Set up SPF, DKIM and DMARC for Brevo

The exact SPF, DKIM and DMARC records Brevo needs, where to add them and how to check they pass and align, so Brevo mail reaches the inbox.

Updated September 30, 2026

Brevo (formerly Sendinblue) authenticates a domain with a brevo-code TXT record, two DKIM CNAMEs at brevo1._domainkey and brevo2._domainkey (older accounts get one TXT record at mail._domainkey) and a DMARC record, which Brevo requires. You don’t add Brevo to your SPF record on shared IPs. DMARC passes through DKIM; a branded subdomain adds SPF alignment.

Records at a glance

HostTypeValue
@TXT
brevo-code:<code from Brevo>
Proves you own the domain. It sits alongside your SPF record; don’t merge them.
brevo1._domainkeyCNAME
b1.<your-domain-with-dashes>.dkim.brevo.com
For example b1.example-com.dkim.brevo.com. Copy the exact value from Brevo.
brevo2._domainkeyCNAME
b2.<your-domain-with-dashes>.dkim.brevo.com
_dmarcTXT
v=DMARC1; p=none; rua=mailto:<your report address>
Required by Brevo. If you already have one, keep it; don’t add a second.

Set up SPF for Brevo

On Brevo’s shared IPs you don’t need an SPF record for Brevo at all. Brevo says SPF and MX records aren’t required to authenticate a domain, and it only shows them when you set up a dedicated IP. Messages use a Brevo-owned return-path domain, which already passes SPF.

An old include:spf.sendinblue.com (or include:spf.brevo.com) in your root SPF record doesn’t help DMARC on shared IPs, because your root domain isn’t the return-path. Leave your existing record as it is:

Your SPF record doesn’t change for Brevo on shared IPs
v=spf1 include:_spf.google.com -all

If you set up a branded subdomain or a dedicated IP, Brevo gives you the records for that subdomain (a CNAME that links it to Brevo for SPF and the return-path, plus an A record per dedicated IP). Those go on the subdomain, not in your root SPF record. With DMARC Dojo’s hosted SPF, senders that do need an include are added in the dashboard rather than in DNS.

Set up DKIM in Brevo

  1. In Brevo, open the account dropdown and select Settings > Senders, Domains, IPs > Domains.
  2. Click Add a domain (or Authenticate next to a domain already listed) and enter the domain after the @ in your sender address.
  3. Choose automatic authentication if Brevo supports your DNS host; it signs in to the host and adds the records. If your domain already has DMARC, Brevo asks whether to replace it. To keep yours, choose Authenticate the domain yourself instead.
  4. For manual setup, copy each record into your DNS host: the Brevo code (TXT), then either two DKIM records of CNAME type or one of TXT type, whichever your account shows, then DMARC.
  5. Click Authenticate this email domain. Each record shows “Value matched” when Brevo finds it. DNS can take up to 48 hours.

CNAME-type DKIM uses 2048-bit keys that Brevo hosts. TXT-type DKIM defaults to 1024 bits; Brevo support can switch you to a 2048-bit key (its value starts with sib2k). Brevo is rolling out a new Set up your domain flow that combines authentication, a branded subdomain and dedicated IPs; the records are the same kind.

Make it pass DMARC (alignment)

  • DKIM aligns once the domain is authenticated, because Brevo signs with your domain. That passes DMARC.
  • SPF doesn’t align on shared IPs without a branded subdomain, because the return-path is on Brevo’s domain.

The fix is a branded subdomain (such as send.example.com), which Brevo says enables full SPF alignment and moves tracking links and the return-path onto your domain. It’s optional on shared IPs and required with a dedicated IP, where your domain becomes the return-path. Until your domain is authenticated, Brevo replaces your sender address with one on brevosend.com. See DMARC alignment for how relaxed alignment treats subdomains.

Add DMARC

Brevo’s suggested record sends reports to Brevo. If you want to read them elsewhere, put your own address in rua or list both, separated by a comma:

Starter DMARC record with two report addresses
v=DMARC1; p=none; rua=mailto:<your report address>,mailto:rua@dmarc.brevo.com

Brevo checks for a rua tag and warns if it’s missing. DMARC Dojo recognizes Brevo in DMARC reports, so you can confirm its mail passes with alignment before moving to quarantine and reject (the safe path to p=reject).

Check your Brevo DKIM

Enter your domain to check DKIM, SPF and DMARC, with a score out of 100 and the fixes to make.

Troubleshooting

  • DKIM fails on Cloudflare. Turn off the proxy on both CNAMEs and disable CNAME flattening. With flattening on, Cloudflare serves the record as TXT and DKIM fails.
  • Multiple DMARC records. Adding Brevo’s record next to your own leaves two, and receivers ignore both. Merge them into one record with both rua addresses.
  • Records not detected. Hosts that append the domain turn brevo1._domainkey.example.com into …example.com.example.com. Enter only brevo1._domainkey, or add a trailing dot.
  • 2048-bit TXT key rejected. Values over 255 characters must be split into two quoted strings at hosts that limit TXT length.
  • Status drops back to “Not authenticated”. A record was changed or deleted. Brevo’s records must stay in place for as long as you send with Brevo.

Frequently asked questions

Do I still need include:spf.sendinblue.com?

Not on shared IPs. Brevo no longer asks for an SPF record unless you use a dedicated IP, and an include on your root domain doesn’t affect DMARC because Brevo’s return-path isn’t your root domain.

Why does my Brevo account show a TXT DKIM record instead of CNAMEs?

Some accounts still get the older single TXT record at mail._domainkey. Both work; publish whichever type your Domains page shows, exactly as shown.

Can I keep my existing DMARC record instead of Brevo’s?

Yes. Authenticate manually instead of automatically, so Brevo doesn’t replace it. Keep one DMARC record with a rua tag; you can add Brevo’s report address next to your own if you want its reports too.

What happens if I send from Brevo without authenticating my domain?

Brevo replaces your sender address with one on brevosend.com to protect deliverability to Gmail and Yahoo. Recipients see an unfamiliar address, so authenticate before you send.

Do I need to authenticate subdomains separately in Brevo?

Yes, if you send from them. Brevo authenticates the exact domain after the @, so marketing.example.com needs its own records. It inherits the parent’s DMARC policy unless it has its own.