Fix guides › Newsletter and CRM email

Make Mailchimp, SendGrid and your CRM pass DMARC

Emails from newsletter tools, CRMs, invoicing and help desk systems often “pass SPF” yet still fail DMARC and land in spam. The fix is a setting most of these services call domain authentication.

Last reviewed 7 October 2026

Why it happens

DMARC only counts an SPF or DKIM pass if it’s for your domain, the one in the From address. Out of the box, most services send with their own return address and sign with their own domain. So SPF and DKIM pass, but for them, not for you, and DMARC fails.

You can see this for yourself: send a test email from the service to a Gmail address, open it, choose ⋮ › Show original, copy the headers and paste them into our header analyser. If it says the message was authenticated as another domain, this guide is the fix.

The fix: domain authentication

Each service gives you a few DNS records, usually two or three CNAME records, that let it sign your email with your domain using DKIM, and often use a return address on your domain too. Once they’re in place, DMARC passes.

  1. In the service, find the domain settings. Common names: Domain authentication, Sender authentication, Email sending domain or Verified domains.
  2. Add your domain. The service shows the records to create.
  3. Add each record at your DNS host exactly as shown. If your DNS is at Cloudflare, set CNAME records to DNS only (grey cloud).
  4. Return to the service and select Verify or Authenticate.

What the records look like

  • Mailchimp: CNAME records such as k2._domainkey and k3._domainkey, found under your account’s Domains settings.
  • SendGrid: CNAME records for s1._domainkey and s2._domainkey, plus one with a name like em1234 for the return address. Found under Settings › Sender Authentication.
  • CRMs and other tools (HubSpot, Zoho CRM, Salesforce, Xero, Freshdesk and so on) follow the same pattern with their own record names.

The exact names and values are specific to your account, so always copy them from the service.

Do I also need to add them to SPF?

Only if the service tells you to. DKIM signing with your domain is what matters for DMARC, and every include: you add to SPF uses up part of its 10-lookup limit. Many services that use a return address on your domain handle SPF through that instead. Check with the SPF checker before adding more.

Before you tighten DMARC

Make a list of every tool that sends email on behalf of your domain. Finance, marketing, sales and support teams often sign up for services IT doesn’t know about. Your DMARC reports list them all. Authenticate each one before moving your policy to quarantine or reject, or their email will start going to spam.

Check your work

Send another test email to Gmail and paste the headers into the header analyser. You want DMARC: Pass, with DKIM signed by your own domain.