Set up SPF, DKIM and DMARC for Mailchimp

The exact SPF, DKIM and DMARC records Mailchimp needs, where to add them and how to check they pass and align, so Mailchimp mail reaches the inbox.

Updated September 30, 2026

Mailchimp needs two DKIM CNAME records, k2._domainkey pointing to dkim2.mcsv.net and k3._domainkey pointing to dkim3.mcsv.net, plus a DMARC record at _dmarc. You don’t need to add Mailchimp to your SPF record: Mailchimp uses its own bounce domain and SPF record, so your mail passes DMARC through aligned DKIM.

Records at a glance

HostTypeValue
k2._domainkeyCNAME
dkim2.mcsv.net
Copy the values from your Mailchimp account to be sure they match what Mailchimp expects.
k3._domainkeyCNAME
dkim3.mcsv.net
_dmarcTXT
v=DMARC1; p=none; rua=mailto:<your report address>
Mailchimp requires a DMARC record. Keep the one you have if it already exists.

Set up SPF for Mailchimp (you probably don’t need to)

Mailchimp’s domain authentication asks for two CNAMEs and a DMARC record, and no SPF change. Campaigns go out with a Mailchimp-owned envelope sender (the Return-Path), typically on domains such as mcsv.net or mcdlv.net. Receivers check SPF against that domain, and Mailchimp maintains its SPF record.

So the old include:servers.mcsv.net does nothing for campaign mail. If your SPF record still has it, you can remove it and get a DNS lookup back:

Before and after
v=spf1 include:_spf.google.com include:servers.mcsv.net ~all
v=spf1 include:_spf.google.com ~all

Keeping your root SPF record short matters once you use several services (see the 10-lookup limit). With DMARC Dojo’s hosted SPF you add or remove senders in the dashboard instead of editing DNS.

Set up DKIM (domain authentication)

  1. Verify the domain first. Mailchimp sends a link or code to an address at that domain, and you can’t authenticate a domain you haven’t verified.
  2. Click your profile icon and go to Account & billing, then the Domains tab. Next to the domain, choose Start authentication.
  3. Mailchimp may offer to set records up automatically for supported DNS hosts. Otherwise, copy the two CNAME records and the TXT record it shows.
  4. At your DNS host, create CNAME records at k2._domainkey and k3._domainkey and, if you don’t already have one, the DMARC TXT record at _dmarc.
  5. Return to Mailchimp and let it validate the records. Mailchimp says most records update within minutes but it can take up to 48 hours.

Mailchimp hosts the keys behind the CNAMEs; as of September 2026 they are 2048-bit keys. To confirm signing, send a test campaign to yourself and look for dkim=pass with header.d= your domain. Until the domain is authenticated, recipients may see “via mcsv.net” or a similar Mailchimp domain next to your From name.

Make it pass DMARC (alignment)

  • SPF never aligns for Mailchimp campaigns, because the Return-Path is a Mailchimp domain. That’s normal and not something to fix.
  • DKIM aligns once you authenticate the domain. Mailchimp then signs with d= your domain, which matches the From address.

That makes DKIM the only path to a DMARC pass, so authenticate every domain you use as a From address. Don’t send campaigns from a free address such as Gmail or Yahoo: you can’t authenticate those domains, so the mail can’t align, and Yahoo publishes p=reject. DMARC alignment explains the rules.

Add a DMARC record

Mailchimp requires a DMARC record on authenticated domains, and Gmail and Yahoo require one from bulk senders. The minimum is v=DMARC1; p=none. Add a report address so you can see results:

Starter DMARC record
v=DMARC1; p=none; rua=mailto:<your report address>

DMARC Dojo recognizes Mailchimp in DMARC reports, so you can check that campaign traffic passes DKIM with alignment before you move to quarantine and reject. Expect Mailchimp rows to show SPF “fail” for your domain; the DKIM result is the one that counts.

Check your Mailchimp DKIM records

Enter your domain to confirm k2 and k3 resolve, and see your DMARC and SPF results with the fixes to make.

Troubleshooting

  • Authentication won’t validate. The DNS host appended your domain, creating k2._domainkey.example.com.example.com. Enter just k2._domainkey.
  • DKIM fails through Cloudflare. Set both CNAMEs to DNS only so they resolve to Mailchimp’s keys.
  • Mailchimp says a DMARC record is missing. The record is at the wrong name, or there are two DMARC records, which invalidates both. Keep exactly one at _dmarc.
  • Mail still shows “via mcsv.net”. The campaign’s From address uses a domain you haven’t authenticated, such as a different brand domain or a subdomain. Authenticate that domain too.

Frequently asked questions

Should I remove include:servers.mcsv.net from my SPF record?

Yes, if Mailchimp campaigns are the only reason it’s there. Mailchimp’s current setup doesn’t use it, and removing it frees a DNS lookup.

Why do my DMARC reports show SPF failing for Mailchimp?

SPF is checked against Mailchimp’s own bounce domain, so it can’t align with yours. DMARC passes as long as DKIM passes with your domain, which is what domain authentication sets up.

Can I authenticate a Gmail or Outlook.com address in Mailchimp?

No. You can only authenticate domains whose DNS you control. Send from an address at your own domain.

Do I need to authenticate each domain separately?

Yes. Each domain you use in a From address needs its own verification and its own k2 and k3 CNAMEs.

What happens if I send from Mailchimp without authenticating my domain?

Mail is signed with a Mailchimp domain instead of yours, so it passes DKIM for Mailchimp but fails DMARC alignment for you. At p=none it’s still delivered, often showing “via mcsv.net”; at quarantine or reject it goes to spam or bounces.