Email deliverability for cold email: reputation, SPF, DKIM and DMARC explained (2026)
RJ, Founder, ZheatUpdated
Short answer
Whether an email lands in the inbox comes down to two things: reputation (does the receiving server trust you) and configuration (can it prove the email really comes from you).
- Reputation is built from the sending server, the domain and the individual mailbox. Send from Google Workspace or Microsoft 365, never cold email from your main domain, and warm up every new mailbox before using it.
- Configuration is five DNS records: MX, SPF, DKIM, DMARC and, optionally, BIMI. Since 2024, Google and Yahoo require SPF, DKIM and DMARC for bulk senders, and Microsoft followed in 2025. Without them, mail goes to spam or gets rejected.
This guide follows Lead Gen Jay's free email deliverability course, updated for 2026 and with what we run on our own campaigns.
Why this matters even outside cold email
Lead Gen Jay's agency learned this the hard way. Someone was spoofing emails from their main domain, and soon the whole team's normal emails, to clients and leads, were landing in spam. A single DNS record set up properly would have prevented it. Deliverability isn't only a cold email problem: it protects the address your clients, invoices and sales calls depend on.
Reputation: server, domain, mailbox
Server reputation. Not every mail server is trusted equally. Google and Microsoft servers have the best reputation, and most of your recipients also use Google or Microsoft. Stick to them, especially for your main domain.
Domain reputation. Your main domain carries every client conversation, so protect it. Never send cold email from it. Buy separate sending domains for outbound, so a reputation problem never touches the main one. A new domain needs weeks of warm-up before it sends anything at volume.
Mailbox reputation. A mailbox that has sent normal email for years is trusted more than one created yesterday. Every new mailbox, including a new employee's on your main domain, benefits from warm-up. For cold email, warm up for at least 2 to 4 weeks before the first campaign. If your main domain starts landing in spam, warming several of its mailboxes helps it recover faster.
Configuration: the five DNS records
You add these in your DNS host (Cloudflare, your registrar, Route 53 and so on). It looks the same everywhere: a record type, a name and a value.
MX (mail exchange). Tells the internet where to deliver email for your domain. Without it, you can't receive mail. Google Workspace and Microsoft 365 give you standard MX values to copy.
SPF (sender policy framework). A TXT record listing which servers may send email for your domain. The receiving server checks the sending server against the list, and a mismatch usually means spam. With Google Workspace it typically looks like v=spf1 include:_spf.google.com ~all. Two rules: one SPF record per domain, and no more than 10 DNS lookups inside it, or it breaks.
DKIM (DomainKeys Identified Mail). A digital signature. Your provider signs each email with a private key, and the receiving server checks it against the public key published in your DNS. Unlike SPF and MX, the value is unique to each domain. You generate it in Google Workspace or Microsoft 365 and publish it as a TXT record under a selector, for example google._domainkey. Use a 2048-bit key: the course suggests 1024, but 2048 is what Google recommends today.
DMARC (domain-based message authentication, reporting and conformance). A TXT record at _dmarc that tells receiving servers what to do when SPF or DKIM fails, and where to send reports. It has three policies:
p=none: monitor only. Failing emails are still delivered.p=quarantine: failing emails go to spam.p=reject: failing emails are refused.
The reports show how many emails pass or fail and why, which makes DMARC the best early warning you have. One correction to a common habit: p=none does not stop anyone spoofing your domain. Start at none to read the reports, then move your main domain to quarantine or reject once legitimate mail passes.
BIMI (brand indicators for message identification). Shows your logo next to your emails in Gmail and other inboxes. It requires DMARC at quarantine or reject, and for Gmail's verified check mark a Verified Mark Certificate, which needs a registered trademark. It builds trust on a main brand domain, but it isn't needed for cold email domains.
Tools to check your setup
- A DMARC tool such as EasyDMARC, used in the course, or EmailGuard, which we use. Both look up and generate SPF, DKIM and DMARC records and read the DMARC reports for you.
- mail-tester.com. Send an email to the address it gives you and get a score out of 10. It checks your authentication, spam filter score, blacklists and broken links. Signatures with broken links or images without alt text show up here more often than you'd think.
- Your sending tool's warm-up dashboard. Instantly, for example, shows a health score per mailbox, tests the domain's DNS and watches blacklists. The course's rule of thumb: if a mailbox's health drops below about 95%, stop campaigns on it and only warm it until it recovers.
Blacklists, briefly
Hundreds of blacklists exist and almost every domain is on a minor one at some point. That isn't an emergency. The ones that hurt are those mailbox providers check, such as Spamhaus and Barracuda, plus domain lists like SURBL. One update to the course: it names SORBS as one of the worst, but SORBS shut down in 2024.
If you land on a list that matters, stop campaigns on that domain, find out what went wrong, keep warm-up running and request removal. Domain blacklists have their own patterns, which we covered in why new cold email domains get blacklisted.
What changed since the course
- Bulk sender rules. Since February 2024, Google and Yahoo require anyone sending over 5,000 emails a day to their users to have SPF, DKIM and DMARC, keep spam complaints under 0.3%, and offer one-click unsubscribe on marketing email. Microsoft applied similar rules to Outlook.com in 2025. Cold email at a few dozen emails per mailbox is under that volume, but the same checks shape how every email is judged.
- Shared infrastructure became a signal. In 2026, cold email domains sharing the same name servers were blacklisted in bulk. Where your DNS lives now matters, not just what's in it.
What we run on every campaign
- Separate sending domains, a few Google Workspace mailboxes on each, never the client's main domain.
- SPF, DKIM and DMARC set up and verified before the first send.
- Warm-up for weeks before launch and kept on while campaigns run, at 20 to 30 emails per mailbox per day.
- Open and click tracking off, no attachments, no link shorteners.
- Placement, blacklists and DMARC reports checked daily with EmailGuard. A mailbox that slips is paused and replaced.
- An easy way to opt out in every email, honoured right away.
The rest of what makes a campaign work, mainly copy written for strangers, is in why most cold email campaigns don't book meetings.
FAQ
What is the difference between SPF, DKIM and DMARC? SPF lists the servers allowed to send for your domain. DKIM signs each email so the receiver can check it wasn't forged or changed. DMARC tells receivers what to do when those checks fail and sends you reports on the results.
Do I need DMARC for cold email?
Yes. Google, Yahoo and Microsoft expect SPF, DKIM and DMARC on bulk mail, and a missing DMARC record is a common reason mail goes to spam. On a dedicated sending domain, a p=none policy is common. On your main domain, move to quarantine or reject.
How long should I warm up a new mailbox? At least 2 to 4 weeks before the first cold campaign, and keep warm-up running afterwards. New domains benefit from more time.
Should I send cold email from my main domain? No. Use separate sending domains so a reputation problem never affects the domain your clients and team use every day.
How do I know if my emails are going to spam? Run an inbox placement test or send to mail-tester.com, and read your DMARC reports. A sudden drop in replies on a setup that was working is often the first sign.
