SendGrid SPF, DKIM and DMARC: the CNAME records domain authentication asks for
What SendGrid domain authentication adds to DNS, why the SPF include sits on the return-path subdomain, automated vs manual security, and the DMARC record.
On this page
SendGrid (Twilio SendGrid) authenticates your domain with CNAME records you add in DNS, not with a line pasted into your root SPF record. Add the records SendGrid shows under Sender Authentication, click Verify, then publish a DMARC record. SendGrid's domain authentication documentation (opens in a new tab) generates four DNS records; with automated security on, which is the default, Twilio creates and maintains the SPF, DKIM and DMARC records on your behalf. The SPF include:sendgrid.net line only appears when automated security is off, and even then on the return-path subdomain rather than your root domain.
What SendGrid domain authentication does
Domain authentication verifies your email servers, messages and sending addresses by having you add DNS records to your domain. On SendGrid's domain authentication page (opens in a new tab), authentication removes the via sendgrid.net tagline after the From address and improves trust with receiving servers and recipients. It also sets up a return path: when you authenticate, SendGrid creates a subdomain of your domain, made of four random alphanumeric characters, where receiving servers send delayed bounces and unsubscribe notices.
The records depend on the automated security setting. With it on, SendGrid can create and update your SPF and DKIM records for you; if you buy a dedicated IP address, SendGrid adds it to the SPF record itself. With it off, SendGrid gives you MX, SPF, DKIM and DMARC values, and keeping them current becomes your job: when you add an IP address to the account, you update the SPF TXT record yourself. One constraint from the same page: if your DNS provider does not accept underscores in CNAME records, you cannot use automated security.
Check your domain now
See the SPF, DKIM and DMARC records your domain publishes and what to fix first. Free, no account needed.
The records SendGrid asks for
The steps from SendGrid's documentation (opens in a new tab): in the console open Settings, then Sender Authentication, click Get Started under Domain Authentication, type the domain you send from, and under Advanced Settings leave Use automated security checked. Click Next and the Install DNS Records page shows the records for your DNS host. With automated security on, the example table looks like this on example.com:
| Type | Host | Points to | Purpose |
|---|---|---|---|
| CNAME | em0000.example.com |
u00000000.wl000.sendgrid.net |
SPF (return path) |
| CNAME | s1._domainkey.example.com |
s1.domainkey.u00000000.wl000.sendgrid.net |
DKIM |
| CNAME | s2._domainkey.example.com |
s2.domainkey.u00000000.wl000.sendgrid.net |
DKIM |
| TXT | _dmarc.example.com |
v=DMARC1; p=none; |
DMARC |
Copy the exact values from your Install DNS Records page rather than from this table. Two traps the page names: subdomains do not inherit authentication from the parent domain, so authenticate each domain you send from; and major DNS providers such as GoDaddy, Amazon Route 53 and Namecheap append your domain to records you add, so entering em123.example.com as the host stores em123.example.com.example.com and fails verification. Enter only em123 there. After adding the records, return to the console and click Verify; verification can take up to 48 hours, and if only half the records verify, wait or check for a typo.
With automated security off, SendGrid instead generates an MX record for the return-path subdomain pointing to mx.sendgrid.net, a TXT record on that subdomain with v=spf1 include:sendgrid.net ~all, a DKIM TXT record at m1._domainkey.example.com, and the DMARC TXT record. If another service already uses the selector s on your domain, Advanced Settings offers a custom DKIM selector.
SPF: do you need include:sendgrid.net?
Not on your root domain when automated security is on. SendGrid's SPF page (opens in a new tab) describes the check receivers perform: they read the message's return path and compare the sending server's IP address with the SPF record of the return-path domain. On SendGrid's domain authentication page (opens in a new tab), the return path is the bounce subdomain SendGrid created, the automated-security table carries SPF on that subdomain's CNAME, and the manual-security table puts v=spf1 include:sendgrid.net ~all in a TXT record on that same subdomain, not on the root. SendGrid's SPF page does show v=spf1 include:sendgrid.net -all as a typical record that allows SendGrid to send for a domain; the domain authentication tables show where SendGrid itself places it.
Adding the include to your root record anyway has a cost. RFC 7208 (opens in a new tab) lists include, a, mx, ptr, exists and redirect as the terms that cause DNS queries and limits them to 10 per evaluation; past that the result is permerror. SendGrid's SPF page repeats the limit and advises keeping includes to domains essential for your delivery. Checked against live DNS, sendgrid.net publishes an SPF record with eleven ip4 ranges plus include:ab.sendgrid.net ~all, and ab.sendgrid.net publishes four more ranges, so the include costs two of your ten lookups. If your root record is already near the limit, see SPF too many DNS lookups. Keep one SPF record per domain whatever you add; RFC 7208 section 3.2 (opens in a new tab) forbids a domain name from having multiple records that an authorization check would select.
DKIM: the two selectors
DKIM (DomainKeys Identified Mail (opens in a new tab)) is the second factor of SendGrid's domain authentication: the sending server signs each message with a private key and receivers fetch the public key from DNS. SendGrid's DKIM page (opens in a new tab) explains the two CNAMEs: SendGrid uses the selectors s1 and s2 interchangeably, activates only one for signing at any time, and rotates them when needed. The receiver looks the key up from the s= and d= tags of the signature, so the name it queries is s1._domainkey.example.com or s2._domainkey.example.com; RFC 6376 (opens in a new tab) defines that lookup name as the selector under _domainkey in the signing domain. SendGrid turns on DKIM for all email messages.
If the DKIM record does not exist when the receiver queries it, the check fails, and the receiver handles the message under your DMARC policy or its own filtering. That is what a missing or mistyped CNAME looks like from the outside; DKIM fail explains how to read the reason the receiver gives.
DMARC for a SendGrid sender
DMARC (Domain-based Message Authentication, Reporting, and Conformance (opens in a new tab)) is the third factor of domain authentication. SendGrid's DMARC page (opens in a new tab) requires two tags, v and p, with p=none to collect reports first, and names rua as the address receivers send daily aggregate reports to. SendGrid's domain authentication page (opens in a new tab) lists the record as a TXT record at _dmarc.example.com with v=DMARC1; p=none;. A reporting address makes it useful; publish the record built in the DMARC generator at that name:
v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com
DMARC also needs alignment. RFC 7489 (opens in a new tab) requires the From domain to match an authenticated identifier: in relaxed mode the SPF or DKIM domain only needs the same organizational domain as the From domain, so a return path of cbg.bounces.example.com aligns with payments@example.com; in strict mode only an exact match counts. SendGrid's CNAMEs put the return path and the DKIM keys under subdomains of your domain, so relaxed alignment, the default, is what makes them pass. SendGrid's troubleshooting page (opens in a new tab) adds that SendGrid matches the From address of each email to an authenticated domain, falls back to your default authenticated domain when none matches, and uses sendgrid.net when it cannot match a valid authenticated domain at all; a sendgrid.net identifier cannot align with your domain. That page also notes that Sender Authentication confirms the SPF, DKIM and DMARC records but does not require a DMARC pass. If p=none shows failures, see DMARC fail; if a checker finds no record at all, see No DMARC record found.
Check your domain
The free SPF, DKIM and DMARC check reads the public DNS records of the domain you enter and reports each record as pass, warning, fail or error. For SPF it flags a missing record, ~all, and a record close to or over the 10-lookup limit; for DMARC it flags a missing record, p=none, no reporting address and subdomains left at none. For DKIM it tries commonly used selectors; if your selector is not among them, the key is there but the check cannot see it. A DNS finding shows how the domain is set up, not where a particular message landed.
Sources
- Twilio SendGrid: Configure domain authentication (opens in a new tab)
- Twilio SendGrid: Verify senders with SPF (opens in a new tab)
- Twilio SendGrid: Verify message integrity with DKIM (opens in a new tab)
- Twilio SendGrid: Enforce authentication with a DMARC policy (opens in a new tab)
- Twilio SendGrid: Troubleshooting Sender Authentication (opens in a new tab)
- RFC 7208 section 4.6.4: DNS lookup limits (opens in a new tab)
- RFC 7208 section 3.2: one SPF record per domain (opens in a new tab)
- RFC 6376 section 1: what DKIM is (opens in a new tab)
- RFC 6376 section 3.6.2: the DKIM key name (opens in a new tab)
- RFC 7489 section 1: what DMARC is (opens in a new tab)
- RFC 7489 section 3.1: identifier alignment (opens in a new tab)
Tools for this
-
SPF, DKIM and DMARC check
Check the email records a domain publishes today and see what to fix first.
-
DMARC record generator
Build a DMARC record step by step, from monitoring to reject.
Frequently asked questions
Do I still need an SPF record for SendGrid?
Not on your root domain. With automated security SendGrid handles SPF and DKIM with the CNAME records you add; with manual security it gives you a TXT record with include:sendgrid.net for the return-path subdomain it created.
Why does SendGrid say verified but DMARC still fails?
Sender Authentication confirms the SPF, DKIM and DMARC records but does not require a DMARC pass. DMARC needs the From domain to align with the authenticated domain, and when the From address matches no authenticated domain SendGrid falls back to the default domain or to sendgrid.net.
Can I use one authenticated domain for marketing and transactional mail?
Yes. SendGrid applies an authenticated domain to every message whose From address matches it, and multiple authenticated domains can exist on one account. Subdomains do not inherit authentication from the parent domain, so authenticate each sending domain you use.
Check your domain now
See the SPF, DKIM and DMARC records your domain publishes and what to fix first. Free, no account needed.