Email Authentication for Online Stores: How Gmail Knows Your Email Is Real

Read summarized version with
Summary
- What it answers: What email authentication is, explained as a guest list, a seal and an instruction to the doorman.
- Why it matters: Gmail, Yahoo and Outlook.com require it from bulk senders, and Black Friday is when a store's volume is most likely to cross that line.
- How to fix it: If you send with SmartrMail, it generates the records and Entri can add them for you. Then run the two-minute Gmail check and the checklist before your BFCM sends.
A Black Friday email that lands in spam doesn't sell anything. Missing email authentication is one cause you can fix yourself, and the time to fix it is before November.
Email authentication means three short records on your store's domain, called SPF, DKIM and DMARC. They let Gmail, Yahoo and Outlook check that an email really came from you. If you send marketing email from your own domain, this is for you, and your email platform supplies the records. One honest caveat: authentication gets you considered for the inbox. It doesn't guarantee it.
What Is Email Authentication?
Think of Gmail as the doorman at a private event. Every email is a guest who says it comes from your store, and that claim is the From address your customer sees. The doorman runs three checks.
SPF is the guest list. It lists the servers allowed to send email for a domain, like your email platform and Shopify. One catch: SPF checks the guest list of whichever domain is in the email's return address, the hidden address bounces go back to, and that isn't always your From address.
DKIM is the tamper-evident seal. Your email platform seals each email with a digital signature, and the doorman checks it against a key published by the domain that made it. A seal that doesn't check out means the message changed on the way or wasn't sealed with that key.
DMARC is your instruction to the doorman. A guest is cleared when at least one check passes for a name that matches your From address. For a guest who fails both, DMARC says what to do: let them in and note it, send them to spam, or turn them away. It also asks for reports on who has used your name.
That match explains how a store can set up "everything" and still fail. Many platforms put their own domain in the return address and on the seal. Both checks pass for the platform's name, not yours, so neither counts for DMARC. The match is called alignment, and it's why you send from your own domain.
If You Send With SmartrMail: The Short Path
SmartrMail generates the records for your sending domain, DMARC policy included, and works with Entri, which can add them to your DNS for you. Here's the path from SmartrMail's custom sending domain guide:
- Start with your own domain. A
.myshopify.comaddress can't get a custom sending domain. - Go to Settings > Email settings and verify the address you'll send from.
- Request a sending domain. SmartrMail generates the records. Its SPF record sits on its own subdomain, so it won't clash with the one your domain already has.
- Let Entri add them after you log in to your DNS provider. If your domain was bought and is managed in Shopify, Entri may not reach it, so add the records under Settings > Domains in your Shopify admin.
- Click Verify record status. DNS changes can take up to 48 hours.
- Warm up the new domain by sending to your most engaged subscribers first.
Why your own domain? On a shared sending domain, your reputation also depends on everyone else who sends from it. On your own, the reputation you build stays attached to your domain. Moving from another platform? SmartrMail's free migration includes "DNS and authentication configured so deliverability transfers cleanly".
What Gmail, Yahoo and Outlook Ask For
Gmail and Yahoo have required these from bulk senders since February 2024, and Outlook.com since May 2025. Google and Outlook.com draw the line at 5,000 emails a day to their users; Yahoo gives no number. If your list is big enough, your Black Friday sends are the ones that cross it.
As of September 2026, the three ask for four things:
- All three records. DMARC can be on its monitor-only setting. Yahoo adds that DMARC has to pass, and Outlook.com that SPF and DKIM both have to pass.
- Matching names. Your From address matches the name on the guest list or on the seal.
- Few spam complaints. Google and Yahoo set the ceiling at 0.3%, about 3 complaints for every 1,000 emails that reach the inbox. Google asks you to stay under 0.1%, or 1 in 1,000.
- Easy unsubscribes. Google and Yahoo require one-click unsubscribe plus a visible link, and Yahoo wants unsubscribes honored within 2 days. Outlook.com recommends a working, easy-to-find link.
Google says mail that misses them might not be delivered as expected, or might be marked as spam. Microsoft's April 2025 update says Outlook.com rejects mail from high-volume senders that fails its checks, from May 5, 2025. None of the three promises the inbox for meeting the rules. They're the minimum.
Sources, as of September 2026: Google's sender guidelines, Yahoo's best practices and Microsoft's Outlook requirements.
How to Check Yours in Two Minutes
- Send a test email from your store to a Gmail address.
- Open it, click More next to Reply, and choose Show original (Gmail's steps).
- Find the line that starts with
Authentication-Results.
A pass looks like this (a made-up, shortened example for yourstore.com):
Authentication-Results: mx.google.com;
dkim=pass header.i=@yourstore.com;
spf=pass smtp.mailfrom=mail.yourstore.com;
dmarc=pass header.from=yourstore.comIn doorman terms: spf=pass means the server was on the guest list, dkim=pass with @yourstore.com means the seal is yours and intact, and dmarc=pass means a passing check matches your From address.
Reading a fail:
spf=failorsoftfail: a sender is missing from your guest list.dkim=fail: the seal is missing or broken. Google's help says "body hash did not verify" means the message was changed on the way.dkim=passwith your platform's domain: the seal isn't yours, so DMARC relies on SPF alone.dmarc=failwhile SPF or DKIM passes: the names don't match.
If you see a fail, send the header and the last section of this post to whoever manages your DNS.
If You Sell on Shopify, You Have Two Senders
Shopify sends your order and shipping emails, and it authenticates them separately. If you bought your domain through Shopify, it sets up SPF, DKIM and DMARC for you. If your domain is registered elsewhere, Shopify's records cover SPF and DKIM, and you add DMARC yourself. Without those records, Shopify rewrites your sender address to one at shopifyemail.com (Shopify Help Center, as of September 2026).
So a typical store has two senders on one domain: Shopify for orders, an email platform for campaigns. Both need to pass, and they share your domain's one DMARC record.
What Authentication Won't Fix
Getting past the doorman gets you into the room. Whether anyone's glad to see you is still up to you:
- Bounces. Google, Yahoo and Microsoft all tell senders to clear out addresses that don't exist. Here's how to avoid hard bounces.
- Unengaged subscribers. Yahoo says mailing people who don't read your emails harms your delivery and reputation. A sunset email flow gives them one last chance.
- Complaints. Every "report spam" click counts toward your spam rate. An unsubscribe doesn't, so make it easy.
Your Pre-BFCM Email Authentication Checklist (September 2026)
Method: built from Google's, Yahoo's and Microsoft's sender pages, Shopify's help center and the SPF and DMARC specs, as of September 2026. Recheck them before you rely on the list.
- List every service that sends email as your store.
- Ask whoever manages your DNS to confirm one SPF record, covering every sender, within 10 DNS lookups.
- Send a test to Gmail and check SPF, DKIM and DMARC all pass in Show original.
- In that test, check that the DKIM seal carries your domain, not your platform's.
- Confirm a DMARC record exists, at least on monitor-only, with a report address someone reads.
- Check that marketing emails have one-click unsubscribe and a visible unsubscribe link.
- Check that unsubscribes are processed within 2 days (Yahoo's rule).
- Set up Google Postmaster Tools and keep your spam rate under 0.1%, well clear of 0.3%.
- Don't tighten your DMARC policy between now and Cyber Monday. (Our recommendation.)
For Whoever Manages Your DNS: The Technical Setup
Forward this part to your developer or agency.
SPF, DKIM and DMARC at a Glance
| Record | What it checks | Where it lives |
|---|---|---|
| SPF | The sending server is authorized for the envelope sender (Return-Path) domain | One TXT per name, starting v=spf1 |
| DKIM | The signing domain signed the message and it wasn't altered | selector._domainkey.yourdomain.com, CNAME or TXT from your platform |
| DMARC | SPF or DKIM passed and aligned with the From domain; sets policy and reports | One TXT at _dmarc.yourdomain.com |
How to Set Up SPF
- One SPF record per name. A second
v=spf1TXT breaks SPF, so edit the existing one. - Each sender gives you an
include:. SPF allows 10 DNS lookups at most, and everyinclude:counts (RFC 7208). - SmartrMail's SPF record sits on
smartr.yourdomain.com, so it doesn't conflict with the one on your root domain. Shopify says its CNAMEs handle SPF with no separate SPF TXT. - Our recommendation: end with
~all(softfail) while testing, then-all(fail) once every sender is listed.
How to Set Up DKIM
- The platform generates the keys and gives you CNAME or TXT records. Add them exactly as given.
- The selector is the label before
._domainkey. Each platform has its own, so several DKIM records can coexist.
How to Set Up DMARC
Starter record: v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com
p=noneblocks nothing. Theruaaddress gets reports on which servers sent as your domain and whether they passed.- One DMARC record per domain. Shopify warns that multiple records make validation fail. If one exists, update it.
- If it has
adkim=soraspf=s, Shopify recommends relaxed (r) instead. - Our recommendation, not a rule: stay at
p=noneuntil reports show every legitimate sender passing, thenp=quarantine, and only laterp=reject. Microsoft's Outlook FAQ advises the same gradual order. Don't tighten it right before Black Friday. Spec: RFC 7489.
Shopify DKIM and DMARC Records
Shopify's email domain authentication is under Settings > Notifications, in the Sender email section. Its CNAMEs cover DKIM and SPF. On a domain registered elsewhere, add DMARC as a TXT at _dmarc (Shopify's default: v=DMARC1; p=none;). Domains bought through Shopify get all three automatically.
Email Authentication FAQ
How do I authenticate my email?
Add SPF, DKIM and DMARC records to the domain you send from. In SmartrMail, they're generated under Settings > Email settings, and Entri can add them for you. Then check a test in Gmail's Show original.
How do I fix "email authentication failed"?
Open Show original and see which check failed. SPF: a sender is missing, or there are two SPF records or too many lookups. DKIM: re-copy the records and re-verify. Only DMARC: the names don't match, and sending from your own custom sending domain fixes it.
How can I verify the authenticity of an email?
Choose Show original in Gmail. A pass on all three for the sender's own domain means that domain sent it and nobody changed it on the way. It doesn't mean the content is safe.
Once all of that passes, the next thing between your email and the open is the subject line. Our list of Black Friday subject lines is a good place to start.
SmartrMail is email marketing for ecommerce stores. See what's included.
Launch your next campaign in a flash
15 days free. Then free forever up to 200 active subscribers. Cancel anytime, no questions asked.
