Announcement High-deliverability cold outreach and transactional email infrastructure at unbeatable transparent rates. Learn more →
Technical DNS Guide

The Complete SPF, DKIM & DMARC Setup Guide for Cold Outreach

Step-by-step instructions to configure DNS authentication records and pass Google and Yahoo inbox deliverability requirements.

✓
Written & Verified by Deliverability Engineering · Updated September 2026 · 7 min read

Why DNS Authentication Matters in 2024 and Beyond

Major mailbox providers—specifically Google Workspace, Microsoft 365, and Yahoo—require strict domain authentication for outbound senders. Without proper SPF, DKIM, and DMARC alignment, cold emails are either routed directly to the spam folder or rejected outright with permanent 550 delivery error codes.

The DNS Authentication Handshake
Your Domain DNS SPF, DKIM, DMARC TXT
→
Centimailer MTA Cryptographic Signing
→
Recipient Mail Server Google / Microsoft / Yahoo
→
Primary Inbox Pass (Aligned)

1. SPF (Sender Policy Framework)

SPF is a DNS TXT record that authorizes specific mail servers to send email on behalf of your domain name. To authorize Centimailer's outbound delivery cluster, add the following TXT record to your domain root (@):

DNS TXT Record · SPF
Type:  TXT
Host:  @ (or root domain)
Value: v=spf1 include:_spf.centimailer.com ~all
Common SPF Pitfall: A domain can only have ONE SPF record. If you already have an existing SPF record (e.g. for Google Workspace or Microsoft 365), do NOT create a second record. Instead, merge the include directives into a single record:
v=spf1 include:_spf.google.com include:_spf.centimailer.com ~all

2. DKIM (DomainKeys Identified Mail)

DKIM adds a cryptographic signature to every outgoing message header. Receiving servers verify this signature against the public key published in your domain's DNS. This proves that the message genuinely originated from your domain and was not altered in transit.

DNS TXT Record · DKIM Selector
Type:  TXT
Host:  cm._domainkey
Value: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC3s7...

3. DMARC (Domain-based Message Authentication)

DMARC ties SPF and DKIM together. It instructs recipient mail servers what policy to enforce if an incoming message fails authentication. In 2024, Google and Yahoo made DMARC mandatory for all outbound senders.

DNS TXT Record · DMARC Monitoring Policy
Type:  TXT
Host:  _dmarc
Value: v=DMARC1; p=none; sp=none; rua=mailto:dmarc-reports@yourdomain.com; pct=100
Best Practice: Always start with a monitoring policy (p=none) for the first 2–4 weeks. Once you confirm via aggregate reports (rua) that legitimate sends pass authentication, advance your policy to p=quarantine or p=reject to eliminate domain spoofing.

4. Testing & Verification

After saving your DNS records, allow up to 15–30 minutes for DNS propagation. You can verify your records using standard terminal commands or online lookup tools:

  • Check SPF: dig TXT yourdomain.com +short
  • Check DKIM: dig TXT cm._domainkey.yourdomain.com +short
  • Check DMARC: dig TXT _dmarc.yourdomain.com +short

Need Pre-Authenticated Senders?

Centimailer includes built-in authenticated transport pools, letting you send cold campaigns immediately without waiting for DNS propagation.

Start Sending Free on Centimailer →