SPF and DKIM for SendGrid

SendGrid needs include:sendgrid.net in your SPF record. With automated security on, SendGrid handles SPF through a CNAME for its em subdomain, so the root include is not needed. Check your domain below once the records are in.

  • Free
  • No Sign-Up
  • Live Lookup

Examples:

SPF Checker

SendGrid records

SPF Includeinclude:sendgrid.net
SPF Record (on Its Own)v=spf1 include:sendgrid.net ~all
With Another Providerv=spf1 include:sendgrid.net include:other.example ~all
DKIM Selectorss1, s2 (CNAME)
Starter DMARC (_dmarc)v=DMARC1; p=none; rua=mailto:[email protected]

With automated security on, SendGrid handles SPF through a CNAME for its em subdomain, so the root include is not needed.

DKIM: CNAME records at s1._domainkey and s2._domainkey, created when you authenticate the domain.

A domain can have only one SPF record. If you already send through another service, add the include to your existing record rather than creating a second one, and keep the total under 10 DNS lookups.

Once SPF and DKIM pass, add a DMARC record at _dmarc with p=none and a reporting address, read the reports for a couple of weeks, then move to quarantine and reject.

Questions

What is the SPF record for SendGrid?
v=spf1 include:sendgrid.net ~all. If you also send through other services, add their includes to the same record.
Where do I find the DKIM record for SendGrid?
CNAME records at s1._domainkey and s2._domainkey, created when you authenticate the domain.
Do I need DMARC with SendGrid?
Yes. Gmail and Yahoo require DMARC for bulk senders, and it is what stops others sending as your domain. Start with p=none and move to reject.
How long do new SPF and DKIM records take to work?
As soon as resolvers see them, usually within minutes; at most the old record's TTL. Use the checker above to confirm.

Your customers' VMs sending spam?

Frabs spots outbound spam from any VM within seconds and stops it, before your IPs end up on a blocklist.