DMARC setup guide for cold email (SPF, DKIM, DMARC in plain English)
DMARC tells inbox providers what to do with mail that fails SPF/DKIM. For cold email you need all three aligned, at minimum p=quarantine. Here's the exact DNS setup.
Short answer: publish an SPF record listing your senders, turn on DKIM signing for your mailbox, then add a DMARC TXT record at _dmarc.yourdomain.com set to at least p=quarantine. Since 2024, Gmail and Yahoo reject bulk mail unless all three line up.
The three records
- SPF (
TXTon root):v=spf1 include:yourprovider.com ~all— names who's allowed to send as you. - DKIM (
TXTon a selector): a public key your provider hands you; it cryptographically signs every message. - DMARC (
TXTon_dmarc):v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com— the policy, plus where the reports go.
Quarantine vs reject
Start at p=quarantine (failures go to spam) once you've confirmed your legitimate mail passes. Then move to p=reject (failures bounced) for the strongest protection — it's what high-trust senders run.
The cold-email gotcha
For DMARC to pass, your *envelope-from* domain has to align with your *header-from* domain. Plenty of "spray" tools quietly break that alignment with custom return-paths. Autocloz keeps it intact and monitors SPF/DKIM/DMARC continuously, flagging a misconfiguration before it tanks your placement.
> Rather not hand-edit DNS? Start free — Autocloz points out every auth gap right on the mailbox setup screen.