Setup & DNS
Key takeaway: SPF, DKIM, and DMARC are three DNS records that answer three questions every inbox asks. Get all three present and aligned before you send. Since February 2024, Google and Yahoo require them for bulk senders.
If you have spent any time near cold email, you have been told to "set up SPF, DKIM, and DMARC" without anyone explaining what they do. Here is the plain version. All three are DNS records, small text entries you add wherever your domain is managed, and together they answer three questions every inbox provider asks: Is this server allowed to send for this domain? Was the message tampered with? And what do I do if something fails?
SPF: is this server allowed to send?
A TXT record listing which servers may send for your domain. It looks like v=spf1 include:_spf.google.com ~all. Two rules break it constantly: you may have only one SPF record per domain (merge providers into a single record), and SPF allows a maximum of 10 DNS lookups. Stack too many includes and the whole thing silently fails.
DKIM: was this tampered with?
Your server signs each email with a private key, and you publish the matching public key in DNS at a selector, for example selector1._domainkey.yourdomain.com. The receiver verifies the signature, confirming the message is genuinely yours and unaltered. Your provider hands you the exact record to paste. You do not generate keys by hand.
DMARC: what do I do if something fails?
A policy record at _dmarc.yourdomain.com, like v=DMARC1; p=none; rua=mailto:you@yourdomain.com. The p= sets the policy: none monitors only, quarantine sends failures to spam, reject blocks them. DMARC also enforces alignment: the domain in your visible "From" must match what SPF or DKIM authenticated, which is what stops spoofing.
Together, one email gets checked like this: SPF confirms the server is allowed, DKIM confirms the message is authentic, and DMARC confirms the From address aligns and decides what happens if it does not. Pass all three and you clear the trust bar between inbox and spam. Since February 2024, Google and Yahoo require all three for bulk senders.
Setup, step by step
SPF. One TXT record at your root domain with your provider's include and a
~allending. Confirm there is only one.DKIM. Paste the record from your provider's admin panel at the selector they specify, then enable signing.
DMARC. A TXT record at
_dmarc.yourdomain.comstarting withp=noneand anrua=address so you can monitor safely.Verify. Wait for DNS to propagate, send a test to Gmail, open "Show original," and confirm SPF, DKIM, and DMARC all say PASS.
Tighten. Once reports show only legitimate mail passing, move DMARC to
quarantine, then eventuallyreject.
Done once, it is straightforward. Done by hand across dozens of cold email domains every time you scale, it is a tedious, error prone slog, and a single typo quietly routes you to spam. Every Frostmailer mailbox ships with SPF, DKIM, and DMARC preconfigured and verified, so authentication is solved before you log in. Either way, now you actually understand what those three records are doing for you.
Want this done for you?
Our Build and Release service stands up your entire cold email infrastructure: domains, mailboxes, authentication, warm-up, and tracking, all authenticated and ready to send. You skip the weeks of setup and start with campaigns.
Related resources
Ready to send better cold email?
Sign Up Now
