← Back to Blog
Deliverability

Cold email DNS authentication: a pre-launch checklist

ColdMail Editorial · Infrastructure guides
2026-09-13 · 5 min read

Start with the complete message path

Map the domain shown in the From address, the service sending the message, and the person who controls DNS. Keep one launch record per domain with its owner, mailbox inventory, sequencer, and latest test. This creates a clear operating view for every campaign and client.

1. Authorize every sender with SPF

SPF identifies the systems authorized to send for your domain. List every active sending service, build one accurate record, and update it whenever your stack changes. ColdMail brings this configuration into the provisioning workflow so teams can launch domains consistently at scale.

Google Workspace: set up SPF

2. Activate DKIM signing

DKIM adds a cryptographic signature to outgoing messages. Confirm the selector and domain, publish the key, enable signing, and send through the same path your campaign will use. The received authentication result gives your team a direct confirmation that signing is active.

Google Workspace: set up DKIM

3. Align DMARC with the visible sender

DMARC connects authentication with the domain recipients see in the From address. Configure alignment, enable reporting, and use the reports to keep every legitimate sender visible. This gives operators a dependable view of how each domain is being used.

Google Workspace: set up DMARC

4. Confirm outbound delivery and inbound replies

Send a message through the campaign path, inspect its authentication results, and reply to the new mailbox. Confirm that the response reaches the mailbox and appears in the team’s reply workflow. One end-to-end test validates the full operating path before launch.

5. Record launch readiness

Record the test time, sending path, authentication results, reply result, sequencer connection, and campaign owner for every domain. A shared launch record makes handoffs faster and gives the team a repeatable process for every new client or campaign.

ColdMail turns authentication into infrastructure

ColdMail configures SPF, DKIM, DMARC, and MX alongside official Google Workspace mailbox provisioning. Domain health visibility, automated setup, and sequencer connections turn a technical checklist into a scalable launch workflow.

#dns#spf#dkim#dmarc#google-workspace