Mailchimp SPF, DKIM and DMARC
Two CNAMEs and a DMARC record — and one SPF include you can probably delete.
Mailchimp's current domain authentication is two DKIM CNAME records plus one DMARC TXT record. There is no SPF record in the flow, because campaigns go out with Mailchimp's own envelope sender — SPF authenticates Mailchimp's domain, and DMARC aligns through your DKIM signature instead.
That is the detail most Mailchimp guides get wrong. If you are following an older article that tells you to add `include:servers.mcsv.net` to your SPF record, that include is not what makes your campaigns pass, and it is consuming part of your 10-lookup budget.
The records Mailchimp needs
CNAME · host k<n>._domainkey
dkim<n>.mcsv.net
Two of these, with the exact selector numbers shown on the Domains page in your Mailchimp account. Enter the bare host, e.g. `k2._domainkey`, not the full name.
TXT · host _dmarc
v=DMARC1; p=none; rua=mailto:<your reporting address>
Mailchimp includes a DMARC record in the setup. Add your own reporting address so the reports go somewhere you read.
Values shown with placeholders are account-specific — copy the exact value from Mailchimp, never from a guide.
What goes wrong
- The host field gets the domain appended
- Mailchimp warns about this directly: entering `k2._domainkey.example.com` in a panel that appends the zone creates `k2._domainkey.example.com.example.com`. Enter only `k2._domainkey`.
- A stale SPF include is a silent cost
- An unused `include:servers.mcsv.net` does not break anything on its own, but combined with Google Workspace or Microsoft 365 plus two other tools it is what tips you over the 10-lookup limit into a PermError.
- Verifying the email address is only step one
- Mailchimp lets you send after verifying a From address. Verification is not authentication: without the DKIM CNAMEs your campaigns have no aligned signature and fail DMARC.
- Campaigns are the thing most likely to be filtered
- Bulk campaign mail is judged on list hygiene, complaint rate and content as well as authentication. Fixing DNS removes the authentication reasons for filtering; it does not address list quality.
Questions
- Do I need an SPF record for Mailchimp?
- Not for campaigns. Mailchimp's current setup is DKIM CNAMEs plus DMARC, and campaign mail uses Mailchimp's envelope sender. You still need SPF for whatever sends your ordinary business mail.
- What is the Mailchimp DKIM selector?
- A `k<n>._domainkey` name — the exact numbers are account-specific and shown on your Mailchimp Domains page, targeting `dkim<n>.mcsv.net`. Older setups used `k1._domainkey` pointing at `dkim.mcsv.net`.
- Why are my Mailchimp emails going to spam?
- Check authentication first: DKIM CNAMEs resolving, DMARC published, and alignment confirmed. If authentication is clean, the remaining causes are list quality, complaint rate and content — which DNS changes cannot fix.
- Can I remove include:servers.mcsv.net?
- Once you have confirmed nothing else sends mail using your root domain as the envelope sender, yes. Run the SPF check first to see what else is in the record and what each mechanism costs.
Fix this from ChatGPT or Claude
MailVakt is an MCP server, so your assistant can run this check itself, read the findings and walk you through the DNS edit. Ask it:
“example.com sends campaigns through Mailchimp. Check its DKIM and DMARC, and tell me whether the Mailchimp SPF include is still doing anything.”
- Claude: Settings → Connectors → Add custom connector, then paste
https://mcp.mailvakt.com/mcp. - Cursor and other MCP clients: add the same address as an MCP server. Setup details.
Checks are free and need no account. Sign in only to collect DMARC reports for a domain.