Authenticate your sending domain with SPF, DKIM, and DMARC, and configure a custom tracking domain
Authenticated domains land in inboxes; unauthenticated ones land in spam.
Mailbox providers decide whether your cold email reaches the inbox largely by checking whether the sending domain is authenticated. Cold Outreach gates sending behind a domain preflight: a sequence cannot launch from a mailbox whose domain has not passed the SPF, DKIM, and DMARC checks. This protects both your deliverability and the reputation of every other sender on Laureo.
The three DNS records every sending domain needs.
| Field | Description |
|---|---|
| SPF | A DNS TXT record that lists which servers are allowed to send mail for your domain. It tells receivers your sending mailbox provider is authorized. |
| DKIM | A cryptographic signature published in DNS that lets receivers verify the message was not altered and genuinely came from your domain. |
| DMARC | A policy record that tells receivers what to do when SPF or DKIM fails, and where to send alignment reports. Start with a monitoring policy before tightening. |
Your mailbox provider (Google Workspace or Microsoft 365) publishes the exact record values you need. Add them at your DNS host, then return to the Mailboxes tab and run the preflight. The check passes once all three records resolve and align.
Protect your primary domain's reputation.
For cold outbound, the recommended practice is to send from a secondary domain— a lookalike of your primary domain set up specifically for outbound — rather than your main company domain. This keeps any deliverability impact off the domain your team uses for everyday email and transactional mail. If you connect a mailbox on your primary domain, Cold Outreach surfaces a hard warning so the choice is deliberate.
Open and click tracking for cold sequences requires your own CNAME.
Open and click tracking on cold sequences is served from a custom tracking domain that you own — a subdomain you point at Laureo with a CNAME record. Until you configure and verify a tracking domain, tracking stays off for cold sends. Tracking links and the unsubscribe footer are then built on your verified tracking host, which keeps the links on a domain receivers recognize as yours.
link.yourdomain.com).Setting one up is a plan feature. Serving links from one is not.
Adding, verifying, retiring, or replacing a tracking domain is a plan feature, and only a teammate with organization-wide outreach access can do it. Everyone else sees the same card in read-only form.
Once a domain is verified, it keeps serving links on every plan. If your plan changes later, campaigns and sequences that already use the host carry on using it, and the one-click unsubscribe header keeps pointing at the same place. Only the ability to change the setup follows the plan. That is deliberate: a billing change should never move the links in mail that has already been delivered.
Removing a domain retires it. Keep the DNS record published for 30 days.
The card action is Retire. It takes two clicks: the first arms a warning, the second confirms. Retiring turns open and click tracking off for every sequence in the organization straight away. A campaign that had already frozen the host carries on using it for the rest of its sends, which is why the CNAME record has to stay published.