ConvertKit / Kit: SPF, DKIM & DMARC Setup Guide
ConvertKit's custom sending domain feature requires DNS authentication. Getting it right means your emails show your domain — not convertkit.com — and pass authentication at every inbox provider.
1SPF Record Setup
Recommended SPF record for ConvertKit:
v=spf1 include:spf.convertkit.com ~allConvertKit uses CNAME-based domain authentication for custom sending domains. The SPF and DKIM are handled via CNAMEs that point to ConvertKit's infrastructure. Available on Creator and Creator Pro plans.
Step-by-step setup:
- 1In ConvertKit, go to Settings → Email → Custom Sending Domain
- 2Enter your sending subdomain (e.g., mail.yourdomain.com or email.yourdomain.com)
- 3ConvertKit provides CNAME records to add
- 4Add the CNAME records to your DNS
- 5Click Verify in ConvertKit after 24–48 hours
- 6Set this domain as your default sending domain
2DKIM Setup
Example DKIM record location:
ck1._domainkey.yourdomain.comConvertKit's DKIM is configured via CNAME delegation as part of the custom sending domain setup. The DKIM selector will reference ConvertKit's signing infrastructure.
Step-by-step setup:
- 1Complete the custom sending domain setup in ConvertKit
- 2The DKIM CNAMEs are included in the records ConvertKit provides
- 3Verify all CNAMEs are correctly propagated
- 4ConvertKit's dashboard shows verification status for each record
- 5Test with our DKIM checker using your sending subdomain
3DMARC Policy
Recommended DMARC record:
v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com; sp=quarantine; pct=100Add as a TXT record at: _dmarc.yourdomain.com
Since ConvertKit sends from a subdomain of your domain, include sp=quarantine in your DMARC record to ensure subdomain protection. Publish at _dmarc.yourdomain.com.
Common ConvertKit Deliverability Issues
ConvertKit emails still showing 'via convertkit.com'
Custom sending domain setup must be completed and verified. This feature requires a paid plan. Once verified, new broadcasts will use your custom domain — existing scheduled emails may still use the old domain.
Low open rates after switching to custom domain
Your custom domain needs to build a reputation. Start with smaller segments, monitor engagement, and gradually increase volume. Check if your domain is blacklisted with our tool.
ConvertKit CNAME verification failing
CNAME records can take up to 48 hours to propagate. Check for conflicts — CNAME records can't coexist with other record types at the same subdomain. Use our DNS Lookup tool to verify propagation.
Is Your ConvertKit Domain Blacklisted?
Authentication passing is necessary — but not sufficient. Check if your sending domain or IP is on any of 60 blacklists. Free, instant, no signup.
Check Your Domain FreeChecks all 60 blacklists + SPF, DKIM, DMARC, MX in under 10 seconds