How to Set Up the Domain Authentication in Marketing Cloud Next An authenticated domain is what allows your email campaigns to land in your recipient's inbox instead of their spam folder. In Agentforce Marketing, emails are sent from a subdomain rather than your root domain — which is a deliberate best practice, because email service providers like Gmail and Outlook evaluate domain reputation independently, and using a dedicated subdomain protects your main domain from being impacted by email marketing activity. This guide walks through the full process: navigating to Email Setup in Assistant Home, adding your subdomain via Authenticated Domains, creating your first email address on that domain, and then updating the DNS records at your domain registrar (GoDaddy, Hostinger, Crazy Domains, etc.) to validate the authentication. This is a prerequisite for everything else in the email channel — From Addresses, Reply Mail Management, and sending campaigns all depend on it. Link in comments.
Email Authentication
Explore top LinkedIn content from expert professionals.
-
-
1. SPF (Sender Policy Framework) 🔹 Purpose: Prevents spammers from sending messages on behalf of your domain. 🔹 How it works: The domain owner publishes a list of IP addresses (in DNS) allowed to send emails from that domain. Receiving servers check if the email’s sending server is on the list. 🔹 Pass/Fail Decision: If it’s not on the list, SPF fails. ✅ Good for: Detecting forged sender addresses in the envelope. 2. DKIM (DomainKeys Identified Mail) 🔹 Purpose: Ensures that the content of the email hasn’t been altered. 🔹 How it works: The sender’s server adds a digital signature (private key) to email headers. The receiver verifies the signature using a public key stored in DNS. 🔹 Pass/Fail Decision: If the signature matches, the email is valid. ✅ Good for: Verifying message integrity and authenticity. 3. DMARC (Domain-based Message Authentication, Reporting, and Conformance) 🔹 Purpose: Combines SPF and DKIM to enforce domain policies. 🔹 How it works: Domain owners publish a policy in DNS (e.g., reject/quarantine unauthenticated emails). DMARC checks if the email passes SPF or DKIM and if the domain in the "From" address aligns. 🔹 Reports: Domain owners get reports on who is sending mail on their behalf. ✅ Good for: Domain protection and visibility into email spoofing attempts.
-
📧 Most M365 admins still don't know this exists. You can send emails directly from an Alias in Microsoft 365 — no extra mailbox, no extra license. Here's everything you need to know. 👇 🤔 What's the problem it solves? Before this feature, if you wanted users to send from addresses like: support@company.com sales@company.com noreply@company.com You had two painful options: ❌ Create a shared mailbox for each one (licensing cost) ❌ Use "Send As" delegation (complex permissions) There's now a better way. ✅ ⚡ Enter: Send From Alias Released by Microsoft in April 2021, refined in early 2022 — and still flying under the radar for most IT admins. Why it's a game-changer: → No shared mailboxes needed → Zero extra licensing cost → Perfect for multi-domain organizations → Cleaner branding for support, sales & project teams → Works across Outlook, OWA & mobile — natively ⚙️ Enable it in just 2 PowerShell commands: { powershell Connect-ExchangeOnline Set-OrganizationConfig -SendFromAliasEnabled $True } That's it. Seriously. 📌 Important caveats: → Exchange Online only — not for On-Premises → Feature may be disabled by default on older tenants → Aliases must already be added to the user's mailbox ✅ After enabling, your users can: → Select any alias as the "From" address in Outlook → Manage multiple email identities from one mailbox → Eliminate unnecessary mailbox sprawl across your tenant 🔖 For the full step-by-step setup guide, check out Ali Tajran's detailed walkthrough here → https://lnkd.in/g-aHHFVD #Microsoft365 #ExchangeOnline #M365Admin #ITAdmin #CloudComputing #MicrosoftExchange #EmailManagement #PowerShell #SysAdmin #ITOperations #MicrosoftTips #TechTips #Azure #ITInfrastructure #DigitalWorkplace
-
It’s official: email best practices are no longer best — they’re required. Here’s why... Microsoft recently announced new bulk sender requirements that mirror the ones Google and Yahoo rolled out last year. And they aren’t just doing this for fun, promise. They’re doing it because too many senders ignored best practices when they were optional. So, now they’re mandatory. ¯\_(ツ)_/¯ Starting May 5th, if you’re sending more than 5,000 emails a day and not following the rules, Microsoft’s going to start rejecting your mail. Not junking it. Rejecting it. And I wanna be clear here: this isn’t coming out of nowhere. The writing’s been on the wall for a while... and mail has been silently filtered away from the inbox all this time. Now it's just that the rules aren't written in invisible ink! So, what are these rules I speak of? 💌 Authentication (SPF, DKIM, DMARC) Yes, we’re still talkin’ about this… get used to it. Microsoft wants the same setup Google and Yahoo asked for. If your domains aren’t properly authenticated and aligned, your deliverability will suffer. 💌 Valid “From” and “Reply-To” Addresses Microsoft wants to make sure that when someone replies to your message, there’s someone on the other end. No more sending from a “noreply@brand.com” black hole. 💌 One-Click Unsubscribe (RFC 8058) They’re cracking down on bad unsubscribe flows. Make it easy. No weird hoops or loops or “oops, we need 10 days to process your request.” Just a simple unsubscribe option that actually works. If you’re already sending it right (ahem, compliant with Google and Yahoo’s requirements), this is mostly a “cool, cool, carry on” moment. But you’ll need a whole lotta margaritas and tacos to overcome your sorrow if you’ve been dragging your feet. May 5th (ahem, cinco de mayo!) is not the day to find out Microsoft doesn’t play. What happens if you’re not ready? If you need help figuring out where you stand, here are a few fast checks: ✅ SPF, DKIM, and DMARC passing in headers? ✅ “Reply-To” address monitored and functioning? ✅ One-click unsubscribe live and working? ✅ Lists clean and bounce/spam complaint rates under control? If not, now’s the time to fix it. Not next week. Not next quarter. Now. TLDR: if you’re not sending responsibly, you’re not sending at all. Because come Monday — yes, THIS Monday — non-compliant mail will be rejected at the door. No inbox. No spam folder. Just blocked. So, get it together, you (not so) filthy animals! LinkedIn says I’m outta characters, but if you need tool recommendations or a second set of eyes on your setup, I'm happy to help. Reach out, email scout. 💌
-
We send 800k+ emails a month, and I have spent the last 2 years understanding every reason for emails landing in spam. Today, I am sharing all the good resources I found during this journey! Most emails don’t get blocked because you’re a spammer. They get blocked because you missed one tiny config buried in a 20-year-old spec. Email delivery feels a little like a black box! Old docs, conflicting advice, and invisible rules. So sharing the list I wish I had when we started. 1. LearnDMARC (learndmarc.com) - An interactive visualizer that makes SPF, DKIM, and DMARC simple and easy to understand. 2. Postmark’s “Why Emails Go to Spam.” - The clearest explanation of sender reputation, content filters, and engagement signals. 3. MXToolbox - Debug SPF/DKIM/DNS issues 4. Mail-tester.com - Send a test email, get a deliverability score. My go-to before every big template change. 5. Google Postmaster Tools - Gmail’s own dashboard for domain reputation. No more guessing. 6. RFC 5321 (SMTP spec) - Yes, this feels intimidating. But even skimming it gave me massive clarity on how email really works. 7. Spamhaus blog: Word to the Wise - Insights on sender reputation straight from the people who run the biggest blocklists. This is one of the best blogs I have found on the internet! Email isn't glamorous. But it’s critical infrastructure. And most of the knowledge is scattered across forums and old blog posts. If you’re building anything that sends email, save this! It’ll save you a loooot of time debugging!
-
I thought great copy was the secret to cold email. Then I realized 80% of my emails were landing in spam. Here’s what we found: 1️⃣ Domain protection is the #1 lever for deliverability → Most teams burn their main domain without realising it. Once a domain is flagged, everything gets filtered (even normal emails). We run 100+ secondary domains to protect our brand and reduce risk. Tool stack: Google Workspace, Namecheap, Warmup tools Next step: Move every outbound sequence off your primary domain. 2️⃣ Safe volume beats high volume → Sending 500 emails/day from one domain is the fastest path to spam. Deliverability collapses instantly. We spread volume across hundreds of mailboxes and stay under 40/day for each. Impact: Fewer red flags, higher trust, better inbox placement. Next step: Audit how many sends each domain is doing right now. 3️⃣ Authentication is non-negotiable → SPF, DKIM, and DMARC are the foundation ESPs check before letting anything through. Without proper authentication, you look suspicious by default. Tools: dmarcian, Google Admin, Cloudflare Next step: Run a deliverability test and fix whatever shows up in red. 4️⃣ Warm-up → Most domains get burned because people start sending too early. ESPs need time to trust you. We warm each domain for two full weeks before sending anything. Why it works: Slow ramp-up = better deliverability. If you just bought a domain, don’t touch it for 14 days. 5️⃣ Natural variation reduces spam triggers → Sending the same message repeatedly creates patterns that ESPs flag. You need micro-variation to look human. We use subtle spintax + a few message versions per campaign. Tools: Instantly.ai, Smartlead Next step: Add small variations to your first lines and CTAs. 6️⃣ Clean tracking protects your domain reputation → Tracking links are an instant red flag. Most agencies don’t realize this. We use custom tracking domains or disable tracking entirely for key campaigns. Next step: Replace all generic tracking links. The results: → 500,000+ emails/month reaching real decision-makers → Higher inbox placement across every ESP → Predictable revenue for ColdIQ clients → Stable domain health across all mailboxes Deliverability isn’t the flashy part of outbound, but it’s the part everything else depends on. If you want our 7-day GTM deliverability setup (domains, warm-up, templates, monitoring tools)... drop me a message, happy to help.
-
If you’re still sending email from an onmicrosoft.com address, Microsoft is tightening the rules. This matters because your messages could start getting throttled or blocked, which means invoices, password resets, and customer updates might never arrive. Microsoft’s goal is to stop spammers who spin up fresh tenants and abuse the shared onmicrosoft.com domain. But the side effect is real organizations will see lower deliverability and limits on bulk or automated sends until they move to a proper, verified domain. What’s changing? Microsoft is putting sending limits and stricter checks on any email that leaves an onmicrosoft.com address. Because it’s a shared domain used by millions, one bad actor can hurt the reputation for everyone. The fix is simple but urgent: switch to your own branded domain and set up modern email authentication (SPF, DKIM, and DMARC). That tells receiving mail systems, “Yes, this is really us,” and helps keep your mail out of spam and off block lists. What should you do now? Audit where onmicrosoft.com shows up—service accounts, no-reply inboxes, ticketing tools, scanners, CRM alerts, and scripts. Register or connect your custom domain, add the DNS records, and rotate apps and automations over to the new addresses. Test mail flow, watch for bounce backs, and update address books, forms, and templates. Train your team so they know which sender addresses are approved going forward. A little cleanup today will save a lot of missed messages tomorrow. #Microsoft365 #EmailSecurity #ITAdmin #ChangeYourPassword Follow me for regular updates on Microsoft 365 changes, security tips, and clean-up checklists that keep your org’s email flowing.
-
Using HubSpot for marketing emails? When's the last time you verified your domain authentication on HubSpot? I can't tell you how many times I've seen this overlooked. I consistently find it not authenticated in accounts. Here's what happens when your domain isn't properly authenticated: • Your deliverability tanks • Emails hit spam folders instead of inboxes • Your sender reputation takes a hit • You're burning budget on emails nobody sees The fix takes minutes. Go to Settings → Content → Domains & URLs Check for these three things: 1. SPF record (green checkmark) 2. DKIM record (green checkmark) 3. DMARC policy (configured) If you see red X's or warnings, fix them today. Your IT team can help if you're not sure how to update DNS records. HubSpot's documentation walks through it step by step. Don't let a simple technical oversight kill your email performance. Check it now. Your campaigns will thank you.
-
Stop using your company's primary domain for cold outreach. Here's why that's killing your deliverability (and your brand): Your main domain is your reputation. It's where your team communicates. Where customers email you. Where partners reach out. One bad cold email campaign can torch that reputation. Forever. When you cold email from your main domain: → Every bounce damages sender reputation. → Every spam complaint hurts your primary domain. → Every risky campaign puts your whole company email at risk. Then one day, your CEO's emails start landing in spam. Your support team's responses get filtered. Your invoices disappear. All because you tried to save $12/year on a separate domain. The better approach is to buy a secondary domain for cold outreach. Similar to your main domain, but slightly different. • Main: company.com → Cold: getcompany.com • Main: acme.com → Cold: acmeteam.com • Main: brand.com → Cold: trybrand.com Keep them related but separate. → Your main domain stays clean. If something goes wrong with cold email, your primary communications are protected. → You can test aggressively. Try new campaigns. Scale quickly. Without risking your core business operations. If a cold domain gets flagged, you can switch to a new one without touching your main brand. "But people won't trust emails from a domain they don't recognize!" If your cold email is good, they won't care. They care about the value you're offering, not whether you're using .com or .io. And if they do care that much, they weren't going to respond anyway. The setup: 1️⃣ Buy a secondary domain ($12-15/year) 2️⃣ Set up proper DNS records (SPF, DKIM, DMARC) 3️⃣ Warm it up for 2-3 weeks before sending 4️⃣ Keep your sending volume conservative 5️⃣ Monitor deliverability separately from your main domain The cost of not doing this: One bad campaign. One blacklist. One spam complaint spiral. Your entire company's email reputation destroyed. Is that worth saving $12/year? Separate your domains. Protect your brand. Are you using a separate domain for cold outreach? Or risking your main domain?
-
100+ cold email stacks audited. Every one under 5% reply broke on the same 10 things. SURBL wasn't one of them. Everyone's panicking about the SURBL blacklist. Our audit says it's not why your emails are in spam - it just exposed the fundamentals that were already broken. Here's the 10-point checklist: 1. Monitor inbox placement weekly ↳ Don't assume you're landing. Validity tracked 16.5% of legit B2B email going to spam in 2026 ↳ Test placement weekly (GlockApps, MailReach, or your sequencer's built-in tool) ↳ Stop guessing. Test the actual placement 2. SPF, DKIM, DMARC ↳ Not optional. Skip it and your spam rate spikes within 2-3 weeks ↳ Run a check with MXToolbox before the next campaign 3. Move DMARC from p=none to p=reject within 90 days ↳ Most teams set p=none and never enforce. Providers flag domains stuck there ↳ p=quarantine after 30 days, p=reject after 90. p=none is the parking spot 4. Secondary domains only, never your primary ↳ Cold sending from your primary is how you burn the domain your business runs on ↳ Buy secondaries. Space the purchases across registrars and days, no same-day batches 5. 2 inboxes per secondary domain ↳ Too many senders on one domain gets it flagged ↳ Want 10 inboxes? That's 5 domains, not 1 domain with 10 mailboxes 6. Warm up 2-4 weeks before the first cold send ↳ A new domain sending 50 cold on day one is a death sentence ↳ Bare minimum 2 weeks. Ideal 3-4. There's no shortcut 7. 5-20 cold emails per inbox per day, no spikes ↳ 200 Monday and 20 Tuesday flags you faster than a steady 20 a day ↳ Consistent low volume beats spikes that burn inboxes 8. Bounce rate under 2% ↳ Above 2% and Gmail starts flagging. Verify 100% of the list before sending ↳ Re-validate any list older than 30 days. Always 9. Plain text only. No HTML, no images, no tracking pixels ↳ HTML reads as marketing to the filters. One image raises your spam rate ↳ If you wouldn't type it as a Slack DM to a coworker, don't send it cold 10. Domain age + clean registration ↳ Nothing under 30 days old in a live campaign ↳ No hyphens, no .net or .info, no bulk buys from a single registrar flagged for abuse Here's what the SURBL scare actually taught us: the teams that panicked had no infrastructure discipline to begin with. The ones who audit weekly barely felt it. SURBL didn't break your deliverability. It just found the cracks that were already there. Infrastructure is 99% of your results. If you're in spam, the copy and the offer don't matter. What's your average bounce rate, spam rate, and inbox placement right now? If you don't know all three, that's the real problem. Repost if someone else needs this ♻
Explore categories
- Hospitality & Tourism
- Productivity
- Finance
- Soft Skills & Emotional Intelligence
- Project Management
- Education
- Technology
- Leadership
- Ecommerce
- User Experience
- Recruitment & HR
- Customer Experience
- Real Estate
- Marketing
- Sales
- Retail & Merchandising
- Science
- Supply Chain Management
- Future Of Work
- Consulting
- Writing
- Economics
- Artificial Intelligence
- Employee Experience
- Healthcare
- Workplace Trends
- Fundraising
- Networking
- Corporate Social Responsibility
- Negotiation
- Engineering
- Career
- Business Strategy
- Change Management
- Organizational Culture
- Design
- Innovation
- Event Planning
- Training & Development