BlogDeliverability
Deliverability

Email Deliverability Checklist: SPF, DKIM, DMARC Explained

July 30, 2026·9 min read·By ReachHighly Team

Most cold emails that "don't work" aren't a copywriting problem — they never reached the inbox in the first place. Deliverability is the unglamorous, technical foundation that everything else depends on. Get it wrong and the best subject line in the world lands in spam.

This is the exact checklist we use before any domain sends its first cold email. Work through it top to bottom.

1. SPF (Sender Policy Framework)

SPF is a DNS record that tells the world "these servers are allowed to send email as my domain." Without it, receiving mail servers have no way to know if an email claiming to be from you is legitimate.

Example SPF record (TXT, on your root domain)
v=spf1 include:_spf.google.com ~all

Replace _spf.google.com with whatever your actual sending provider requires (Google Workspace, Microsoft 365, your ESP, etc.). If you send from more than one provider, they all need to be included in the same record — a domain can only have one SPF record.

2. DKIM (DomainKeys Identified Mail)

DKIM adds a cryptographic signature to every email you send, proving it genuinely came from your domain and wasn't altered in transit. It's generated by your email provider — you just add the public key they give you as a DNS record.

Example DKIM record (CNAME or TXT, provider-specific)
selector1._domainkey.yourdomain.com → selector1-yourdomain-com.dkim.provider.com

Your provider's dashboard will give you the exact record to add — you never write this one from scratch.

3. DMARC (Domain-based Message Authentication)

DMARC tells receiving servers what to do if an email fails SPF or DKIM — reject it, quarantine it, or let it through anyway. It also gives you visibility: providers send you reports showing who's sending email claiming to be from your domain.

Example DMARC record (TXT, on _dmarc.yourdomain.com)
v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com

Start with p=quarantine (suspicious mail goes to spam, not rejected outright) rather than p=reject — you want a safety net while you confirm everything's configured correctly, especially in the first few weeks.

4. Domain and Mailbox Warmup

Even with perfect SPF/DKIM/DMARC, a brand-new domain or mailbox has zero sending history — and mailbox providers treat unknown senders with suspicion. Sending real cold-email volume on day one is the single most common cause of getting flagged, regardless of how correct your DNS setup is.

Ramp up gradually: start around 20–50 emails/day on a new domain, and increase over 4–8 weeks as you build a track record of real opens and replies with no spam complaints. This is exactly why ReachHighly's warmup system caps new mailboxes low and only raises the limit as they prove themselves over time.

5. List Hygiene

Sending to invalid, disposable, or long-dead addresses spikes your bounce rate — and a high bounce rate is one of the fastest ways to tank sender reputation, even on a perfectly configured domain.

6. Sending Pace, Not Just Volume

It's not only how many emails you send per day — it's how bursty the sending looks. Blasting 50 emails in two minutes looks nothing like normal human behavior, even if 50/day is otherwise a safe number. Spacing sends out over the day (a few minutes apart, not seconds) matters just as much as the daily cap.

Quick Checklist

☐ SPF record added and verified
☐ DKIM record added and verified
☐ DMARC record added (starting at p=quarantine)
☐ New domain/mailbox on a warmup ramp, not full volume
☐ Real-time email verification before every send
☐ Unsubscribe link and List-Unsubscribe header on every email
☐ Sends spaced out over the day, not bursted

Frequently Asked Questions

Do I need SPF, DKIM, and DMARC, or just one of them?

All three, ideally. SPF and DKIM authenticate your emails; DMARC tells receivers what to do if authentication fails and gives you visibility. Skipping any one weakens the whole setup.

How long does it take for DNS changes to take effect?

Usually a few minutes to a few hours, though it can take up to 48 hours in rare cases depending on your DNS provider's propagation time.

Can I use a free Gmail or Outlook account for cold email?

You can, but personal consumer accounts have much lower sending limits and less tolerance for bulk sending than a dedicated business domain on Google Workspace or Microsoft 365. For any real volume, a dedicated domain is safer.

What's a safe bounce rate?

Under 2% is healthy. Above 5% is a strong signal your list has stale or invalid addresses and needs cleaning before you send more.

ReachHighly handles warmup and verification automatically

No manual DNS guesswork — connect your domain and we guide you through the rest.

Start for free →