SendGrid SPF, DKIM and DMARC
What SendGrid domain authentication publishes, and why your root SPF usually stays untouched.
SendGrid calls this domain authentication, and with automated security on — the default — it is entirely CNAME-based. You delegate three names to SendGrid, and SendGrid maintains the SPF and DKIM values behind them so you never edit a key by hand.
The consequence surprises people: with automated security on you do **not** add `include:sendgrid.net` to your root SPF record. SendGrid signs with your domain and uses a delegated subdomain as the envelope sender, so DMARC aligns through DKIM.
The records SendGrid needs
CNAME · host em<nnnn>
u<nnnnnnnn>.wl<nnn>.sendgrid.net
The delegated sending subdomain. It carries SendGrid's SPF and is the envelope sender for your mail.
CNAME · host s1._domainkey
s1.domainkey.u<nnnnnnnn>.wl<nnn>.sendgrid.net
First DKIM selector. SendGrid rotates the key behind this name.
CNAME · host s2._domainkey
s2.domainkey.u<nnnnnnnn>.wl<nnn>.sendgrid.net
Second DKIM selector. Both are required, for the same rotation reason as Microsoft 365.
TXT · host _dmarc
v=DMARC1; p=none;
SendGrid now includes a DMARC record in the setup. Add a `rua=mailto:` address so you actually get the reports.
Values shown with placeholders are account-specific — copy the exact value from SendGrid, never from a guide.
What goes wrong
- Automated security off is a different, worse setup
- Turning it off replaces the CNAMEs with an MX on the subdomain, a TXT SPF of `v=spf1 include:sendgrid.net ~all`, and a hand-managed `m1._domainkey` TXT key. You then own key rotation. Leave automated security on unless you have a specific reason.
- A leftover include:sendgrid.net costs you a lookup
- If you added it before switching to automated security, it is doing nothing for your campaign mail and is spending one of your 10 SPF lookups. Remove it once you have confirmed nothing else sends with your root domain as the envelope sender.
- Single Sender Verification is not authentication
- Verifying one From address lets you send, but it does not give you aligned DKIM, so DMARC fails. Domain authentication is the thing that makes your mail pass.
- The subdomain must not be proxied
- If your DNS host proxies or flattens CNAMEs, the delegation breaks and DKIM stops resolving. On Cloudflare, these records must be DNS-only.
Questions
- What is the SendGrid SPF record?
- With automated security on, there is none to add — SendGrid publishes SPF behind the `em<nnnn>` CNAME. With it off, add `v=spf1 include:sendgrid.net ~all` on the sending subdomain SendGrid gives you.
- What are the SendGrid DKIM selectors?
- `s1` and `s2` with automated security on, published as CNAMEs at `s1._domainkey` and `s2._domainkey`. With it off, a single TXT key at `m1._domainkey`.
- Why does my SendGrid mail fail DMARC?
- Almost always because only Single Sender Verification is set up, or because the DKIM CNAMEs do not resolve. Run the check above with selector `s1` to see whether the key is reachable.
- Do I need a separate subdomain for SendGrid?
- SendGrid creates one for you as the `em<nnnn>` CNAME. Using a dedicated sending subdomain for bulk mail is still good practice because it keeps its reputation and its SPF budget separate from your business mail.
Fix this from ChatGPT or Claude
MailVakt is an MCP server, so your assistant can run this check itself, read the findings and walk you through the DNS edit. Ask it:
“example.com sends through SendGrid. Check whether its DKIM selectors s1 and s2 resolve and whether DMARC will align.”
- Claude: Settings → Connectors → Add custom connector, then paste
https://mcp.mailvakt.com/mcp. - Cursor and other MCP clients: add the same address as an MCP server. Setup details.
Checks are free and need no account. Sign in only to collect DMARC reports for a domain.