Domain authentication guide

SPF, DKIM, and DMARC for cold email: what each record actually does.

SPF authorizes sending infrastructure. DKIM signs messages. DMARC checks alignment and publishes a policy. For a reliable sending identity, configure and validate all three.

Reviewed September 8, 2026 9 minute read Product behavior checked against current implementation
Short answer: SPF identifies allowed senders, DKIM proves message integrity with a signature, and DMARC requires the visible From domain to align with SPF or DKIM. Passing one check does not make the other two optional.

SPF vs DKIM vs DMARC

RecordPrimary jobWhat receiving systems evaluateCommon mistake
SPFAuthorize sending sourcesWhether the envelope sender's domain permits the sending serverPublishing multiple SPF records or omitting a legitimate sender
DKIMSign the messageWhether the signature validates against the domain's public keyPublishing the key but never enabling signing
DMARCRequire alignment and state policyWhether SPF or DKIM passes with a domain aligned to the visible From addressPublishing a policy before inventorying every legitimate sender

What SPF proves

SPF is a DNS TXT policy listing the services allowed to send for a domain. The receiver evaluates it against the message's envelope sender, which is not always the same address a recipient sees in the From field.

Keep one SPF record per domain. When several systems send mail, combine their permitted sources inside that one policy instead of creating competing records. Google and Microsoft both warn that multiple SPF records cause validation problems.

What DKIM proves

DKIM adds a cryptographic signature to each message. The public key lives in DNS under a selector; the sending service keeps the private key and uses it to sign outbound mail.

A DNS record alone is not enough: signing must also be enabled in the mailbox provider. Google recommends 2048-bit keys when the DNS host supports them, while accepting 1024-bit keys where necessary.

What DMARC adds

DMARC connects authentication to the visible identity. It checks whether the domain validated by SPF or DKIM aligns with the domain in the From address, then applies the published policy when alignment fails.

A monitoring policy such as p=none can collect reports before stricter enforcement. Moving to quarantine or reject without understanding every legitimate sender can block mail your organization intended to send.

What large mailbox providers require

Google requires SPF or DKIM for all senders to personal Gmail accounts. Senders above Google's bulk threshold must use SPF, DKIM, and DMARC, align the From domain, support easy unsubscribe for applicable messages, and keep reported spam rates below 0.3%.

Yahoo's published bulk-sender requirements similarly call for SPF, DKIM, a valid DMARC policy, alignment, easy unsubscribe, and spam complaint rates below 0.3%.

These provider requirements establish sender identity and accountability. They cannot guarantee inbox placement or make unwanted mail welcome.

A safer setup order

  1. Inventory every service that sends mail for the domain.
  2. Publish one SPF policy containing all legitimate sources.
  3. Generate DKIM keys, publish the public records, and enable signing.
  4. Publish DMARC in monitoring mode with a reporting destination you control.
  5. Send test messages and inspect the authentication results.
  6. Review DMARC reports before tightening enforcement.
  7. Revalidate whenever a provider, domain, or sending path changes.

How MailSequence handles this

With the Cloudflare nameserver-delegation flow, MailSequence coordinates SPF, DKIM, and DMARC setup and shows nameserver and setup status. Confirm the resulting live records independently before sending. You still own the domain and remain responsible for accounting for every other system that sends from it.

See the MailSequence domain and DNS workflow →

Primary sources

Authenticate the domain before asking it to build reputation.

Use the supported DNS workflow, verify every published record, and keep other legitimate senders in the inventory.