SendGrid (Twilio): SPF, DKIM & DMARC Setup Guide
SendGrid's sender authentication requires publishing CNAME records for DKIM and optionally updating SPF. Getting this right protects your domain reputation — and separates it from shared IP pool issues.
1SPF Record Setup
Recommended SPF record for SendGrid:
v=spf1 include:sendgrid.net ~allSendGrid recommends using their DKIM authentication (CNAME method) instead of manual SPF. When you use SendGrid's domain authentication, SPF is handled automatically via CNAME. For manual setup, add include:sendgrid.net.
Step-by-step setup:
- 1In SendGrid dashboard, go to Settings → Sender Authentication
- 2Click Authenticate a Domain and select your DNS provider
- 3SendGrid will give you 3 CNAME records to add to your DNS
- 4Add all 3 CNAME records to your domain registrar
- 5Return to SendGrid and click Verify — this handles both SPF and DKIM
- 6Verify with our SPF and DKIM checkers after 24–48 hours
2DKIM Setup
Example DKIM record location:
s1._domainkey.yourdomain.comSendGrid uses CNAME-based DKIM delegation. You add CNAMEs that point to SendGrid's signing servers, which means SendGrid controls the key rotation. This is the recommended approach — no manual key management needed.
Step-by-step setup:
- 1In SendGrid, go to Settings → Sender Authentication → Domain Authentication
- 2Complete the domain authentication wizard
- 3Add the 3 CNAME records provided (2 for DKIM, 1 for SPF/tracking)
- 4Click Verify in SendGrid after DNS propagates (24–48h)
- 5Your DKIM selector will appear as s1._domainkey.yourdomain.com
- 6Test with our DKIM checker
3DMARC Policy
Recommended DMARC record:
v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com; pct=100Add as a TXT record at: _dmarc.yourdomain.com
SendGrid's DKIM authentication aligns with DMARC. Once domain authentication is set up, DMARC will pass automatically. Publish your DMARC record at _dmarc.yourdomain.com.
Common SendGrid Deliverability Issues
Emails from SendGrid going to spam
First check if your sending domain or SendGrid's shared IPs are blacklisted. If on shared IPs, consider a dedicated IP. Ensure domain authentication is complete — not just API key setup.
DKIM not verifying after adding CNAME records
CNAME propagation can take up to 48 hours. Verify the exact CNAME values match what SendGrid provided — no trailing dots, no extra spaces. Use our DKIM checker to confirm.
Domain blacklisted despite using SendGrid
Your domain reputation is separate from SendGrid's IP reputation. Check if your domain (not just IP) is blacklisted using our tool. Review your sending lists and complaint rates in SendGrid's Activity Feed.
550 5.1.1 The email account does not exist bounce errors
You're sending to invalid addresses. Enable SendGrid's Bounce handling and clean your list. High bounce rates will hurt your sender reputation and can get your account suspended.
Is Your SendGrid Domain Blacklisted?
Authentication passing is necessary — but not sufficient. Check if your sending domain or IP is on any of 60 blacklists. Free, instant, no signup.
Check Your Domain FreeChecks all 60 blacklists + SPF, DKIM, DMARC, MX in under 10 seconds