Sending provider

SendGrid SPF, DKIM and DMARC setup

With automated security on (the default), SendGrid domain authentication is three CNAME records: em<0000> for the return path, which carries SPF, and s1._domainkey and s2._domainkey for DKIM. Nothing is added to your root SPF record. Add a DMARC TXT record at _dmarc, then click Verify in Settings > Sender Authentication.

SendGrid

Records at a glance

SPF

CNAME em<0000> to SendGrid; no include on the root

DKIM

CNAMEs s1._domainkey and s2._domainkey

DMARC
v=DMARC1; p=none;

Check SendGrid on your domain

Enter the domain you send from: the check looks for the SendGrid SPF include, its DKIM key and your DMARC record, and says what to fix.

Looks for the SPF record, DKIM at s1 and s2 and a DMARC record. Lookups go from your browser to Cloudflare's public DNS resolver.

DNS records

The SendGrid records

Values in angle brackets are specific to your account; copy them from the provider. Hosts are relative to your domain, as most DNS panels expect them.

Good to know

Step by step

Authenticate your domain in SendGrid

  1. Open Sender Authenticationsource (opens the vendor's page in a new tab)

    In SendGrid go to Settings > Sender Authentication and click Get Started under Domain Authentication

  2. Pick the DNS host and link brandingsource (opens the vendor's page in a new tab)

    Select your DNS host provider and choose whether to brand links with your domain, then click Next

  3. Enter the domainsource (opens the vendor's page in a new tab)

    Type the domain you send from. Under Advanced Settings keep automated security on unless you manage the SPF and DKIM records yourself

  4. Add the recordssource (opens the vendor's page in a new tab)

    Click Next to see the records and add each one at your DNS host, with the host names as SendGrid shows them

  5. Verifysource (opens the vendor's page in a new tab)

    Return to SendGrid and click Verify. Records can take up to 48 hours to validate

DMARC

DMARC with SendGrid

DMARCA safe first record

TXT at _dmarc

v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com

Replace the address with a mailbox you read; move to p=quarantine when the reports show every sender passing.

Troubleshooting

Common SendGrid errors and fixes

For cold email

Mailboxes that come with the DNS records done

If the domain is for cold outreach, keep SendGrid on your main domain and send from separate domains. Outreach2day buys the domains, publishes SPF, DKIM and DMARC, creates the mailboxes and starts warm-up, then sends your campaigns from its own sequencer or exports the mailboxes to Instantly or Smartlead.

  • SPF, DKIM and DMARC set for youOn every domain, checked after setup and kept in place
  • $2.50 a mailbox a month12-mailbox minimum; warm-up and the sending engine included
  • 1,000+ mailboxesA volume price per mailbox, quoted on a call

Questions

Do I add include:sendgrid.net to my SPF record?

Not with automated security on. SPF is checked on the return-path subdomain em<0000>, a CNAME that SendGrid manages. With automated security off, the SPF TXT record v=spf1 include:sendgrid.net ~all goes on that subdomain as well.

What are the SendGrid DKIM selectors?

s1 and s2, published as CNAMEs at s1._domainkey and s2._domainkey. With automated security off the key is a TXT record at m1._domainkey, and Advanced Settings allow a custom selector of three letters or numbers.

Why does SendGrid domain authentication fail?

Most often the host name has the domain twice, a record conflicts with an existing one on the same host, or DNS has not caught up yet. Check each host name as your DNS panel shows it and click Verify again.

Can I send cold email through SendGrid?

SendGrid is built for transactional and marketing mail to people who asked for it. Cold outreach usually runs from separate domains and mailboxes with warm-up, so the main domain's SendGrid reputation stays clean.

Sources

SendGrid documentation, checked . Menus and values change; if a step differs, SendGrid's own page is the reference.

Deliverability call

Talk to our deliverability team

Book a call with the people who run our mailbox infrastructure. We look at your current setup and tell you what to change. Running 1,000+ mailboxes? We also quote a volume price below every vendor list price in our comparisons, warm-up and sending included.

  • Review your domains, DNS records and current inbox placement
  • Size the setup: domains, mailboxes per domain and daily volume per mailbox
  • Plan warm-up and the move from your current provider or sequencer
  • 1,000+ mailboxes: a volume price per mailbox for your setup

Free call

See open times in your time zone and book on this page.

Or open the booking page