Skip to main content
CRM Setup · 12 min read

SPF, DKIM and DMARC for ActiveCampaign in 2026.

The exact DNS records ActiveCampaign needs, the Configure-Domain vs manual paths, and why its Mailserver Domain CNAME means you usually don't add an SPF include by hand. DKIM is what carries DMARC.

Updated May 2026·By EmailSheriff

1. Why ActiveCampaign authentication matters in 2026

ActiveCampaign requires domain verification before you can send campaigns, 1:1 emails, or notifications - and since 2024, Google and Yahoo require DKIM and DMARC for bulk senders anyway. The good news: ActiveCampaign does more of the SPF work for you than most platforms. The catch: that's exactly what confuses people who expect to add an SPF include by hand.

The ActiveCampaign difference

ActiveCampaign uses a Mailserver Domain CNAME that handles SPF alignment for you - so you usually don't add a manual SPF include. And because its DKIM always aligns with your domain, your mail passes DMARC on DKIM even when SPF alignment doesn't. DKIM is the piece that matters.

CNAME
How ActiveCampaign handles both DKIM and the Mailserver/SPF domain
DKIM
The protocol that carries ActiveCampaign DMARC alignment
30 days
Minimum sending-domain age ActiveCampaign recommends
48 hr
Worst-case DNS propagation after you publish a record

2. Two setup paths: Configure Domain vs. Set up manually

In ActiveCampaign, go to Settings → Advanced (sending-domain setup) and pick one:

Configure Domain - ActiveCampaign connects to a supported DNS provider and publishes the DKIM, Mailserver Domain (SPF), and DMARC records automatically. Fastest, fewest mistakes.

Set up manually - ActiveCampaign shows you the exact CNAME and TXT records to add at your DNS provider yourself. Use this if your DNS host isn't supported by the automatic flow.

3. Publish the DKIM and Mailserver Domain CNAMEs

Setting up manually, ActiveCampaign gives you two CNAME records: the DKIM record (signs your mail) and the Mailserver Domain record (aligns SPF). Add both exactly as shown.

DNS · ActiveCampaign CNAMEs (example - use your own values)
dk._domainkey CNAME dkim.emsd1.comem._yourdomain CNAME mailserver.emsd1.com

The DKIM CNAME is the important one for DMARC: it aligns to your domain, so DMARC passes on DKIM regardless of SPF.

4. SPF: only if you set up manually and need it

Because the Mailserver Domain CNAME aligns SPF for you, you generally don't add a manual SPF include. If your configuration does require one, the include is emsd1.com, merged into your single SPF record:

DNS · only if needed - merged single SPF record
v=spf1 include:emsd1.com ~all

One SPF record per domain, under ten lookups. Don't duplicate SPF records - merge.

5. Publish your DMARC policy

DNS · TXT record at _dmarc.yourdomain.com
v=DMARC1; p=none; rua=mailto:[email protected]

Start at p=none, confirm DKIM alignment in reports, then tighten to p=quarantine and p=reject.

Don't forget the link-tracking domain

ActiveCampaign rewrites links for click tracking. While the tracking domain isn't used in DMARC evaluation, a misconfigured one can hurt deliverability and trust. If you use a custom tracking domain, make sure its CNAME is set up correctly alongside your auth records.

6. Verify in ActiveCampaign

After publishing, return to ActiveCampaign and click Check DNS. Once propagated (minutes to 48 hours), your domain shows as verified. A nice side effect of proper DKIM: Gmail drops the "via activecampaign" header, so mail looks fully yours.

Confirm it independently

Run your domain through our CRM DNS Verifier - it checks your records against ActiveCampaign's spec, confirms DKIM is aligning, and flags a missing Mailserver Domain CNAME or DMARC policy.

7. Authenticated but still landing in spam?

Beyond authentication: (1) is your domain or IP blacklisted? Run a blacklist sweep. (2) is your content tripping filters? Run a spam score check. (3) is your list stale? Clean it with our List Cleaner.

8. Frequently asked questions

Do I need an SPF record for ActiveCampaign?
Usually not a manual one. ActiveCampaign handles SPF for you via a Mailserver Domain CNAME record that aligns SPF on your behalf. If you set up manually and need an include, it's include:emsd1.com merged into your single SPF record. But because ActiveCampaign's DKIM always aligns with your domain, your mail passes DMARC on DKIM even if SPF alignment doesn't - so DKIM is the key piece.
What is the ActiveCampaign Mailserver Domain CNAME?
It's a CNAME record ActiveCampaign has you publish that points your sending subdomain at ActiveCampaign's infrastructure and aligns SPF using your organizational domain. Combined with the DKIM CNAME, it means ActiveCampaign manages SPF/DKIM alignment for you rather than you hand-crafting SPF includes.
How do I set up authentication in ActiveCampaign?
Go to Settings, then Advanced (or the sending-domain setup), and choose one of two options: Configure Domain, which auto-publishes DKIM, Mailserver Domain (SPF), and DMARC records to a supported DNS provider for you; or Set up manually, which gives you the CNAME and TXT records to add yourself. After publishing, click Check DNS to verify.
Why is ActiveCampaign authenticated but emails still go to spam?
Authentication confirms your records resolve, not that you'll inbox. Watch for: a missing or p=none DMARC policy, misconfigured link-tracking domains (ActiveCampaign rewrites links and the tracking domain should be set up properly), a blacklisted domain, spammy content, or a stale list. Confirm DKIM alignment, then check reputation and list health.

Keep your sending healthy

CRM DNS Verifier
Forensic verification for Pipedrive, ActiveCampaign, HubSpot, Salesforce and more - finds the exact misconfigurations that break authentication.
Full Audit
All 6 deliverability checks on a domain in 30 seconds, graded A-F. Catches SPF lookup overflow and DKIM alignment issues.
DNS Checker
SPF · DKIM · DMARC · MX with plain-English explanations. Includes a 10-lookup counter for SPF.