SPF, DKIM and DMARC are three short records in your domain’s DNS. Together they tell receiving mail servers that an email claiming to come from your domain really did. Without them, cold emails are far more likely to be filtered or rejected. In our first campaigns, a sending domain without them received no replies.
Who needs to do this
This applies if you send from your own mailbox. If Communication21 sends for you, the agency mailbox’s domain is managed for you and there is nothing to add. You will need access to your domain’s DNS settings, usually at your domain registrar or hosting provider, or help from whoever manages them.
SPF: who may send
SPF is a list of the servers allowed to send email for your domain. It is one TXT record on the domain itself.
Type: TXT Host: @ (your domain, e.g. example.com.my) Value: v=spf1 include:<your provider’s SPF domain> ~all
- Google Workspace uses
include:_spf.google.com; Microsoft 365 usesinclude:spf.protection.outlook.com. Other providers publish their own value in their help pages. - A domain must have only one SPF record. If you already have one, add the new
include:to it rather than creating a second record.
DKIM: a signature on each email
DKIM adds a digital signature to every email. Your provider holds the private key; you publish the public key in DNS so receivers can check the signature.
Type: TXT (or CNAME, if your provider says so) Host: <selector>._domainkey (e.g. google._domainkey) Value: v=DKIM1; k=rsa; p=<public key from your provider>
- In your email provider’s admin console, generate or switch on DKIM for your domain.
- Copy the host name and value it shows into your DNS.
- Return to the provider and start signing, if it asks you to.
- Note the selector: the part before
._domainkey. You will enter it in Outreach Asia.
DMARC: what to do when checks fail
DMARC tells receivers what to do with email that fails SPF and DKIM, and where to send reports. Start with a monitoring policy.
Type: TXT Host: _dmarc Value: v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com.my
p=none changes nothing about delivery; it only asks for reports. Once reports show your legitimate email passing, you can move to p=quarantine, then p=reject. Replace the report address with a mailbox you actually read.
Check your records in Outreach Asia
- Allow time for DNS changes to take effect: often under an hour, sometimes up to a day or two.
- Go to Settings → Mailbox and enter your DKIM selector (optional) under the Sent-folder and domain authentication settings.
- Select Test connection and save, and read the SPF, DMARC and DKIM results.
- Send a test email to an external address you control and inspect its headers for
spf=pass,dkim=passanddmarc=pass.
The app checks that the records exist in public DNS. It does not prove they are correct for your provider. “SPF record found” does not confirm your mail server is listed in it, and without a selector DKIM is shown as not checked. If the app reports multiple SPF records, merge them into one.
Authentication makes delivery possible; it does not guarantee inbox placement or replies. Content, list quality, bounce rates and a steady warm-up all matter too.
Need help with something not covered here? Email wilson@communication21.com or use Help & glossary in the app.