Set up SPF, DKIM and DMARC for SendGrid
The exact SPF, DKIM and DMARC records SendGrid needs, where to add them and how to check they pass and align, so SendGrid mail reaches the inbox.
Updated September 30, 2026
SendGrid is set up through Domain Authentication. With automated security on (the default) you add three CNAME records: em#### for the return path and SPF, plus s1._domainkey and s2._domainkey for DKIM. You also need a DMARC record at _dmarc. Until you authenticate the domain, SendGrid mail is signed and bounced through sendgrid.net and fails DMARC alignment.
Records at a glance
| Host | Type | Value |
|---|---|---|
em#### | CNAME | u#######.wl###.sendgrid.netThe number after em and the target are unique to your account. SendGrid’s dashboard shows them. |
s1._domainkey | CNAME | s1.domainkey.u#######.wl###.sendgrid.net |
s2._domainkey | CNAME | s2.domainkey.u#######.wl###.sendgrid.net |
_dmarc | TXT | v=DMARC1; p=none; rua=mailto:<your report address> |
With automated security off, SendGrid gives you records to manage yourself instead:
| Host | Type | Value |
|---|---|---|
em#### | MX | 10 mx.sendgrid.netReceives bounces for the return-path subdomain. |
em#### | TXT | v=spf1 include:sendgrid.net ~all |
m1._domainkey | TXT | k=rsa; t=s; p=<key from SendGrid> |
Set up SPF for SendGrid
You don’t need include:sendgrid.net in your root domain’s SPF record. After domain authentication, SendGrid uses the em#### subdomain as the envelope sender, and SPF is checked there. With automated security on, that subdomain is a CNAME to SendGrid, so SendGrid maintains its SPF and MX for you. With it off, you publish v=spf1 include:sendgrid.net ~all on the subdomain yourself.
As of September 2026, include:sendgrid.net costs two DNS lookups (it nests ab.sendgrid.net). If you do add it to a root record, for example because you relay through SendGrid from a system that uses your root domain as the envelope sender, merge it into your one existing record:
v=spf1 include:spf.protection.outlook.com include:sendgrid.net -allIf you use DMARC Dojo’s hosted SPF, you add SendGrid in the dashboard instead of editing DNS, and changes that would exceed the 10-lookup limit are refused.
Set up DKIM with Domain Authentication
- In the SendGrid app, go to Settings > Sender Authentication and choose Get Started under Domain Authentication.
- Choose your DNS host and whether to brand links (see below).
- Enter the domain you send From, for example
example.com. - Under Advanced Settings, leave Use automated security checked unless you have a reason to manage SPF and DKIM records yourself. Optionally choose Use custom return path (a label instead of
em####) or Use a custom DKIM selector if another service already usess1/s2. - Add the records SendGrid shows at your DNS host, then click Verify. SendGrid says verification can take up to 48 hours after you publish them.
The CNAMEs let SendGrid rotate DKIM keys without you touching DNS. To confirm signing, send a test and check for dkim=pass with header.d= your domain in the Authentication-Results header.
Make it pass DMARC (alignment)
- Nothing aligns before domain authentication. SendGrid signs with its own domain and uses a
sendgrid.netreturn path, so both SPF and DKIM pass for SendGrid, not for you. - After domain authentication, both align. DKIM signs with
d=example.com, and the return pathem####.example.comaligns withexample.comunder relaxed SPF alignment, the DMARC default.
Authenticate the exact domain you use in the From address (or its parent). If you send from news.example.com and authenticated example.com, relaxed alignment still works; with adkim=s or aspf=s it doesn’t. Subusers have their own authenticated domains, so make sure each subuser that sends has one. DMARC alignment covers the rules.
Add a DMARC record
SendGrid’s setup includes a basic v=DMARC1; p=none; record. If you already have a DMARC record, keep yours and don’t add a second one: two DMARC records cancel each other out. Make sure it has a report address:
v=DMARC1; p=none; rua=mailto:<your report address>DMARC Dojo recognizes SendGrid in DMARC reports, so you can see SendGrid traffic on its own and check it passes with alignment before you move to quarantine and reject.
Check your SendGrid DKIM records
Enter your domain to confirm the s1 and s2 selectors resolve, and see SPF and DMARC results with the fixes to make.
Troubleshooting
- Verification fails on every record. Your DNS host appended the domain, creating
em1234.example.com.example.com. Enter only the part before your domain. - DKIM fails through Cloudflare. Set the CNAMEs to DNS only. Proxied records don’t return SendGrid’s targets.
- Reports still show d=sendgrid.net. Mail is going out from a subuser, or from a From domain that isn’t the one you authenticated. Authenticate that domain or subuser too.
- Two DMARC records after setup. You added SendGrid’s
_dmarcrecord next to an existing one. Delete one so exactly one remains. - Selector conflict. Another service already publishes
s1._domainkey. Redo the setup with a custom DKIM selector.
Frequently asked questions
What is the em#### record SendGrid asks for?
It’s the return-path subdomain SendGrid uses as the envelope sender for your mail. Bounces go there, and SPF is checked there, which is why you don’t need SendGrid in your root SPF record.
Should I turn off automated security?
Usually not. With it on, SendGrid maintains the SPF and DKIM records behind your CNAMEs and can rotate keys. Turn it off only if your DNS host can’t publish CNAMEs on those names or policy requires you to hold the records yourself.
Is Single Sender Verification enough for DMARC?
No. Single Sender Verification only proves you own an address. Mail is still signed as sendgrid.net and won’t align, so it fails DMARC once your policy is quarantine or reject. Use Domain Authentication.
Do I need a dedicated IP for DMARC with SendGrid?
No. Alignment comes from Domain Authentication, which works on shared and dedicated IPs alike.
What happens to SendGrid mail at p=reject if the domain isn’t authenticated?
It fails DMARC, because neither the sendgrid.net signature nor the sendgrid.net return path matches your From domain. Receivers that honor your policy will reject it, so authenticate the domain before you enforce.