Establishing signal
LoadingEstablishing signal
LoadingSendGrid's “Domain Authentication” wizard covers SPF and DKIM through CNAMEs. Completing it — plus your own DMARC record — is what gets you through Gmail and Yahoo's bulk-sender checks.
In SendGrid: Settings → Sender Authentication → Authenticate Your Domain. SendGrid generates three CNAME records, typically:
em1234.yourdomain.com → u1234.wl.sendgrid.net (the envelope/bounce subdomain that makes SPF pass and align)s1._domainkey.yourdomain.com → s1.domainkey.u1234.wl.sendgrid.nets2._domainkey.yourdomain.com → s2.domainkey.u1234.wl.sendgrid.netThe s1/s2 selectors give you a DKIM signature with d=yourdomain.com — aligned with your From address. “Single Sender Verification” alone does none of this.
With domain authentication, the envelope-from is your em subdomain, whose SPF SendGrid manages via the CNAME. Adding include:sendgrid.net to your root record is unnecessary and wastes one of the 10 SPF lookups — check yours with the SPF lookup counter.
Add a DMARC TXT record at _dmarc.yourdomain.com:
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com
For marketing sends, enable SendGrid's subscription tracking / unsubscribe settings so the List-Unsubscribe + List-Unsubscribe-Post headers are added.
include:sendgrid.net plus other vendor includes pushing the SPF record over 10 lookups.sendgrid.net — enable Link Branding so click domains match your brand.Run a free scan to confirm SPF/DMARC are live, then send yourself a campaign and paste its headers to verify DKIM alignment and one-click unsubscribe end-to-end.