SPF, DKIM and DMARC record generator.
Build the three DNS records mailbox providers now check before they trust your mail. Pick your setup, copy the records, paste them into your DNS. No signup, nothing leaves your browser.
Which services send email for you?
Tick every provider you send from. One SPF record covers them all.
A domain can only have one SPF record. If you already have one, merge these mechanisms into it rather than adding a second.
Why authentication decides whether cold email works
In February 2024 Google and Yahoo drew a line: send in volume without SPF, DKIM and DMARC and your mail gets filtered or bounced. Every other provider has moved the same way. For cold outreach that is brutal, because you are a stranger to the recipient and their server has no reason to give you the benefit of the doubt. These three records are how you earn it.
The generator above gives you correct records to paste in. That clears the first gate. The second gate is reputation, and no DNS record fixes that for you. Sending 5,000 cold emails a day from one freshly bought domain will still get you filtered, authenticated or not.
HotHawk runs the part authentication cannot
Under every campaign, HotHawk warms your mailboxes on real Google and Microsoft inboxes, rotates sending across many of them so no single inbox carries the load, and holds each one to a sensible daily volume. That is the sending infrastructure that lets you push 40,000 emails a day and more while your domains stay healthy. Get your records right here, then send from a system built to protect them.
No credit card required.
Frequently asked
What are SPF, DKIM and DMARC?
They are the three DNS records that prove your email is really from you. SPF lists which servers are allowed to send for your domain. DKIM adds a cryptographic signature that survives forwarding. DMARC tells receiving servers what to do when a message fails those checks, and where to send reports. Together they are the baseline every mailbox provider now expects before it trusts your mail.
Do I really need all three?
Yes. Since February 2024, Google and Yahoo require SPF, DKIM and a DMARC record for anyone sending in volume, and other providers have followed. Missing any one of them is now a fast route to the spam folder. For cold outreach, where you have no prior reputation with the recipient, authentication is not optional.
Where do I put these records?
In your domain’s DNS, wherever you manage it: Cloudflare, GoDaddy, Namecheap, Google Domains and so on. Each one is a TXT record. This tool gives you the exact host and value to paste. Changes usually take effect within an hour, though DNS can take up to 48 hours to fully propagate.
Can I generate a DKIM key here?
Yes. The DKIM tab generates a 2048-bit key pair right in your browser using the Web Crypto API, so the private key never leaves your machine. Publish the public key as a TXT record and install the private key in your mail server. If you send through Google Workspace or Microsoft 365, they generate the key for you in their admin console instead, and the tab explains that path too.
Will these records get my cold email into the inbox?
They are the entry ticket, not the whole show. Authentication stops you being rejected outright, but reaching the inbox at scale also depends on warmed mailboxes, sensible per-inbox volume and a clean sending reputation. HotHawk runs that side: authenticated domains, warmup on real inboxes, and inbox rotation so no single mailbox gets burned.
More free tools
Updated 12 July 2026