Set up SPF, DKIM and DMARC for SendGrid

The exact SPF, DKIM and DMARC records SendGrid needs, where to add them and how to check they pass and align, so SendGrid mail reaches the inbox.

Updated September 30, 2026

SendGrid is set up through Domain Authentication. With automated security on (the default) you add three CNAME records: em#### for the return path and SPF, plus s1._domainkey and s2._domainkey for DKIM. You also need a DMARC record at _dmarc. Until you authenticate the domain, SendGrid mail is signed and bounced through sendgrid.net and fails DMARC alignment.

Records at a glance

With automated security on (the default)
HostTypeValue
em####CNAME
u#######.wl###.sendgrid.net
The number after em and the target are unique to your account. SendGrid’s dashboard shows them.
s1._domainkeyCNAME
s1.domainkey.u#######.wl###.sendgrid.net
s2._domainkeyCNAME
s2.domainkey.u#######.wl###.sendgrid.net
_dmarcTXT
v=DMARC1; p=none; rua=mailto:<your report address>

With automated security off, SendGrid gives you records to manage yourself instead:

With automated security off
HostTypeValue
em####MX
10 mx.sendgrid.net
Receives bounces for the return-path subdomain.
em####TXT
v=spf1 include:sendgrid.net ~all
m1._domainkeyTXT
k=rsa; t=s; p=<key from SendGrid>

Set up SPF for SendGrid

You don’t need include:sendgrid.net in your root domain’s SPF record. After domain authentication, SendGrid uses the em#### subdomain as the envelope sender, and SPF is checked there. With automated security on, that subdomain is a CNAME to SendGrid, so SendGrid maintains its SPF and MX for you. With it off, you publish v=spf1 include:sendgrid.net ~all on the subdomain yourself.

As of September 2026, include:sendgrid.net costs two DNS lookups (it nests ab.sendgrid.net). If you do add it to a root record, for example because you relay through SendGrid from a system that uses your root domain as the envelope sender, merge it into your one existing record:

Combined root SPF record
v=spf1 include:spf.protection.outlook.com include:sendgrid.net -all

If you use DMARC Dojo’s hosted SPF, you add SendGrid in the dashboard instead of editing DNS, and changes that would exceed the 10-lookup limit are refused.

Set up DKIM with Domain Authentication

  1. In the SendGrid app, go to Settings > Sender Authentication and choose Get Started under Domain Authentication.
  2. Choose your DNS host and whether to brand links (see below).
  3. Enter the domain you send From, for example example.com.
  4. Under Advanced Settings, leave Use automated security checked unless you have a reason to manage SPF and DKIM records yourself. Optionally choose Use custom return path (a label instead of em####) or Use a custom DKIM selector if another service already uses s1/s2.
  5. Add the records SendGrid shows at your DNS host, then click Verify. SendGrid says verification can take up to 48 hours after you publish them.

The CNAMEs let SendGrid rotate DKIM keys without you touching DNS. To confirm signing, send a test and check for dkim=pass with header.d= your domain in the Authentication-Results header.

Make it pass DMARC (alignment)

  • Nothing aligns before domain authentication. SendGrid signs with its own domain and uses a sendgrid.net return path, so both SPF and DKIM pass for SendGrid, not for you.
  • After domain authentication, both align. DKIM signs with d=example.com, and the return path em####.example.com aligns with example.com under relaxed SPF alignment, the DMARC default.

Authenticate the exact domain you use in the From address (or its parent). If you send from news.example.com and authenticated example.com, relaxed alignment still works; with adkim=s or aspf=s it doesn’t. Subusers have their own authenticated domains, so make sure each subuser that sends has one. DMARC alignment covers the rules.

Add a DMARC record

SendGrid’s setup includes a basic v=DMARC1; p=none; record. If you already have a DMARC record, keep yours and don’t add a second one: two DMARC records cancel each other out. Make sure it has a report address:

Starter DMARC record
v=DMARC1; p=none; rua=mailto:<your report address>

DMARC Dojo recognizes SendGrid in DMARC reports, so you can see SendGrid traffic on its own and check it passes with alignment before you move to quarantine and reject.

Check your SendGrid DKIM records

Enter your domain to confirm the s1 and s2 selectors resolve, and see SPF and DMARC results with the fixes to make.

Troubleshooting

  • Verification fails on every record. Your DNS host appended the domain, creating em1234.example.com.example.com. Enter only the part before your domain.
  • DKIM fails through Cloudflare. Set the CNAMEs to DNS only. Proxied records don’t return SendGrid’s targets.
  • Reports still show d=sendgrid.net. Mail is going out from a subuser, or from a From domain that isn’t the one you authenticated. Authenticate that domain or subuser too.
  • Two DMARC records after setup. You added SendGrid’s _dmarc record next to an existing one. Delete one so exactly one remains.
  • Selector conflict. Another service already publishes s1._domainkey. Redo the setup with a custom DKIM selector.

Frequently asked questions

What is the em#### record SendGrid asks for?

It’s the return-path subdomain SendGrid uses as the envelope sender for your mail. Bounces go there, and SPF is checked there, which is why you don’t need SendGrid in your root SPF record.

Should I turn off automated security?

Usually not. With it on, SendGrid maintains the SPF and DKIM records behind your CNAMEs and can rotate keys. Turn it off only if your DNS host can’t publish CNAMEs on those names or policy requires you to hold the records yourself.

Is Single Sender Verification enough for DMARC?

No. Single Sender Verification only proves you own an address. Mail is still signed as sendgrid.net and won’t align, so it fails DMARC once your policy is quarantine or reject. Use Domain Authentication.

Do I need a dedicated IP for DMARC with SendGrid?

No. Alignment comes from Domain Authentication, which works on shared and dedicated IPs alike.

What happens to SendGrid mail at p=reject if the domain isn’t authenticated?

It fails DMARC, because neither the sendgrid.net signature nor the sendgrid.net return path matches your From domain. Receivers that honor your policy will reject it, so authenticate the domain before you enforce.