Brevo SPF, DKIM and DMARC: authenticate your domain with the records Brevo gives you
The DNS records Brevo asks for to authenticate a sending domain (Brevo code, DKIM and DMARC), when SPF matters, how to merge spf.brevo.com, and how to check.
On this page
Brevo authenticates your sending domain with the DNS records it shows under Settings, Senders, Domains, IPs, Domains: a Brevo code that proves you own the domain, a DKIM record, and a DMARC record. Under Brevo's domain authentication article (opens in a new tab), SPF and MX records are not required to authenticate a domain and are only given when you set up a dedicated IP. If you do publish SPF for Brevo, Brevo's SPF article (opens in a new tab) allows one SPF record per domain, so merge include:spf.brevo.com into the record you have rather than adding a second one.
What Brevo asks you to add
The steps from Brevo's domain authentication article (opens in a new tab): in Brevo, open the account menu, choose Settings, then Senders, Domains, IPs, then Domains, and click Add a domain, or Authenticate next to a domain already listed. Brevo can detect your provider, add the Brevo code, DKIM and DMARC records and verify them for you. Otherwise you copy the records into your DNS provider; depending on your Brevo account, that is three or four records.
| Record | What it does |
|---|---|
| Brevo code | Verifies that you own and control the sending domain |
| DKIM, as two CNAME records or one TXT record | Signs mail so receivers can tell it was not modified after sending |
| DMARC | Tells mail servers how to handle suspicious mail under your policy: none, quarantine or reject |
Copy the host names and values exactly as Brevo shows them, then click Authenticate this email domain in Brevo. DNS changes can take up to 48 hours to propagate, and you can repeat the check over that period until the domain shows as Authenticated. Authenticate the domain you actually send from, the one in your From address. Keep the records in place for as long as you send with Brevo; the same article warns that changing or deleting them can cause delivery problems or mail marked as spam.
Brevo's guided setup (opens in a new tab) generates all the records in one flow and adds a branded subdomain that links to Brevo's infrastructure for SPF and the return path.
Check your domain now
See the SPF, DKIM and DMARC records your domain publishes and what to fix first. Free, no account needed.
SPF: merge Brevo into your existing record
A domain can only have one SPF record. Brevo's article on merging SPF records (opens in a new tab) warns that more than one can hurt your domain's reputation and cause delivery problems, and asks you to merge them into one. Its example combines Google Workspace and Brevo:
v=spf1 include:_spf.google.com include:spf.brevo.com mx ~all
The article puts each include in the middle of the record and all at the end, and notes that a domain without a valid SPF record gets a permanent error, which some receivers reject on. RFC 7208 (opens in a new tab) states the same one-record rule for every domain. Checked against live DNS, spf.brevo.com publishes ten ip4 ranges ending in -all, and spf.sendinblue.com publishes the same ranges, so either include costs one DNS lookup and no nested ones. RFC 7208's lookup limit (opens in a new tab) counts every include, a, mx, ptr, exists and redirect toward a maximum of 10 per evaluation, and the mx in Brevo's example counts too. If your record is close to the limit, see SPF too many DNS lookups.
DKIM
Brevo offers two forms of the DKIM record. Brevo's domain authentication article (opens in a new tab) describes two CNAME records as the more secure way, because they delegate the key to Brevo and let it rotate keys without any action from you, and the TXT form as a single record with a 1024-bit key by default. To switch from TXT to the two CNAMEs, the article asks you to contact Brevo support. The host names are under _domainkey in your domain; RFC 6376 (opens in a new tab) defines that lookup as the selector from the signature followed by _domainkey and the signing domain. After sending, look for dkim=pass in the message headers to confirm mail is signed with your domain.
DMARC
Brevo's DMARC policy FAQ (opens in a new tab) explains that Brevo only provides a p=none record, v=DMARC1; p=none; rua=mailto:rua@dmarc.brevo.com, and recommends getting professional help before moving to another policy. Your domain should have a single DMARC record with a rua tag; multiple DMARC records can interfere with authentication. If you already publish a record with your own reporting address, keep one record rather than adding Brevo's next to it. A monitoring record from the DMARC generator looks like this:
v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com
Alignment decides whether Brevo mail passes DMARC. Brevo's deliverability article (opens in a new tab) states that when you authenticate a domain, Brevo still uses its own infrastructure for SPF and the return path, so without a branded subdomain SPF passes on Brevo's domain, not yours; branding moves SPF alignment onto your sending domain. RFC 7489 (opens in a new tab) requires the From domain to align with an authenticated identifier and counts a DMARC pass if any aligned DKIM signature verifies, so DKIM with your domain is what carries Brevo mail through DMARC until SPF is branded. For a missing record, see No DMARC record found; for dmarc=fail in a message header, see DMARC fail.
Check your domain
The free SPF, DKIM and DMARC check reads the public DNS records of the domain you enter and flags a missing SPF record, ~all, a record close to or over the 10-lookup limit, a missing DMARC record, a policy of none and no reporting address. For DKIM it tries commonly used selectors; if Brevo's selector is not among them, the key is there but the check cannot see it. A DNS finding shows how the domain is set up, not where a particular message landed.
Sources
- Brevo: Authenticate your domain with Brevo (Brevo code, DKIM, DMARC) (opens in a new tab)
- Brevo: Set up your domain in Brevo (guided setup) (opens in a new tab)
- Brevo: Merge multiple SPF records (opens in a new tab)
- Brevo: What is a DMARC policy (opens in a new tab)
- Brevo: Domain setup for better email deliverability (opens in a new tab)
- RFC 7208 section 3.2: one SPF record per domain (opens in a new tab)
- RFC 7208 section 4.6.4: DNS lookup limits (opens in a new tab)
- RFC 6376 section 3.6.2: the DKIM key name (opens in a new tab)
- RFC 7489 section 3.1: identifier alignment (opens in a new tab)
Tools for this
-
SPF, DKIM and DMARC check
Check the email records a domain publishes today and see what to fix first.
-
DMARC record generator
Build a DMARC record step by step, from monitoring to reject.
Frequently asked questions
Is include:spf.sendinblue.com still valid?
It still resolves: checked against live DNS, spf.sendinblue.com publishes the same IP ranges as spf.brevo.com. Brevo's current help uses include:spf.brevo.com in its SPF example, so use that name in new records.
Do I need to keep Brevo's DNS records after authentication?
Yes. Brevo asks you to keep the DNS records as they are for as long as you send with Brevo, and warns that changing or deleting them can cause delivery problems or mail marked as spam.
Why does SPF not align for Brevo mail when the domain shows as authenticated?
Without a branded subdomain, SPF passes on Brevo's own infrastructure rather than your domain, so SPF does not align with your From domain. DKIM signed with your domain is what aligns; Brevo's branded subdomain moves SPF alignment onto your sending domain.
Check your domain now
See the SPF, DKIM and DMARC records your domain publishes and what to fix first. Free, no account needed.