Set up SPF, DKIM and DMARC for HubSpot

The exact SPF, DKIM and DMARC records HubSpot needs, where to add them and how to check they pass and align, so HubSpot mail reaches the inbox.

Updated September 30, 2026

To authenticate HubSpot, connect your email sending domain in Settings > Content > Domains & URLs > Email Sending. HubSpot gives you two DKIM CNAME records (like hs1-<Hub ID>._domainkey and hs2-<Hub ID>._domainkey), an SPF include for your account (like include:<Hub ID>.spf03.hubspotemail.net) and asks for a DMARC record. On HubSpot’s shared IPs, DMARC passes through DKIM; SPF passes on HubSpot’s own return-path domain.

Records at a glance

HostTypeValue
hs1-<Hub ID>._domainkeyCNAME
<value from HubSpot>
The target ends in dkim.hubspotemail.net. Copy it from the Required data column.
hs2-<Hub ID>._domainkeyCNAME
<value from HubSpot>
The second DKIM key. Publish both.
@TXT
v=spf1 include:<Hub ID>.spf03.hubspotemail.net -all
The include is specific to your account (the spf number varies). Merge it into your existing SPF record.
_dmarcTXT
v=DMARC1; p=none; rua=mailto:<your report address>

HubSpot’s setup screen lists every record your domain needs, and its documentation mentions MX records as part of the process too. Add exactly what the screen shows; the table above is the shape, not your values.

Set up SPF for HubSpot

HubSpot asks you to add its SPF include to your From domain, and the domain only shows as Authenticated once SPF, DKIM and DMARC all verify. Add the value from the Required data column after include: in your existing record. Don’t create a second SPF record, and keep one v=spf1 and one all at the end:

Google Workspace plus HubSpot in one SPF record
v=spf1 include:_spf.google.com include:<Hub ID>.spf03.hubspotemail.net -all

Older accounts may have been told to use include:shared.hubspot.com. Use whatever your current setup screen shows. Each include costs DNS lookups toward the limit of 10. With DMARC Dojo’s hosted SPF, you add HubSpot as a sender in the dashboard instead of editing this record, and changes that would pass the limit are refused.

Set up DKIM in HubSpot

  1. Click the settings icon in the top navigation bar, then go to Content > Domains & URLs in the left sidebar and open the Email Sending tab.
  2. Click Connect sending domain, enter an address you send marketing email from, click Next, and confirm the domain.
  3. Use Sign in with [provider] if HubSpot offers it for your DNS host, or choose No, I’ll set it up manually.
  4. For each record, copy the Host and Required data values into your DNS host. The two DKIM records are CNAMEs, so HubSpot hosts the keys and can rotate them.
  5. Wait at least 20 minutes (usually 10 to 70, up to 48 hours), then check the status on the same tab: Partially authenticated means DKIM works but SPF or DMARC is still missing.

You need domain settings permission. HubSpot recommends a sending domain that isn’t used to host a website; a subdomain like info.example.com works, and it should match the domain in your From address.

Make it pass DMARC (alignment)

  • DKIM aligns once the domain is connected. HubSpot signs with your domain, so the signature matches your From address. Until then, HubSpot won’t send with your domain in the From address at all: it rewrites it to a HubSpot-managed domain (for example user=yourcompany.com@hs-domain.com).
  • SPF doesn’t align on shared IPs. SPF is checked on the envelope return path, which HubSpot sets to its own domain on its shared servers. SPF passes there, but for HubSpot’s domain, not yours.
  • Dedicated IP customers configure SPF on their own return-path domain during IP setup, so their SPF can align too.

For most accounts, DKIM is what carries DMARC for HubSpot mail. That’s enough to pass, but it means a broken or missing DKIM record fails DMARC outright. See DMARC alignment for why.

Add DMARC

Starter DMARC record
v=DMARC1; p=none; rua=mailto:<your report address>

If you connect a subdomain, HubSpot accepts a DMARC record on the root domain, since subdomains inherit it. DMARC Dojo recognizes HubSpot in DMARC reports, so you can see its volume and whether it passes with alignment next to your other senders before you enforce (moving from p=none to p=reject).

Check your HubSpot DKIM and SPF

Enter your sending domain to check DKIM, SPF (with the lookup count) and DMARC, with the fixes to make.

Troubleshooting

  • Records show as missing. Many DNS hosts append the domain, turning hs1-123456._domainkey.example.com into hs1-123456._domainkey.example.com.example.com. Enter only hs1-123456._domainkey.
  • The DNS host rejects the CNAME. Some hosts refuse underscores in names. HubSpot’s records follow the DKIM standard, so ask your DNS host to add them.
  • Cloudflare breaks verification. HubSpot asks you to turn off proxying and domain-wide CNAME flattening for the sending domain’s records.
  • Two SPF records. Adding HubSpot as a new v=spf1 record instead of merging it makes SPF return a permanent error for every sender.
  • Stuck on Partially authenticated. DKIM is fine, but SPF or DMARC isn’t found yet. Check the root domain’s DMARC record exists and that the SPF include matches exactly.

Frequently asked questions

What happens if I don’t connect my domain to HubSpot?

HubSpot won’t send with your domain in the From address. It rewrites the sender to a HubSpot-managed domain, which looks unfamiliar to recipients and can hurt engagement.

Do I need a separate DMARC record for my HubSpot subdomain?

No. A subdomain inherits the root domain’s DMARC policy (or its sp= policy), and HubSpot treats that as authenticated. Add a subdomain record only if you want a different policy for it.

Can I connect more than one sending domain?

Yes. HubSpot accounts can connect up to 2,000 sending domains, and each needs its own DKIM records. Using separate subdomains for different brands or email types keeps their reputations apart.

Why does HubSpot mail pass DMARC even though SPF isn’t aligned?

DMARC needs only one aligned pass. HubSpot’s DKIM signature uses your domain, so it aligns even though SPF is checked on HubSpot’s own return-path domain.