Sending provider
HubSpot SPF, DKIM and DMARC setup
HubSpot authenticates a sending domain with two DKIM CNAME records, an SPF include for your account (HubSpot's example is include:123456.spf03.hubspotemail.net) and a DMARC TXT record. Copy each Host and Required data value from Settings > Content > Domains & URLs > Email Sending > Connect sending domain. The domain shows Authenticated when all three pass.
HubSpot
Records at a glance
- SPF include
include:<HubID>.spf0X.hubspotemail.net
- DKIM
Two CNAMEs, values from the connect wizard
- DMARC
v=DMARC1; p=none;
Check HubSpot on your domain
Enter the domain you send from: the check looks for the HubSpot SPF include, its DKIM key and your DMARC record, and says what to fix.
Lookups go from your browser to Cloudflare's public DNS resolver.
DNS records
The HubSpot records
Values in angle brackets are specific to your account; copy them from the provider. Hosts are relative to your domain, as most DNS panels expect them.
- Name / host
@ (your sending domain)Valuev=spf1 include:<HubID>.spf0X.hubspotemail.net -allMerge the include into your existing record; v=spf1 and -all appear once. Copy the exact include from HubSpot
- Name / host
<Host from the HubSpot wizard>Value<Required data from the HubSpot wizard>HubSpot generates two DKIM CNAMEs per account; its help pages do not list the names
- Name / host
_dmarcValuev=DMARC1; p=none;HubSpot calls this the bare minimum; a subdomain counts as authenticated when the root domain has DMARC
Good to know
- On shared IPs HubSpot manages the return path and its SPF; it still highly recommends adding HubSpot's SPF include to your From domainsource (opens the vendor's page in a new tab)
- Without DKIM, HubSpot rewrites the From domain to a HubSpot system domainsource (opens the vendor's page in a new tab)
- Remove a null MX record (MX 0 .) from the sending domain; it causes permanent bouncessource (opens the vendor's page in a new tab)
- HubSpot's stricter DMARC examples: v=DMARC1; p=quarantine; pct=25; ruf=mailto:reporting@example.com; and v=DMARC1; p=reject; rua=mailto:reporting@example.com;source (opens the vendor's page in a new tab)
Step by step
Connect your sending domain in HubSpot
Open Email Sendingsource (opens the vendor's page in a new tab)
Click the settings icon, then Content > Domains & URLs in the left sidebar, and the Email Sending tab
Connect the domainsource (opens the vendor's page in a new tab)
Click Connect sending domain, enter an address you send marketing email from, click Next and verify the domain
Pick the setupsource (opens the vendor's page in a new tab)
Click Sign in with your DNS provider if HubSpot offers it, or No, I'll set it up manually
Copy every recordsource (opens the vendor's page in a new tab)
Add the Host and Required data of each record at your DNS host: two DKIM CNAMEs, the SPF TXT and the DMARC TXT
Check the statussource (opens the vendor's page in a new tab)
Wait at least 20 minutes (up to 48 hours) and check the Email Sending tab; Continue setup shows which record still fails
Where the records go
Field by field for the DNS panel your domain uses:
DMARC
DMARC with HubSpot
- v=DMARC1; p=none; is the bare minimum for DMARC to worksource (opens the vendor's page in a new tab)
- Partially authenticated means DKIM passes and SPF or DMARC is still missingsource (opens the vendor's page in a new tab)
- Google and Yahoo bounce bulk mail with a DMARC or policy error when DKIM, SPF and DMARC are not all setsource (opens the vendor's page in a new tab)
TXT at _dmarc
v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.comReplace the address with a mailbox you read; move to p=quarantine when the reports show every sender passing.
Troubleshooting
Common HubSpot errors and fixes
Status: Partially authenticated
DKIM passes; click Continue setup and add the SPF and DMARC TXT recordssource (opens the vendor's page in a new tab)
A second SPF record
Add the include to the existing SPF record so v=spf1 and -all appear oncesource (opens the vendor's page in a new tab)
Cloudflare CNAMEs do not verify
Turn off CNAME flattening and the proxy for the sending domainsource (opens the vendor's page in a new tab)
Domain also hosts the website
Use a sending subdomain that hosts nothing, such as info.yourdomain.comsource (opens the vendor's page in a new tab)
DMARC or policy bounces
Set up DKIM, SPF and DMARC on the sending domainsource (opens the vendor's page in a new tab)
Permanent bounces from a null MX
Remove the MX 0 . record from the sending domainsource (opens the vendor's page in a new tab)
For cold email
Mailboxes that come with the DNS records done
If the domain is for cold outreach, keep HubSpot on your main domain and send from separate domains. Outreach2day buys the domains, publishes SPF, DKIM and DMARC, creates the mailboxes and starts warm-up, then sends your campaigns from its own sequencer or exports the mailboxes to Instantly or Smartlead.
- SPF, DKIM and DMARC set for youOn every domain, checked after setup and kept in place
- $2.50 a mailbox a month12-mailbox minimum; warm-up and the sending engine included
- 1,000+ mailboxesA volume price per mailbox, quoted on a call
Questions
What is the HubSpot SPF record?
An include for your account, like include:123456.spf03.hubspotemail.net in HubSpot's example. Copy yours from the connect wizard and merge it into your existing SPF record.
What does Partially authenticated mean in HubSpot?
DKIM is verified but SPF or DMARC is missing. Click Continue setup on the Email Sending tab to see the records that still fail.
Where do I find the HubSpot DKIM records?
In Settings > Content > Domains & URLs > Email Sending > Connect sending domain. The wizard shows two CNAMEs with Host and Required data values for your account.
Can I send cold email from HubSpot?
HubSpot marketing email is built for contacts who opted in. Cold outreach runs from separate domains and mailboxes, so the domain HubSpot sends from keeps its reputation.
Sources
HubSpot documentation, checked . Menus and values change; if a step differs, HubSpot's own page is the reference.
Deliverability call
Talk to our deliverability team
Book a call with the people who run our mailbox infrastructure. We look at your current setup and tell you what to change. Running 1,000+ mailboxes? We also quote a volume price below every vendor list price in our comparisons, warm-up and sending included.
- Review your domains, DNS records and current inbox placement
- Size the setup: domains, mailboxes per domain and daily volume per mailbox
- Plan warm-up and the move from your current provider or sequencer
- 1,000+ mailboxes: a volume price per mailbox for your setup
Free call
See open times in your time zone and book on this page.
Or open the booking pageLoading available times…
Open the booking page instead