Deliverability

DMARC setup guide for cold email (SPF, DKIM, DMARC in plain English)

DMARC tells inbox providers what to do with mail that fails SPF/DKIM. For cold email you need all three aligned, at minimum p=quarantine. Here's the exact DNS setup.

18 Apr 2026 8 min readBy Autocloz Editorial, Deliverability team
DMARC setup guide for cold email (SPF, DKIM, DMARC in plain English)

Short answer: publish an SPF record listing your senders, turn on DKIM signing for your mailbox, then add a DMARC TXT record at _dmarc.yourdomain.com set to at least p=quarantine. Since 2024, Gmail and Yahoo reject bulk mail unless all three line up.

The three records

  • SPF (TXT on root): v=spf1 include:yourprovider.com ~all — names who's allowed to send as you.
  • DKIM (TXT on a selector): a public key your provider hands you; it cryptographically signs every message.
  • DMARC (TXT on _dmarc): v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com — the policy, plus where the reports go.

Quarantine vs reject

Start at p=quarantine (failures go to spam) once you've confirmed your legitimate mail passes. Then move to p=reject (failures bounced) for the strongest protection — it's what high-trust senders run.

The cold-email gotcha

For DMARC to pass, your *envelope-from* domain has to align with your *header-from* domain. Plenty of "spray" tools quietly break that alignment with custom return-paths. Autocloz keeps it intact and monitors SPF/DKIM/DMARC continuously, flagging a misconfiguration before it tanks your placement.

> Rather not hand-edit DNS? Start free — Autocloz points out every auth gap right on the mailbox setup screen.

Share
Free to start

Stop reading. Start sending.

Every tactic in this article is implemented behind the Autocloz dashboard.