Help Center

Docs

Domain Setup

Authenticate your sending domain with SPF, DKIM, and DMARC, and understand how tracking domains work

Why Domain Authentication Matters

Authenticated domains land in inboxes; unauthenticated ones land in spam.

Mailbox providers decide whether your cold email reaches the inbox largely by checking whether the sending domain is authenticated. Cold Outreach gates sending behind a domain preflight: a sequence cannot launch from a mailbox whose domain has not passed the SPF, DKIM, and DMARC checks. This protects both your deliverability and the reputation of every other sender on Laureo.

SPF, DKIM, and DMARC

The three DNS records every sending domain needs.

FieldDescription
SPFA DNS TXT record that lists which servers are allowed to send mail for your domain. It tells receivers your sending mailbox provider is authorized.
DKIMA cryptographic signature published in DNS that lets receivers verify the message was not altered and genuinely came from your domain.
DMARCA policy record that tells receivers what to do when SPF or DKIM fails, and where to send alignment reports. Start with a monitoring policy before tightening.

Your mailbox provider (Google Workspace or Microsoft 365) publishes the exact record values you need. Add them at your DNS host, then return to the Mailboxes tab and run the preflight. The check passes once all three records resolve and align.

New records usually work within about 10 minutes. Some DNS hosts can take up to 48 hours. If the check still reports a missing record right after you added it, that is usually propagation rather than a mistake in the record.

The check runs when you connect the mailbox, and every time you press Re-check now on its card. Opening the Mailboxes tab also re-runs it quietly for your own mailboxes whose last result is more than a day old, so a domain that loses a record while you are not looking does not keep a passing badge indefinitely. Nothing else re-checks on its own.

The preflight is a hard gate
Sending is blocked until the domain authenticates. If the preflight reports a missing or misaligned record, fix the record at your DNS host and re-run the check. There is no way to launch a cold sequence from an unauthenticated domain.

Use a Secondary Domain for Cold Outbound

Protect your primary domain's reputation.

For cold outbound, the recommended practice is to send from a secondary domain, a lookalike of your primary domain set up specifically for outbound, rather than your main company domain. This keeps any deliverability impact off the domain your team uses for everyday email and transactional mail. If you connect a mailbox on your primary domain, Cold Outreach surfaces a hard warning so the choice is deliberate.

Custom Tracking Domain

Tracking needs a domain you own, and setting one up is not switched on yet.

Open and click tracking on cold sequences needs a tracking domain you own and have verified. There is no standard tracking host behind it today, so until a domain of your own is verified the two tracking switches on a sequence stay inert and launching with them on is refused. Setting a tracking domain up is not switched on yet either, so the card in outreach settings currently reads that custom tracking domains are not available and shows no field and no button. If a standard host is ever switched on, a domain you own and have verified still wins over it, so the links your recipients see stay on a domain they recognize.

When the setup flow is switched on, the card grows a field and an Add tracking domainbutton, and moving tracked links onto your own domain runs like this:

  1. Choose a tracking subdomain (for example, link.yourdomain.com), never your root domain.
  2. Add the CNAME record Laureo shows you at your DNS host.
  3. Return to outreach settings and verify the domain.
  4. Once verified, enable tracking on your sequences.
Tracking is optional
Opens and clicks stay off by default on every cold sequence, because tracking pixels and rewritten links can hurt cold deliverability. You can run cold sequences with tracking off and reply based metrics still work. Turning tracking on adds open and click signals to your cold outreach analytics. It does not fire the opened or clicked triggers in Automations: those triggers read campaign email sent to your contacts, and a cold lead is not a contact until you promote it.

Who can set a tracking domain up

Setting one up is a plan feature. Serving links from one is not.

Adding, verifying, retiring, or replacing a tracking domain is a plan feature, and only a teammate with organization-wide outreach access can do it. Everyone else sees the same card in read-only form.

Once a domain is verified, it keeps serving links on every plan. If your plan changes later, campaigns and sequences that already use the host carry on using it, and the one-click unsubscribe header keeps pointing at the same place. Only the ability to change the setup follows the plan. That is deliberate: a billing change should never move the links in mail that has already been delivered.

Retiring a tracking domain

Removing a domain retires it. Keep the DNS record published for 30 days.

The card action is Retire. It takes two clicks: the first arms a warning, the second confirms. Retiring turns open and click tracking off for every sequence in the organization straight away. A campaign that had already frozen the host carries on using it for the rest of its sends, which is why the CNAME record has to stay published.

  • Leave the CNAME record published. Unsubscribe links in mail you already sent resolve through that record. The card shows the date to keep it until, which is 30 days after the last send that used the host.
  • The domain stays claimed by your organization. Retiring does not release the name, so nobody else can pick up a host whose record still points at us and send mail branded with it.
  • You can restore it. The retired card carries a Restore action that brings the same host back as pending. Check the record is still published, then verify it again.
  • You can set up a different one instead. The retired card also shows the add form. Adding a new host retires the old one for you, so changing domains is one step and there is no limit on how many times you can do it.