Deliverability 4 min read

SPF, DKIM and DMARC explained simply, and how to ramp up sending volume

What SPF, DKIM and DMARC do, how to set them up step by step, and how to increase your sending volume gradually. No promise to avoid spam, only good practice.

Email was designed at a time when anyone could write any sender address. SPF, DKIM and DMARC are three DNS-based mechanisms that let receiving servers check that a message really comes from the domain it claims. Mailbox providers now expect them, and cold outreach without them is a bad idea. Here is what each one does, in plain terms.

SPF: who is allowed to send for my domain

SPF (Sender Policy Framework) is a TXT record in your DNS that lists the servers allowed to send email for your domain. When a message arrives, the receiving server checks whether the sending server is on that list.

  • A domain should have one SPF record only; two records make the check fail.
  • The record usually includes your email provider, for example include:_spf.google.com for Google Workspace or include:spf.protection.outlook.com for Microsoft 365. Check your provider's documentation for the exact value.
  • The standard limits SPF evaluation to 10 DNS lookups. Adding many tools that each add an include can push you over that limit.
  • The record ends with a rule for everything else, often ~all (soft fail) or -all (hard fail).

DKIM: proof that the message was not altered

DKIM (DomainKeys Identified Mail) adds a cryptographic signature to each outgoing message. Your provider signs the message with a private key; the matching public key is published in your DNS under a name of the form selector._domainkey.yourdomain.com. The receiving server uses it to check that the signature is valid and that the signed parts were not modified in transit.

In practice, you generate or enable DKIM in your email provider's admin console, then copy the record it gives you into your DNS. Without that step, your mail is not signed by your own domain.

DMARC: what to do when the checks fail

DMARC (Domain-based Message Authentication, Reporting and Conformance) builds on the two others. It is a TXT record at _dmarc.yourdomain.com that does three things:

  • It requires alignment: the domain in the visible From address must match the domain validated by SPF or by DKIM.
  • It states a policy for messages that fail: none (just observe), quarantine (treat as suspicious) or reject (refuse).
  • It asks receivers to send you reports (the rua address) so you can see who sends mail in your name.

A cautious path is to start with p=none and read the reports to be sure all your legitimate sources pass, then move to quarantine and later reject once you are confident.

What the big providers ask for

Google's sender guidelines require every sender to set up SPF or DKIM, and bulk senders (about 5,000 messages or more per day to personal Gmail accounts) to set up SPF, DKIM and DMARC, with one-click unsubscribe for marketing messages. Google also asks senders to keep the spam rate reported in Postmaster Tools below 0.3%, and recommends staying below 0.1%. These requirements became effective on 1 February 2024. Microsoft applies similar requirements to domains sending more than 5,000 emails per day to Outlook.com consumer addresses (SPF and DKIM must pass, DMARC at least p=none with alignment), effective 5 May 2025.

Most small outbound teams are far below those volumes, but the direction is clear: authenticate everything and keep complaints very low. Setting up all three is cheap and worthwhile. Sources are listed at the end of this article.

Ramping up volume gradually

A brand-new mailbox or domain has no sending history. Suddenly sending a large volume looks abnormal to providers. The usual good practice is to start with a small number of emails per mailbox per day and increase step by step, as long as your results stay healthy.

  • Start low and keep a daily cap per mailbox. Spread sends over the working day instead of in one burst.
  • Increase in steps, for example every few days, and only if bounces stay low and replies come in.
  • Send to verified, relevant contacts first. Bounces and complaints are the quickest way to lose reputation.
  • Pause if bounces spike, clean the list, then resume more slowly.
  • Use a separate domain or subdomain for cold outreach so that your main domain is protected.

Some tools also exchange automatic emails between mailboxes to simulate engagement. This is controversial: it can go against the rules of Google and Microsoft and may lead to restrictions on your accounts. We consider the gradual increase of real, relevant sends the safer base.

A short checklist

  • SPF published once, within the lookup limit.
  • DKIM enabled and the DNS record published.
  • DMARC published with p=none first, reports read, policy tightened later.
  • A separate sending domain or subdomain for outreach.
  • Low starting volume, daily cap, gradual increase, pause on bounce spikes.
  • A working unsubscribe mechanism and a suppression list.

In Outbly, each sending domain gets an SPF, DKIM and DMARC status with fix instructions, daily limits apply per mailbox, and the gradual volume increase is enabled by default. Automatic exchanges between your own mailboxes exist only as an optional setting, with a clear warning about the risks. See also how to start B2B outbound.

Sources

Put it into practice

Build a first sequence, send within safe limits from your own mailboxes and track replies in one place.

Start for free

All articles