Set up SPF, DKIM, and DMARC
Authenticate your sending domain with SPF, DKIM, and DMARC so cold email from your Google Workspace mailboxes reaches the inbox.
Open in Tantra
These open the app in a new tab. You may be asked to sign in.
Overview
SPF, DKIM, and DMARC are three DNS records that prove your email is legitimately from your domain. Receiving mail servers check them on every message. When they pass, your cold email is far more likely to land in the inbox. When they are missing or misconfigured, your mail is more likely to hit spam or be rejected.
Tantra sends your cold email through your own Google Workspace mailboxes using the Gmail API. That means the authentication records live in your domain's DNS, and you set them up once at your DNS provider. This article explains what each record does and how to publish it. Tantra does not change your DNS. It scans it daily and reports problems, which is covered in domain health reports.
How the three records work together
Each record proves a different thing about your mail.
- SPF (Sender Policy Framework) lists which servers are allowed to send mail for your domain. A receiver looks up your SPF record and checks whether the sending server is on the list. Because Tantra sends through Google Workspace, your SPF record must authorize Google.
- DKIM (DomainKeys Identified Mail) adds a cryptographic signature to every message. The receiver uses a public key published in your DNS to confirm the message was signed by your domain and was not altered in transit.
- DMARC (Domain-based Message Authentication, Reporting and Conformance) ties the two together. It tells receivers what to do when SPF or DKIM fails, and where to send reports. It is your policy statement about mail claiming to be from your domain.
You want all three in place before you send cold email at any volume.
Before you start
- Access to your DNS provider so you can add and edit TXT records. This is wherever you manage your domain, such as your registrar or DNS host.
- Access to the Google Workspace Admin console if you administer the domain, so you can turn on DKIM.
- Your domain must already be sending through Google Workspace. Personal webmail addresses cannot be authenticated this way.
DNS record types matter here. SPF and DMARC are TXT records. DKIM is also published as a TXT record. These are all different from the CNAME record used for a custom tracking domain, covered later in this article.
Set up SPF
SPF is a single TXT record on your root domain that names the servers allowed to send for you.
- At your DNS provider, look for an existing
TXTrecord on your root domain whose value starts withv=spf1. You should have at most one SPF record. More than one breaks SPF. - If you have no SPF record, create a
TXTrecord on the root domain. For a domain that sends only through Google Workspace, a common value isv=spf1 include:_spf.google.com ~all. - If you already have an SPF record but it does not authorize Google, add
include:_spf.google.comto the existing record. Do not create a second record. Merge the includes into the one record. - Save the record and wait for DNS to propagate, which can take a few minutes to a few hours.
The include:_spf.google.com part is what authorizes Google's servers to send for your domain. The ~all at the end is a soft fail instruction for everything not listed. Keep your whole SPF record to a small number of includes. Long records with many lookups can hit evaluation limits.
Set up DKIM
DKIM is generated in the Google Workspace Admin console, then published as a TXT record in your DNS. Google produces the key. You copy it into DNS.
- In the Google Admin console, go to Apps, then Google Workspace, then Gmail, then Authenticate email.
- Select your domain and generate a new DKIM key. Google shows you a DNS host name and a long
TXTvalue to publish. The host name uses a selector that Google chooses, in the form<selector>._domainkey.yourdomain.com. - At your DNS provider, create a
TXTrecord with the host name and value Google gave you. - Wait for DNS to propagate, then return to the Authenticate email screen in the Admin console and click Start authentication.
The exact button labels and screen layout in the Google Admin console are Google's, not Tantra's. Follow Google's on-screen instructions, since Google may adjust the flow over time. This is general guidance for Google Workspace, not Tantra behaviour.
Tantra's daily scan probes a set of common DKIM selector names to confirm a key is published. If you use a custom selector that is not one of the common ones, the scan may report no DKIM even when signing is active. That detection limit is explained in domain health reports.
Set up DMARC
DMARC is one TXT record published at a special host name. Start with a monitoring policy, then tighten it once you are confident your legitimate mail passes.
- At your DNS provider, create a
TXTrecord with the host name_dmarc.yourdomain.com. - For the value, start with a monitoring policy such as
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com. - Save the record and wait for propagation.
- Watch the aggregate reports that arrive at your
ruaaddress for a couple of weeks. Confirm your real mail is passing SPF or DKIM. - Once your legitimate mail passes cleanly, move the policy up. Change
p=nonetop=quarantine, and later top=reject.
The policy tag p= is the heart of the record. A policy of none only monitors and asks receivers to take no action. A policy of quarantine asks receivers to treat failing mail as suspicious. A policy of reject asks them to block it. Stronger policies protect your domain from being spoofed, but only move up after you have confirmed your own mail passes, or you risk your legitimate mail being quarantined.
The rua= tag sets the address that receives aggregate reports. Without it, you never see who is sending as you.
How Tantra helps
Tantra does not edit your DNS, but it watches it for you. Every day, in the early morning, Tantra runs a read-only scan of the domains behind your connected sender mailboxes and grades each one. The scan checks:
- Whether an SPF record is present, and flags common problems such as more than one SPF record, an overly permissive setting, a record that is too long, or a missing Google include when your mail points at Google.
- Whether a DKIM key is published under common selector names.
- Whether a DMARC record is present, and what policy it uses.
- Whether your mail servers appear on major public spam blocklists.
Each domain gets a status of healthy, warning, or critical, and a score out of 100. You can also trigger an on-demand refresh. The full breakdown of the score, statuses, and warnings is in domain health reports. Use that report to confirm the records in this article are published correctly.
Do not confuse these with the tracking domain record
A custom tracking domain uses a CNAME record, not a TXT record, and it serves a completely different purpose. SPF, DKIM, and DMARC authenticate your mail. A tracking domain routes tracked click links through a subdomain you control. They are separate records and separate features. Adding one does nothing for the other. See set up a custom tracking domain for that setup.
What happens next
DNS changes are not instant. After you publish a record, receivers and Tantra's scan may not see it for a few minutes to a few hours, depending on your provider and the record's cache time. If you check too soon, the record can read as absent even though it is correct.
Tantra's scan runs automatically once a day. To see your changes reflected sooner, trigger an on-demand refresh from the domain health area rather than waiting for the next daily run. A newly published record should show up once DNS has propagated and the scan runs again.
Best practices
- Publish all three records before you send cold email at volume. Authentication is the foundation of deliverability.
- Keep exactly one SPF record on your root domain. Merge includes into it rather than adding a second record.
- Start DMARC at
p=noneand read the reports before tightening. Move top=quarantine, thenp=reject, only when your real mail passes. - Pair strong authentication with mailbox warmup. See warm up your sending mailboxes.
- After any DNS change, wait for propagation, then use Tantra's domain health refresh to confirm the record is live.
Common mistakes
- Publishing two SPF records. Receivers may pick the wrong one and drop your mail. Merge them into one record.
- Forgetting
include:_spf.google.comwhen you send through Google Workspace. Your SPF passes for other senders but not for Google. - Turning on DKIM in the Admin console but never publishing the
TXTrecord in DNS, or publishing it and forgetting to click Start authentication. - Jumping straight to a DMARC policy of
rejectbefore confirming your mail passes. This can send your own legitimate mail to quarantine. - Mixing up the tracking domain
CNAMEwith the authenticationTXTrecords. They are different records for different jobs.
Troubleshooting
| Symptom | Cause | Fix |
|---|---|---|
| Health report shows SPF missing after you added it | DNS has not propagated, or the record is not on the root domain | Confirm the TXT record is on the root domain and starts with v=spf1. Wait a few minutes, then refresh. |
| Health report warns about a missing Google include | Your SPF record does not authorize Google | Add include:_spf.google.com to your single SPF record. Do not add a second record. |
| Health report shows more than one SPF record | Two TXT records both start with v=spf1 | Merge them into one record and delete the extra. |
| Health report shows DKIM not found although it is on | Your DKIM selector is a custom name the scan does not probe | Confirm signing is active in the Admin console. The scan checks common selectors only, so a custom selector may not be detected. |
| DKIM never starts authenticating | The TXT record was not published, or authentication was not started | Publish the record Google gave you, wait for propagation, then click Start authentication in the Admin console. |
| Health report shows DMARC present but flags a warning | The policy is none, coverage is below full, or there is no report address | Add a rua= address, ensure full coverage, and move the policy toward quarantine once your mail passes. |
| Records look correct but still fail | You are checking before propagation, or a cached old record is still live | Wait for the record's cache time to expire, then refresh the domain health scan. |
FAQ
Do I need all three records? Yes. SPF, DKIM, and DMARC each prove something different. Together they give receivers the strongest signal that your mail is genuine.
Why must my SPF include Google?
Tantra sends your cold email through your own Google Workspace mailboxes with the Gmail API. Google's servers do the sending, so your SPF record has to authorize them with include:_spf.google.com.
Where do I turn on DKIM?
In the Google Workspace Admin console, under Apps, then Google Workspace, then Gmail, then Authenticate email. Google generates the key, and you publish it as a TXT record.
What DMARC policy should I start with?
Start with p=none and a rua= report address. It monitors without affecting delivery. Move to quarantine, then reject, once your reports confirm your mail passes.
How long until my records take effect? DNS changes can take a few minutes to a few hours to propagate. If a record reads as absent right after you add it, wait and check again.
I added a record but the health report still shows it missing. Why? The scan runs once a day and may not have re-checked yet, or DNS has not propagated. Trigger an on-demand refresh, and confirm the record type and host name are correct.
Is the tracking domain the same as these records?
No. A custom tracking domain is a CNAME record for click links. SPF, DKIM, and DMARC are TXT records for authentication. They are separate. See set up a custom tracking domain.
Related articles
Was this article helpful?
Related articles
- Domain health reports (SPF, DKIM, DMARC)Understand how Tantra scans your sender domains daily for SPF, DKIM, DMARC, and blocklist problems, and how to read the health status and score.
- Set up a custom tracking domainAdd a CNAME subdomain, verify it, and set it as your default so tracked email links carry your own branding instead of the shared domain.
- Warm up your sending mailboxesWarm up new Gmail mailboxes in Tantra with a gradual peer-to-peer ramp that builds sending reputation before you run cold email at volume.