SPF, DKIM and DMARC: a checklist for cold email domains
The three DNS records every sending domain needs, what each one does, and how to check them.
By Pipenbox team
Placeholder post. Replace this article with your own content before launch.
Authentication records tell mailbox providers that you are allowed to send from your domain. Missing or broken records are one of the most common — and most fixable — reasons outreach lands in spam.
SPF
SPF lists the servers that may send mail for your domain. Keep it to a single TXT record and stay under the DNS lookup limit.
DKIM
DKIM adds a cryptographic signature to every message so providers can confirm it wasn't changed in transit. Your email provider gives you the key to publish.
DMARC
DMARC tells providers what to do when SPF or DKIM fails, and where to send reports. Start with a monitoring policy and tighten it once everything passes.
The checklist
- One SPF record that includes every service that sends for you
- DKIM enabled with your email provider and published in DNS
- A DMARC record with a reporting address
- Ongoing monitoring, because records drift when tools change
Pipenbox checks all three for every sending domain and flags anything that needs attention.