SPF, DKIM and DMARC for founders: a 20-minute setup
Three DNS records decide whether your emails land in the inbox. Here's what each one does and exactly how to set them up for Google Workspace or Microsoft 365.
- deliverability
- DNS
- SPF
- DKIM
- DMARC
If you send email from your own domain, three DNS records quietly decide whether it reaches the inbox: SPF, DKIM and DMARC. Without them, your investor update or first sales email is more likely to land in spam, or be rejected outright. Since 2024, Google and Yahoo have required bulk senders to have all three, and other mailbox providers have moved the same way.
The good news: for a typical startup on Google Workspace or Microsoft 365, the whole setup takes about 20 minutes, most of it waiting for DNS. This guide explains what each record does and walks through it step by step.
What you need before you start
- Admin access to your email provider (the Google Workspace Admin console or the Microsoft 365 admin and Defender portals).
- Access to your DNS provider, wherever your domain's records are managed: your registrar, Cloudflare, Netlify, Route 53 and so on.
- A list of every service that sends email as your domain: your mailbox provider, your newsletter tool, your CRM or outreach tool, your billing system.
1. SPF: who may send for your domain (5 minutes)
Sender Policy Framework is a single TXT record at the root of your domain that lists the servers allowed to send mail as you. Receivers compare the sending server against it.
For Google Workspace, the record looks like this:
v=spf1 include:_spf.google.com ~all
For Microsoft 365:
v=spf1 include:spf.protection.outlook.com ~all
If other services send as your domain, add their include: values from their documentation, in the same record:
v=spf1 include:_spf.google.com include:servers.example-esp.com ~all
Three rules to follow:
- Only one SPF record. Two
v=spf1records on the same domain make SPF fail. Merge them. - Stay under 10 DNS lookups. Each
include:counts, including the lookups inside it. The SPF standard (RFC 7208) caps this at 10; past it, SPF returns an error. - End with
~allwhile you're setting up. It means "soft fail anything not listed". Once DMARC reports confirm every legitimate sender passes, you can move to-all.
2. DKIM: sign every message (10 minutes)
DomainKeys Identified Mail adds a cryptographic signature to each message. You publish a public key in DNS under a selector, and receivers use it to check the message came from you and wasn't changed on the way.
Google Workspace
- In the Admin console, go to Apps → Google Workspace → Gmail → Authenticate email.
- Select your domain and click Generate new record. Choose a 2048-bit key if your DNS provider supports it.
- Google shows a host name (by default
google._domainkey) and a long TXT value starting withv=DKIM1. Create that TXT record at your DNS provider. - Wait for DNS to update, then return to the Admin console and click Start authentication.
Microsoft 365
- In the Microsoft Defender portal, open Email & collaboration → Policies & rules → Threat policies → Email authentication settings, then the DKIM tab.
- Select your domain. Microsoft shows two CNAME records, for
selector1._domainkeyandselector2._domainkey. - Create both CNAME records at your DNS provider exactly as shown.
- Back in the portal, turn on Sign messages for this domain with DKIM signatures.
Do the same for any other service that sends as your domain. Most give you their own selector and record.
3. DMARC: tie it together (5 minutes)
Domain-based Message Authentication, Reporting and Conformance tells receivers what to do when a message fails SPF and DKIM, and where to send reports. It's a TXT record at _dmarc.yourdomain.com.
Start in monitoring mode:
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com; adkim=r; aspf=r
p=nonemeans "don't block anything yet, just report".ruais where aggregate reports go. Use a mailbox you'll check, or a DMARC reporting service.adkim=randaspf=ruse relaxed alignment, which lets subdomains match. That's the right default for most teams.
DMARC passes when SPF or DKIM passes and aligns with the domain in your From address. That alignment is the part people miss: a newsletter tool might pass SPF for its own domain, but unless it's configured to sign with DKIM for yours, it won't pass DMARC for you.
Tightening the policy
After two to four weeks of reports showing all your real senders pass, move to:
v=DMARC1; p=quarantine; pct=25; rua=mailto:dmarc-reports@yourdomain.com
Then raise pct to 100, and eventually consider p=reject. Each step tells receivers to treat failing mail more strictly, which protects your domain from being spoofed.
Check your work
DNS changes usually appear within minutes, though some providers take longer. To confirm:
- Run your domain through our free SPF and DMARC checker. It reads your MX, SPF, DKIM and DMARC records and explains any issue.
- Send an email to a Gmail address you own, open it, and choose Show original. You want to see
SPF: PASS,DKIM: PASSandDMARC: PASS.
Beyond DNS: habits that keep you in the inbox
Authentication gets you through the door. What you send decides whether you stay:
- Ramp up slowly. A brand-new mailbox that suddenly sends hundreds of cold emails looks like a compromised account. Start with a small daily volume and increase it gradually.
- Verify addresses before you send. Bounces are one of the clearest signals of a poor list. Keep them low by verifying first; our email verifier checks one address at a time.
- Make unsubscribing easy. A one-click unsubscribe header (RFC 8058) plus a visible link lowers spam complaints, which matter more than almost anything else.
- Leave open tracking off for cold email. Tracking pixels add little value, and some filters treat them as a negative signal.
- Consider a separate domain for high-volume cold outreach. Some teams send cold email from a closely related domain so that a mistake can't affect the primary domain their customers and investors rely on. If you do, set up SPF, DKIM and DMARC there too, and keep it clearly branded as you.
Summary
| Record | Where | Typical value | What it does |
|---|---|---|---|
| SPF | yourdomain.com (TXT) | v=spf1 include:... ~all | Lists servers allowed to send as you |
| DKIM | selector._domainkey.yourdomain.com | Key from your provider | Signs each message |
| DMARC | _dmarc.yourdomain.com (TXT) | v=DMARC1; p=none; rua=... | Sets policy and reporting |
Twenty minutes now can save you weeks of wondering why nobody replies.
OmniLead checks SPF, DKIM and DMARC on every connected mailbox and shows problems on the mailbox card. It won't launch a sequence until the mailbox health check passes, and it pauses a campaign automatically if bounces reach 5%.
Send from a mailbox that stays healthy
Connect your mailbox, get a health check on every send, and let the circuit breaker catch problems before they cost you.