Sending provider
SendGrid SPF, DKIM and DMARC setup
With automated security on (the default), SendGrid domain authentication is three CNAME records: em<0000> for the return path, which carries SPF, and s1._domainkey and s2._domainkey for DKIM. Nothing is added to your root SPF record. Add a DMARC TXT record at _dmarc, then click Verify in Settings > Sender Authentication.
SendGrid
Records at a glance
- SPF
CNAME em<0000> to SendGrid; no include on the root
- DKIM
CNAMEs s1._domainkey and s2._domainkey
- DMARC
v=DMARC1; p=none;
Check SendGrid on your domain
Enter the domain you send from: the check looks for the SendGrid SPF include, its DKIM key and your DMARC record, and says what to fix.
Looks for the SPF record, DKIM at s1 and s2 and a DMARC record. Lookups go from your browser to Cloudflare's public DNS resolver.
DNS records
The SendGrid records
Values in angle brackets are specific to your account; copy them from the provider. Hosts are relative to your domain, as most DNS panels expect them.
- Return pathCNAMEsource (opens the vendor's page in a new tab)Name / host
em<0000>Value<u00000000>.<wl000>.sendgrid.netCarries SPF for the return-path subdomain. em<0000> is four random characters unless you set a custom return path
- Name / host
s1._domainkeyValues1.domainkey.<u00000000>.<wl000>.sendgrid.netu00000000 and wl000 are per account; copy them from SendGrid
- Name / host
s2._domainkeyValues2.domainkey.<u00000000>.<wl000>.sendgrid.net - Name / host
_dmarcValuev=DMARC1; p=none;SendGrid lists it with the other records; add rua=mailto:<address> to collect reports
Good to know
- With automated security off you publish the records yourself: MX em<0000> to mx.sendgrid.net, TXT em<0000> with v=spf1 include:sendgrid.net ~all, and a DKIM TXT key at m1._domainkeysource (opens the vendor's page in a new tab)
- Advanced Settings let you pick a custom return path and a custom DKIM selector of three letters or numberssource (opens the vendor's page in a new tab)
- SendGrid's DMARC template is v=DMARC1; p=(none|quarantine|reject); rua=mailto:<email address>; to collect reports, start with nonesource (opens the vendor's page in a new tab)
Step by step
Authenticate your domain in SendGrid
Open Sender Authenticationsource (opens the vendor's page in a new tab)
In SendGrid go to Settings > Sender Authentication and click Get Started under Domain Authentication
Pick the DNS host and link brandingsource (opens the vendor's page in a new tab)
Select your DNS host provider and choose whether to brand links with your domain, then click Next
Enter the domainsource (opens the vendor's page in a new tab)
Type the domain you send from. Under Advanced Settings keep automated security on unless you manage the SPF and DKIM records yourself
Add the recordssource (opens the vendor's page in a new tab)
Click Next to see the records and add each one at your DNS host, with the host names as SendGrid shows them
Verifysource (opens the vendor's page in a new tab)
Return to SendGrid and click Verify. Records can take up to 48 hours to validate
Where the records go
Field by field for the DNS panel your domain uses:
DMARC
DMARC with SendGrid
- SendGrid's record set includes v=DMARC1; p=none; at _dmarcsource (opens the vendor's page in a new tab)
- Add rua=mailto:<address> to receive aggregate reports; SendGrid says to keep p=none while you collect themsource (opens the vendor's page in a new tab)
- A failing DMARC check does not stop SendGrid from sending; fix the DMARC record on its ownsource (opens the vendor's page in a new tab)
TXT at _dmarc
v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.comReplace the address with a mailbox you read; move to p=quarantine when the reports show every sender passing.
Troubleshooting
Common SendGrid errors and fixes
Records do not validate yet
DNS changes can take up to 48 hours to validate; click Verify again latersource (opens the vendor's page in a new tab)
Host doubled: em123.domain.com.domain.com
Follow the format of the records already in your DNS panel; most panels add the domain, so enter em123 alonesource (opens the vendor's page in a new tab)
Expected TXT record: no such host
A long DKIM key was split by the panel; combine it back into one set of quotessource (opens the vendor's page in a new tab)
Conflicting records on one host
Remove duplicate MX, TXT or CNAME entries for the same host namesource (opens the vendor's page in a new tab)
DNS host rejects underscores
DKIM host names need the underscore in _domainkey; a DNS host that refuses it cannot publish DKIMsource (opens the vendor's page in a new tab)
For cold email
Mailboxes that come with the DNS records done
If the domain is for cold outreach, keep SendGrid on your main domain and send from separate domains. Outreach2day buys the domains, publishes SPF, DKIM and DMARC, creates the mailboxes and starts warm-up, then sends your campaigns from its own sequencer or exports the mailboxes to Instantly or Smartlead.
- SPF, DKIM and DMARC set for youOn every domain, checked after setup and kept in place
- $2.50 a mailbox a month12-mailbox minimum; warm-up and the sending engine included
- 1,000+ mailboxesA volume price per mailbox, quoted on a call
Questions
Do I add include:sendgrid.net to my SPF record?
Not with automated security on. SPF is checked on the return-path subdomain em<0000>, a CNAME that SendGrid manages. With automated security off, the SPF TXT record v=spf1 include:sendgrid.net ~all goes on that subdomain as well.
What are the SendGrid DKIM selectors?
s1 and s2, published as CNAMEs at s1._domainkey and s2._domainkey. With automated security off the key is a TXT record at m1._domainkey, and Advanced Settings allow a custom selector of three letters or numbers.
Why does SendGrid domain authentication fail?
Most often the host name has the domain twice, a record conflicts with an existing one on the same host, or DNS has not caught up yet. Check each host name as your DNS panel shows it and click Verify again.
Can I send cold email through SendGrid?
SendGrid is built for transactional and marketing mail to people who asked for it. Cold outreach usually runs from separate domains and mailboxes with warm-up, so the main domain's SendGrid reputation stays clean.
Sources
SendGrid documentation, checked . Menus and values change; if a step differs, SendGrid's own page is the reference.
Deliverability call
Talk to our deliverability team
Book a call with the people who run our mailbox infrastructure. We look at your current setup and tell you what to change. Running 1,000+ mailboxes? We also quote a volume price below every vendor list price in our comparisons, warm-up and sending included.
- Review your domains, DNS records and current inbox placement
- Size the setup: domains, mailboxes per domain and daily volume per mailbox
- Plan warm-up and the move from your current provider or sequencer
- 1,000+ mailboxes: a volume price per mailbox for your setup
Free call
See open times in your time zone and book on this page.
Or open the booking pageLoading available times…
Open the booking page instead