1. Why ActiveCampaign authentication matters in 2026
ActiveCampaign requires domain verification before you can send campaigns, 1:1 emails, or notifications - and since 2024, Google and Yahoo require DKIM and DMARC for bulk senders anyway. The good news: ActiveCampaign does more of the SPF work for you than most platforms. The catch: that's exactly what confuses people who expect to add an SPF include by hand.
ActiveCampaign uses a Mailserver Domain CNAME that handles SPF alignment for you - so you usually don't add a manual SPF include. And because its DKIM always aligns with your domain, your mail passes DMARC on DKIM even when SPF alignment doesn't. DKIM is the piece that matters.
2. Two setup paths: Configure Domain vs. Set up manually
In ActiveCampaign, go to Settings → Advanced (sending-domain setup) and pick one:
Configure Domain - ActiveCampaign connects to a supported DNS provider and publishes the DKIM, Mailserver Domain (SPF), and DMARC records automatically. Fastest, fewest mistakes.
Set up manually - ActiveCampaign shows you the exact CNAME and TXT records to add at your DNS provider yourself. Use this if your DNS host isn't supported by the automatic flow.
3. Publish the DKIM and Mailserver Domain CNAMEs
Setting up manually, ActiveCampaign gives you two CNAME records: the DKIM record (signs your mail) and the Mailserver Domain record (aligns SPF). Add both exactly as shown.
dk._domainkey CNAME dkim.emsd1.comem._yourdomain CNAME mailserver.emsd1.comThe DKIM CNAME is the important one for DMARC: it aligns to your domain, so DMARC passes on DKIM regardless of SPF.
4. SPF: only if you set up manually and need it
Because the Mailserver Domain CNAME aligns SPF for you, you generally don't add a manual SPF include. If your configuration does require one, the include is emsd1.com, merged into your single SPF record:
v=spf1 include:emsd1.com ~allOne SPF record per domain, under ten lookups. Don't duplicate SPF records - merge.
5. Publish your DMARC policy
v=DMARC1; p=none; rua=mailto:[email protected]Start at p=none, confirm DKIM alignment in reports, then tighten to p=quarantine and p=reject.
ActiveCampaign rewrites links for click tracking. While the tracking domain isn't used in DMARC evaluation, a misconfigured one can hurt deliverability and trust. If you use a custom tracking domain, make sure its CNAME is set up correctly alongside your auth records.
6. Verify in ActiveCampaign
After publishing, return to ActiveCampaign and click Check DNS. Once propagated (minutes to 48 hours), your domain shows as verified. A nice side effect of proper DKIM: Gmail drops the "via activecampaign" header, so mail looks fully yours.
Run your domain through our CRM DNS Verifier - it checks your records against ActiveCampaign's spec, confirms DKIM is aligning, and flags a missing Mailserver Domain CNAME or DMARC policy.
Verify my ActiveCampaign DNS →7. Authenticated but still landing in spam?
Beyond authentication: (1) is your domain or IP blacklisted? Run a blacklist sweep. (2) is your content tripping filters? Run a spam score check. (3) is your list stale? Clean it with our List Cleaner.