Sending provider
Mailchimp SPF, DKIM and DMARC setup
Mailchimp authenticates a domain with two DKIM CNAME records (k2._domainkey is Mailchimp's example) and one DMARC TXT record at _dmarc; the exact values appear in Account & billing > Domains. Mailchimp's help pages ask for no SPF include. Mailchimp Transactional (Mandrill) uses mte1 and mte2._domainkey CNAMEs to dkim1 and dkim2.mandrillapp.com.
Mailchimp
Records at a glance
- SPF
No include required by Mailchimp's docs
- DKIM
Two CNAMEs from the Domains tab (k2._domainkey in the docs)
- DMARC
TXT at _dmarc, value shown in Mailchimp
Check Mailchimp on your domain
Enter the domain you send from: the check looks for the Mailchimp SPF include, its DKIM key and your DMARC record, and says what to fix.
Looks for the SPF record, DKIM at k2 and mte1 and a DMARC record. Lookups go from your browser to Cloudflare's public DNS resolver.
DNS records
The Mailchimp records
Values in angle brackets are specific to your account; copy them from the provider. Hosts are relative to your domain, as most DNS panels expect them.
- Name / host
k2._domainkeyValue<CNAME 1 value from the Domains tab>Mailchimp shows CNAME 1 and CNAME 2 with their names and values in the app
- Name / host
_dmarcValue<TXT value from the Domains tab>Gmail and Yahoo require custom authentication and a DMARC record from senders of 5,000+ emails a day to their users
- Name / host
mte1._domainkeyValuedkim1.mandrillapp.comMailchimp Transactional (Mandrill) only; mte2._domainkey points to dkim2.mandrillapp.com
- Return pathCNAMEsource (opens the vendor's page in a new tab)Name / host
<subdomain> (Transactional)Valuemandrillapp.comOptional custom return-path domain for Transactional, on a subdomain such as mail.example.com
Good to know
- Mailchimp says the domain needs 2 CNAME records for DKIM and 1 TXT record for DMARC; its help pages list no SPF recordsource (opens the vendor's page in a new tab)
- Verify the email domain first; authentication starts from the verified domainsource (opens the vendor's page in a new tab)
- For Transactional, DMARC at minimum is v=DMARC1; p=none at _dmarc, and a return-path domain can belong to one Transactional account onlysource (opens the vendor's page in a new tab)
Step by step
Authenticate your domain in Mailchimp
Verify the domainsource (opens the vendor's page in a new tab)
Verify the email domain you send from; authentication needs a verified domain
Open Domainssource (opens the vendor's page in a new tab)
Click your profile icon and choose Account & billing, then the Domains tab, and click Start authentication next to the domain
Pick your DNS providersource (opens the vendor's page in a new tab)
Select your domain provider and click Next. Automatic authentication with Entri updates DNS for you where supported
Or copy the recordssource (opens the vendor's page in a new tab)
Add CNAME 1, CNAME 2 and the _dmarc TXT record at your DNS host by hand
Wait for Authenticatedsource (opens the vendor's page in a new tab)
Most domains validate within minutes, some take up to 48 hours. The Domains page moves from Authentication in progress to Authenticated
Where the records go
Field by field for the DNS panel your domain uses:
DMARC
DMARC with Mailchimp
- Marketing: the _dmarc TXT value is shown in the Domains tab with the two CNAMEssource (opens the vendor's page in a new tab)
- Transactional: v=DMARC1; p=none at _dmarc is the minimumsource (opens the vendor's page in a new tab)
- Gmail and Yahoo require a published DMARC record from senders of 5,000+ emails a day to their addressessource (opens the vendor's page in a new tab)
TXT at _dmarc
v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.comReplace the address with a mailbox you read; move to p=quarantine when the reports show every sender passing.
Troubleshooting
Common Mailchimp errors and fixes
CNAME is not updating
The host may carry the domain twice (k2._domainkey.example.com.example.com); enter k2._domainkey alone if your DNS host adds the domainsource (opens the vendor's page in a new tab)
Records look right but the domain is not authenticated
DNS can take up to 48 hours; check again latersource (opens the vendor's page in a new tab)
Authentication failed
Click Resolve or Restart authentication on the Domains page and check each recordsource (opens the vendor's page in a new tab)
Start authentication is missing
Verify the email domain firstsource (opens the vendor's page in a new tab)
Transactional: _dmarc twice in the host
Some DNS hosts add the domain after _dmarc; make sure it appears oncesource (opens the vendor's page in a new tab)
For cold email
Mailboxes that come with the DNS records done
If the domain is for cold outreach, keep Mailchimp on your main domain and send from separate domains. Outreach2day buys the domains, publishes SPF, DKIM and DMARC, creates the mailboxes and starts warm-up, then sends your campaigns from its own sequencer or exports the mailboxes to Instantly or Smartlead.
- SPF, DKIM and DMARC set for youOn every domain, checked after setup and kept in place
- $2.50 a mailbox a month12-mailbox minimum; warm-up and the sending engine included
- 1,000+ mailboxesA volume price per mailbox, quoted on a call
Questions
Does Mailchimp need an SPF record?
Mailchimp's help pages ask for two DKIM CNAME records and one DMARC TXT record, and list no SPF include. Keep your domain's SPF record for the other services that send as it.
What is the Mailchimp DKIM record?
A CNAME record; Mailchimp's example host is k2._domainkey. The two CNAME names and values for your domain are in Account & billing > Domains after you click Start authentication.
What records does Mandrill need?
Two DKIM CNAMEs, mte1._domainkey to dkim1.mandrillapp.com and mte2._domainkey to dkim2.mandrillapp.com, plus at least v=DMARC1; p=none at _dmarc. A custom return-path subdomain is a CNAME to mandrillapp.com.
Can I send cold email with Mailchimp?
Mailchimp is built for subscribers who opted in. Cold outreach runs from separate domains and mailboxes with warm-up, which keeps the newsletter domain clean.
Sources
Mailchimp documentation, checked . Menus and values change; if a step differs, Mailchimp's own page is the reference.
Deliverability call
Talk to our deliverability team
Book a call with the people who run our mailbox infrastructure. We look at your current setup and tell you what to change. Running 1,000+ mailboxes? We also quote a volume price below every vendor list price in our comparisons, warm-up and sending included.
- Review your domains, DNS records and current inbox placement
- Size the setup: domains, mailboxes per domain and daily volume per mailbox
- Plan warm-up and the move from your current provider or sequencer
- 1,000+ mailboxes: a volume price per mailbox for your setup
Free call
See open times in your time zone and book on this page.
Or open the booking pageLoading available times…
Open the booking page instead