Skip to content
Transactional Email80B+ emails/month

SendGrid (Twilio): SPF, DKIM & DMARC Setup Guide

SendGrid's sender authentication requires publishing CNAME records for DKIM and optionally updating SPF. Getting this right protects your domain reputation — and separates it from shared IP pool issues.

1SPF Record Setup

Recommended SPF record for SendGrid:

v=spf1 include:sendgrid.net ~all

SendGrid recommends using their DKIM authentication (CNAME method) instead of manual SPF. When you use SendGrid's domain authentication, SPF is handled automatically via CNAME. For manual setup, add include:sendgrid.net.

Step-by-step setup:

  1. 1In SendGrid dashboard, go to Settings → Sender Authentication
  2. 2Click Authenticate a Domain and select your DNS provider
  3. 3SendGrid will give you 3 CNAME records to add to your DNS
  4. 4Add all 3 CNAME records to your domain registrar
  5. 5Return to SendGrid and click Verify — this handles both SPF and DKIM
  6. 6Verify with our SPF and DKIM checkers after 24–48 hours

2DKIM Setup

Example DKIM record location:

s1._domainkey.yourdomain.com

SendGrid uses CNAME-based DKIM delegation. You add CNAMEs that point to SendGrid's signing servers, which means SendGrid controls the key rotation. This is the recommended approach — no manual key management needed.

Step-by-step setup:

  1. 1In SendGrid, go to Settings → Sender Authentication → Domain Authentication
  2. 2Complete the domain authentication wizard
  3. 3Add the 3 CNAME records provided (2 for DKIM, 1 for SPF/tracking)
  4. 4Click Verify in SendGrid after DNS propagates (24–48h)
  5. 5Your DKIM selector will appear as s1._domainkey.yourdomain.com
  6. 6Test with our DKIM checker

3DMARC Policy

Recommended DMARC record:

v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com; pct=100

Add as a TXT record at: _dmarc.yourdomain.com

SendGrid's DKIM authentication aligns with DMARC. Once domain authentication is set up, DMARC will pass automatically. Publish your DMARC record at _dmarc.yourdomain.com.

Common SendGrid Deliverability Issues

Emails from SendGrid going to spam

First check if your sending domain or SendGrid's shared IPs are blacklisted. If on shared IPs, consider a dedicated IP. Ensure domain authentication is complete — not just API key setup.

DKIM not verifying after adding CNAME records

CNAME propagation can take up to 48 hours. Verify the exact CNAME values match what SendGrid provided — no trailing dots, no extra spaces. Use our DKIM checker to confirm.

Domain blacklisted despite using SendGrid

Your domain reputation is separate from SendGrid's IP reputation. Check if your domain (not just IP) is blacklisted using our tool. Review your sending lists and complaint rates in SendGrid's Activity Feed.

550 5.1.1 The email account does not exist bounce errors

You're sending to invalid addresses. Enable SendGrid's Bounce handling and clean your list. High bounce rates will hurt your sender reputation and can get your account suspended.

Is Your SendGrid Domain Blacklisted?

Authentication passing is necessary — but not sufficient. Check if your sending domain or IP is on any of 60 blacklists. Free, instant, no signup.

Check Your Domain Free

Checks all 60 blacklists + SPF, DKIM, DMARC, MX in under 10 seconds

Related Free Tools

Other Email Provider Guides