You're staring at your email dashboard. Campaign is live. Copy is solid. Your list is clean. But your delivery rate is in the toilet - bounces, spam folder placements, authentication failures.
And you have no idea why.
This is one of the most frustrating moments in cold email. You've done the work. The infrastructure feels right. But something's broken in the background, and it's costing you deals.
The culprit? Almost always email authentication.
What Email Authentication Actually Is
Before we dig into why it's failing, let's be clear about what we're talking about.
Email authentication is basically proof that you own the domain you're sending from. It's a system that says: "Yes, this person really does have permission to send emails on behalf of example.com."
Without it, email providers treat your messages like spam. Which they kind of are, from their perspective - unverified mail from an unknown sender.
There are three main types:
- SPF (Sender Policy Framework) - Tells receiving servers which IP addresses are allowed to send from your domain
- DKIM (DomainKeys Identified Mail) - Adds a digital signature to your emails so they can't be forged
- DMARC (Domain-based Message Authentication, Reporting and Conformance) - Sets the policy for what happens when SPF or DKIM fails
All three need to be set up correctly. If even one is broken, your delivery suffers.
Why Your Authentication is Probably Failing
You Haven't Set Up SPF Correctly
This is the most common mistake. You added an SPF record, but it's either incomplete or conflicting.
Here's what happens: You're using multiple sending services - maybe your cold email platform, a transactional email service, and your regular email client. Each one needs to be listed in your SPF record.
If you forget one, or if the records conflict, SPF fails. Receiving servers see the discrepancy and downrank your mail.
Another issue - SPF records have a lookup limit of 10. If you have too many services trying to send from your domain, you'll exceed that limit and SPF breaks entirely.
Your DKIM Keys Are Misconfigured
DKIM requires you to generate a public key (goes in your DNS) and a private key (stays with your email provider). If these don't match, or if one is missing, DKIM authentication fails.
This often happens when you switch sending platforms. You set up DKIM with your first provider, then add a second platform without properly adding its DKIM record. Now both are signing your emails, and one of them fails validation.
The fix is tedious but straightforward - you need to add a separate DKIM record for each sending service.
Your DMARC Policy is Too Strict
DMARC is the enforcer. It says: "If SPF or DKIM fails, here's what you do with the email."
A lot of people set DMARC to "reject" immediately. That sounds secure, but it's dangerous when you're still debugging. If anything fails - even temporarily - legitimate emails get rejected before they reach the inbox.
The right approach is to start with "none" (monitor only), then move to "quarantine" (send to spam folder), then eventually "reject" once everything is stable.
You're Using a Subdomain Without Proper Setup
Many cold email platforms recommend sending from a subdomain like mail.yourcompany.com instead of yourcompany.com. That's solid advice for protecting your main domain reputation.
But if you set up SPF, DKIM, and DMARC only on your main domain, the subdomain has no authentication. It fails immediately.
You need to set up authentication records on the subdomain separately. This includes a separate DKIM key just for that subdomain.
Your DNS Changes Haven't Propagated Yet
DNS updates don't happen instantly. They can take up to 48 hours to fully propagate across the internet, though usually it's much faster.
If you just set up your authentication records, you might be testing too soon. Give it at least a few hours before you send campaigns.
Check propagation status with tools like MXToolbox or DNSChecker. Don't start sending until everything shows green.
How to Diagnose the Problem
Don't guess. Test your setup.
- Use MXToolbox. It's free and shows you exactly what's wrong. Check SPF, DKIM, and DMARC all at once. You'll see what's missing or misconfigured
- Send a test email to yourself. Open it in Gmail, click the three dots, and select "Show original." Look for SPF, DKIM, and DMARC pass/fail indicators. This is ground truth
- Check your sending platform's setup guide. Most have specific instructions for SPF and DKIM records. Follow them exactly - don't improvise
- Ask your email provider's support team. They can verify your records are correct on their end and flag any conflicts they see
The Nuclear Option: Start Fresh
If you've been troubleshooting for days and nothing's working, sometimes the fastest fix is to start over with a fresh subdomain.
Create mail2.yourcompany.com. Set up authentication from scratch, carefully. Test it thoroughly. Once it's stable and delivering, move your campaigns over.
This sounds like a step backward, but it's often faster than debugging years of accumulated misconfiguration.
The Reality Check
Email authentication is technical, but it's not rocket science. The issue is that it requires precision - one typo, one missing record, one forgotten service, and the whole thing breaks.
For agencies and service businesses running cold email campaigns, this is exactly where things fall apart. You're focused on leads and revenue. Instead you're stuck in DNS records and propagation windows.
That's why a lot of successful cold email operators don't handle infrastructure themselves. They work with teams that specialize in it - teams that have already solved these problems dozens of times, know exactly what to look for, and can fix issues in hours instead of days.
If authentication troubleshooting is pulling you away from what actually matters - selling - it might be worth asking whether you should be doing it at all.