Knowledge base

Knowledge base / Sending & deliverability / 3 min read

SPF, DKIM and DMARC explained simply

What the three email authentication records do, the records to add for your own sending domain, and how to check them in Outreach Asia.

SPF, DKIM and DMARC are three short records in your domain’s DNS. Together they tell receiving mail servers that an email claiming to come from your domain really did. Without them, cold emails are far more likely to be filtered or rejected. In our first campaigns, a sending domain without them received no replies.

Who needs to do this

This applies if you send from your own mailbox. If Communication21 sends for you, the agency mailbox’s domain is managed for you and there is nothing to add. You will need access to your domain’s DNS settings, usually at your domain registrar or hosting provider, or help from whoever manages them.

SPF: who may send

SPF is a list of the servers allowed to send email for your domain. It is one TXT record on the domain itself.

Type:  TXT
Host:  @   (your domain, e.g. example.com.my)
Value: v=spf1 include:<your provider’s SPF domain> ~all
  • Google Workspace uses include:_spf.google.com; Microsoft 365 uses include:spf.protection.outlook.com. Other providers publish their own value in their help pages.
  • A domain must have only one SPF record. If you already have one, add the new include: to it rather than creating a second record.

DKIM: a signature on each email

DKIM adds a digital signature to every email. Your provider holds the private key; you publish the public key in DNS so receivers can check the signature.

Type:  TXT (or CNAME, if your provider says so)
Host:  <selector>._domainkey   (e.g. google._domainkey)
Value: v=DKIM1; k=rsa; p=<public key from your provider>
  1. In your email provider’s admin console, generate or switch on DKIM for your domain.
  2. Copy the host name and value it shows into your DNS.
  3. Return to the provider and start signing, if it asks you to.
  4. Note the selector: the part before ._domainkey. You will enter it in Outreach Asia.

DMARC: what to do when checks fail

DMARC tells receivers what to do with email that fails SPF and DKIM, and where to send reports. Start with a monitoring policy.

Type:  TXT
Host:  _dmarc
Value: v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com.my

p=none changes nothing about delivery; it only asks for reports. Once reports show your legitimate email passing, you can move to p=quarantine, then p=reject. Replace the report address with a mailbox you actually read.

Check your records in Outreach Asia

  1. Allow time for DNS changes to take effect: often under an hour, sometimes up to a day or two.
  2. Go to Settings → Mailbox and enter your DKIM selector (optional) under the Sent-folder and domain authentication settings.
  3. Select Test connection and save, and read the SPF, DMARC and DKIM results.
  4. Send a test email to an external address you control and inspect its headers for spf=pass, dkim=pass and dmarc=pass.

The app checks that the records exist in public DNS. It does not prove they are correct for your provider. “SPF record found” does not confirm your mail server is listed in it, and without a selector DKIM is shown as not checked. If the app reports multiple SPF records, merge them into one.

GOOD TO KNOW

Authentication makes delivery possible; it does not guarantee inbox placement or replies. Content, list quality, bounce rates and a steady warm-up all matter too.

Need help with something not covered here? Email wilson@communication21.com or use Help & glossary in the app.