Skip to content

SendGrid SPF, DKIM and DMARC check

Enter the domain you send from with SendGrid. We check the SPF include, the SendGrid DKIM key, your DMARC policy and MX records, and tell you what is missing.

What SendGrid expects

SPF

With "automated security" on (the default), SendGrid handles SPF through a CNAME on a subdomain such as em1234.yourdomain, so you do not add anything to your root SPF. Only with automated security off do you add include:sendgrid.net.

Build a combined SPF record if you send from more than one service.

DKIM

Selectors we look for: s1s2

Domain authentication (Settings > Sender Authentication) gives you CNAME records for s1._domainkey and s2._domainkey. Publish all of them, then click Verify in SendGrid.

DMARC

DMARC is set on your domain, not in SendGrid. If you have none, start with v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com and tighten it once reports look clean. Generate one.

MX

SendGrid does not receive your mail, so keep your mailbox provider’s MX records.

Values come from SendGrid’s public setup documentation and can change. The SendGrid dashboard always shows the exact records for your account. Use those if they differ from this page.

Keep it working after setup

The usual failures come later: a second SPF record added for a new tool, a DKIM CNAME lost in a DNS move, a DMARC record deleted with an old zone. SenderBeacon checks twice a day and emails you in plain English. From $9/month, 14-day free trial, no card.

Start free trial

Questions

How long until SendGrid DNS changes show up?

Usually minutes, sometimes up to an hour, depending on the TTL on your records and your DNS host. Re-run the check after publishing.

Why does the check say DKIM is missing when SendGrid says it is verified?

Most often the record went on the wrong host (for example _domainkey.yourdomain.com.yourdomain.com, because the DNS host appended the domain twice), or you are checking a different domain or subdomain than the one you send from.

Other provider checks