The unglamorous layer under every outbound campaign: DNS authentication records, a separate sending domain, a custom tracking domain, and a warm-up plan. Configured, verified against real test sends, and documented so you can prove it is correct later.
Gmail and Yahoo stopped treating authentication as a recommendation. If your sending domain cannot prove who it is, filtering happens before a human ever sees the subject line, and no amount of rewriting the first sentence changes that.
This is a one-time infrastructure job, not an ongoing campaign service. I set the records, verify them with real sends into seeded inboxes, and hand you a document showing what each record does and how to check it still passes in six months.
Three DNS records, one sending domain, one tracking domain, and a verified test send. That is the whole job when it is done properly.
| Item | What gets done |
|---|---|
| Audit | Current SPF, DKIM and DMARC state checked, plus blacklist and reputation lookups on your domain and IP |
| SPF | A single valid record listing every legitimate sender, kept under the DNS lookup limit |
| DKIM | Key generated at the sending provider, published, and verified as signing correctly |
| DMARC | Policy published with reporting address, starting at monitor and tightened once alignment is confirmed |
| Sending domain | A separate outbound domain configured so campaigns cannot damage your primary domain's reputation |
| Tracking domain | Custom CNAME tracking subdomain, so links do not point at a shared provider domain |
| Provider setup | Mailgun, SMTP or your existing platform connected, with bounce and complaint handling enabled |
| Warm-up plan | A written volume ramp over the first weeks, with the metrics that say pause or continue |
| Verification | Real test sends to seeded inboxes across major providers, with headers checked for pass on all three records |
Mailgun sending domain with SPF, DKIM and DMARC configured and verified end to end for outbound campaigns.
What comes nextOnce mail lands, replies need triage: intent classified and a CRM opportunity opened automatically.
A written report on your current authentication, reputation and blacklist status, with the exact records to fix it.
1–2 daysRecords published and verified, sending and tracking domains configured, provider connected, warm-up plan delivered.
3–5 daysSeveral sending domains and mailboxes provisioned for volume outbound, each authenticated and warmed separately.
1–2 weeksDNS propagation adds up to 48 hours outside my control, so timelines above assume it. The full explanation of what each record does lives in why your cold email goes to spam, including the setup steps if you would rather do it yourself.
Book a free 15-minute call and I will check your current SPF, DKIM and DMARC records live on the call and tell you what is missing. It takes about four minutes.
Book a free 15-minute call →Most often authentication. If SPF, DKIM and DMARC are missing or misaligned, major providers treat the message as unverified before anyone reads a word of it. Content filtering happens after authentication.
Plan for two to four weeks on a new domain, starting at low daily volume and increasing gradually while watching reply and bounce rates. Sending at full volume on day one from a fresh domain is the fastest way to burn it.
No. Use a separate but similar sending domain, so damaged outbound reputation does not take your invoices, quotes and internal mail with it. The main domain keeps a strict DMARC policy and stays out of campaigns.
It removes the ceiling on it. Authentication decides whether your message is eligible to be read; the offer and the list decide whether it gets a reply. Fixing DNS on a bad list changes nothing.
Yes. The DNS and authentication layer is the same whether you send through Mailgun, a dedicated cold email platform, Google Workspace, or a CRM's built-in sender.