SPF, DKIM and DMARC in one sentence each

StandardWhat it provesWhere it livesWhat it checks against
SPFThis server is allowed to send for this domainTXT record on the domainThe hidden envelope sender (Return-Path), not the visible From
DKIMThis message was signed by this domain and not alteredTXT record at selector._domainkeyThe d= domain in the signature, which can be any domain
DMARCSPF or DKIM passed for the same domain the reader seesTXT record at _dmarc.domainThe visible From domain

The gap DMARC closes is in the last column. SPF and DKIM can both pass for some other domain while a scammer, or a misconfigured tool, shows your name in the From line. DMARC's job is to catch that mismatch.

Read a DMARC record, left to right

Here is a typical record for an outreach domain:

Example DMARC record (TXT at _dmarc.yourdomain.com)
v=DMARC1; p=quarantine; sp=quarantine; rua=mailto:dmarc@yourdomain.com; adkim=r; aspf=r

The formula DMARC applies to every message is short:

The DMARC pass rule
DMARC pass = (SPF pass AND SPF domain aligned with From)
             OR
             (DKIM pass AND DKIM d= domain aligned with From)

Worked example: the cold email alignment trap

This is one of the most common reasons a new outreach domain fails DMARC. A team buys a new domain, connects inboxes to a sending tool, publishes SPF and a DMARC record, and starts sending. Every message shows:

Everything "passes" on the surface, yet the domain the reader sees is not authenticated. The fix: in the sending platform (or Google Workspace / Microsoft 365 admin), set up a custom DKIM key on getacme.com and, where offered, a custom return-path on a subdomain such as bounce.getacme.com. Then both checks pass for your own domain and DMARC passes. We cover the wider setup in how deliverability works: domains, inboxes and warmup, and the tool side in Smartlead vs Instantly.

Not sure your outreach domains pass DMARC?

Book a call with Shawn. We will look at your sending domains, show you where SPF, DKIM or alignment is failing, and explain how we set up infrastructure for campaigns in the US, UK and Europe, Middle East and India.

30-minute call · no obligation

Why mailbox providers now require it

Since February 2024, Google's sender guidelines require every sender to Gmail to set up SPF or DKIM, and anyone sending more than 5,000 messages a day to Gmail accounts to set up SPF, DKIM and DMARC, with a DMARC policy that can be p=none and a From domain aligned with SPF or DKIM. Google also asks bulk senders to keep their spam rate in Postmaster Tools below 0.3%. Yahoo publishes similar bulk-sender rules, and Microsoft's requirements for high-volume senders to Outlook.com consumer addresses took effect in May 2025.

Cold email teams usually stay below 5,000 a day per domain, but the threshold counts all mail from your domain, and spam filters reward authenticated, aligned mail at any volume. Treat the bulk-sender rules as the minimum. Our email deliverability basics post covers the rest of the checklist, and the cold email infrastructure calculator shows how many domains and inboxes your volume needs.

A safe rollout: none, then quarantine, then reject

  1. Week 0: publish SPF (one record, under the 10 DNS-lookup limit) and DKIM for every tool that sends as the domain.
  2. Week 0: publish p=none with an rua address.
  3. Weeks 1-4: read the aggregate reports. Every legitimate source (Google Workspace, your sequencer, your CRM, invoicing) must show aligned passes. Fix the ones that do not.
  4. Then: move to p=quarantine, watch for a week or two, then p=reject on domains where you control every sender.

On a brand-new outreach domain with one or two senders, this can be quick. On your main company domain, where marketing, billing and support tools all send, take your time. This is why we keep cold outreach on separate domains, as described on our outbound infrastructure page.

Common mistakes

Is the standard changing?

Yes, gently. In 2026 the IETF published RFC 9989, which obsoletes the original DMARC specification, RFC 7489 from 2015, and puts DMARC on the standards track, with aggregate and failure reporting split into companion documents (RFC 9990 and 9991). According to industry summaries, the pct tag is replaced by a simple test flag and a new np tag sets policy for non-existent subdomains. Records starting with v=DMARC1 keep working, so there is no emergency; review your records next time you touch DNS.

Authenticated, warmed up, and replying?

Once your domains pass DMARC and replies start coming in, Tailr CRM turns positive replies from Smartlead, Instantly, lemlist and Apollo into assigned leads with follow-up tasks. 14 days free, no card.

14 days free · no card · no setup fee

Bottom line

SPF and DKIM prove a server and a signature; DMARC proves they belong to the domain your prospect sees. For cold email, the setting that matters most is aligned DKIM on your own domain, plus a DMARC record that starts at p=none and moves toward enforcement once the reports are clean. Check yours with the free DNS checker, and find more guides in the cold email hub.

Sources

Free download

What Is DMARC?

Get this guide as a printable PDF cheat sheet: the short answer and key takeaways, 1 comparison table, 2 copy-ready templates, 6 quick answers.

Free. We may email you occasional guides; unsubscribe any time. Privacy

Frequently asked questions

What is the difference between SPF, DKIM and DMARC?

SPF lists the servers allowed to send mail for a domain. DKIM adds a cryptographic signature that proves a message was not changed and names the signing domain. DMARC sits on top: it checks that SPF or DKIM passed for a domain that matches the visible From address, and tells receivers whether to deliver, quarantine or reject mail that fails.

Do I need DMARC for cold email?

Yes. Gmail requires SPF, DKIM and DMARC from bulk senders, Yahoo and Outlook.com have similar rules for high-volume senders, and an unauthenticated domain looks suspicious to every spam filter. Even if each inbox sends far below 5,000 a day, a DMARC record with aligned DKIM is the baseline for reaching the primary inbox.

What DMARC policy should a cold email domain use?

Start with p=none and a rua address so you receive reports for two to four weeks. Once every legitimate source passes aligned SPF or DKIM, move to p=quarantine and later p=reject. A secondary outreach domain with only one or two sending tools can usually reach enforcement faster than your main company domain.

Does DMARC p=none do anything?

It does not change delivery: receivers treat failing mail as they would without DMARC. But it publishes that you have a policy, which Gmail, Yahoo and Outlook.com require from bulk senders, and the rua tag gets you daily aggregate reports showing every server sending as your domain. That visibility is what makes enforcement safe later.

Why does DMARC fail when SPF and DKIM pass?

Because of alignment. SPF may pass for your sending tool's bounce domain and DKIM may pass for the tool's own signing domain, while the From address shows your domain. Neither passing domain matches yours, so DMARC fails. The fix is a custom return-path and custom DKIM key on your own domain in the sending tool.

What changed with RFC 9989 (DMARCbis)?

In 2026 the IETF published RFC 9989, which obsoletes the original DMARC specification, RFC 7489, and moves DMARC onto the standards track. Industry summaries say the pct tag is replaced by a simple test flag, and reporting moved into separate documents. Existing v=DMARC1 records keep working, so nobody needs to rush a change.

Subhendu J Shawn

About the author

Subhendu J Shawn is the founder of B2BXclusive, a B2B outbound sales and lead generation agency, and the creator of Tailr CRM. His experience spans American Express and Amazon, and he has helped 50+ B2B companies build pipeline across the US, Europe, the Middle East and India. All articles by Shawn · Follow on LinkedIn

Keep reading

Want this running for you next month?

Book a free 30-minute strategy call. We will look at your market, ICP and current pipeline, and tell you honestly whether outbound will work for you.

Get qualified meetings booked for youBook call →