1. Why HubSpot authentication matters in 2026
If you're sending email through HubSpot and not setting up SPF, DKIM, and DMARC properly, your campaigns are going to spam - even if HubSpot's dashboard shows everything as "verified." This is one of the most common deliverability problems we see, and it has gotten dramatically worse since Google and Yahoo's February 2024 sender requirements took effect.
Here's what changed: any domain sending more than 5,000 messages per day to Gmail or Yahoo must now have SPF, DKIM, AND DMARC configured correctly. Below that threshold, DMARC isn't strictly required, but missing authentication still triggers spam-folder placement at every major inbox provider. There is no longer a "small sender" exception.
HubSpot makes this both easier and harder than it should be. Easier because their dashboard generates the exact DNS records you need and walks you through entering them. Harder because their verification only checks that records exist - not that they're correct for your specific configuration. We've seen "verified" HubSpot accounts where 60% of campaigns land in spam because of an SPF lookup-limit overflow that HubSpot's verification doesn't catch.
Setting up SPF/DKIM/DMARC for HubSpot is a 20-minute job if you know what you're doing - and a "why are my emails going to spam" debugging marathon if you skip a step. This guide is the no-shortcuts walkthrough.
2. SPF - the exact record and where to put it
SPF (Sender Policy Framework) tells receiving mail servers which IPs are authorized to send email on behalf of your domain. Without it, every receiving server treats your mail as "could be a spoof, treat with suspicion."
The HubSpot SPF include
HubSpot's required SPF include is _spf.hubspot.com. If your domain doesn't currently have any SPF record, you publish a TXT record at the root of your domain with this value:
v=spf1 include:_spf.hubspot.com ~all
The ~all at the end is "soft fail" - receivers will accept mail from unauthorized IPs but mark it suspicious. Once you're confident your authentication is working correctly (typically after 2-4 weeks of monitoring), tighten this to -all (hard fail), which tells receivers to reject unauthorized mail outright.
If you already have an SPF record (most domains do)
This is where 80% of HubSpot SPF setups break. You cannot publish two separate SPF records on the same domain. RFC 7208 explicitly forbids it, and SPF will fail with a "permerror" if you try. You must merge the HubSpot include into your existing SPF record.
v=spf1 include:_spf.google.com ~all
v=spf1 include:_spf.hubspot.com ~all
v=spf1 include:_spf.google.com include:_spf.hubspot.com ~all
The 10-DNS-lookup limit
SPF has a strict limit of 10 DNS lookups per evaluation. Each include: mechanism counts as one lookup, and many includes contain nested includes that count too. If you exceed 10, SPF fails with "permerror" and receivers treat your mail as unauthenticated.
This is the #1 silent killer of HubSpot deliverability for companies that send through multiple platforms. A typical "stack" - Google Workspace + HubSpot + Mailchimp + a transactional provider - can easily blow past 10 lookups. Use our DNS Checker to count lookups in your current SPF record before adding HubSpot.
3. DKIM - the two CNAME records HubSpot generates
DKIM (DomainKeys Identified Mail) cryptographically signs each message HubSpot sends, proving it came from your domain. HubSpot uses two DKIM selectors: hs1._domainkey and hs2._domainkey.
How to find your specific DKIM values
HubSpot generates DKIM records that are unique to your account. Don't copy values from other guides - yours will be different. To find them:
- In HubSpot, navigate to Settings → Domains & URLs → Email Sending Domains
- Click Connect a sending domain and enter your domain
- HubSpot displays two CNAME records to add - one for
hs1._domainkey.yourdomain.comand one forhs2._domainkey.yourdomain.com - The "value" of each CNAME points to a unique HubSpot subdomain (something like
hs1-12345678._domainkey.hubspotemail.net)
The exact records to publish
hs1._domainkey CNAME hs1-XXXXXXXX._domainkey.hubspotemail.net
hs2._domainkey CNAME hs2-XXXXXXXX._domainkey.hubspotemail.net
Replace XXXXXXXX with the unique values HubSpot generated for your account. Both records must be CNAME (not TXT) - this is a common mistake. CNAME lets HubSpot rotate keys without you having to update DNS, which is why they recommend it.
4. DMARC - your enforcement policy
DMARC (Domain-based Message Authentication) is the policy layer that ties SPF and DKIM together. It tells receiving servers what to do when a message fails authentication, and it sends you reports on what's being sent claiming to be from your domain.
The starter DMARC record
For new HubSpot setups, start with a monitoring-only policy. This lets you collect data on your sending without risking legitimate mail being rejected:
v=DMARC1; p=none; rua=mailto:[email protected]
Translation:
v=DMARC1- version identifier (always this exact string)p=none- "monitoring mode": don't reject anything, just send reportsrua=mailto:[email protected]- where to send aggregate reports (a real inbox you can read)
When to tighten enforcement
After 2-4 weeks of monitoring with p=none, review your DMARC reports. Once you're confident all legitimate sources are passing both SPF and DKIM, progress through the enforcement tiers:
p=quarantine- failed authentication goes to spam folder. Use this for 2-4 more weeks.p=reject- failed authentication is rejected outright. The end-state policy.
Going straight to p=reject without first collecting data via p=none is the fastest way to break legitimate email flows you didn't know existed. Forwarders, mailing lists, and old transactional systems often send mail that looks suspicious to DMARC. Monitoring mode catches these before you start rejecting them.
5. Verification - how to confirm everything works
HubSpot's "verified" status is a starting point, not proof of correct configuration. Here's the layered verification approach we recommend:
Layer 1: HubSpot's own check
In HubSpot, go to Settings → Domains & URLs → Email Sending Domains and click Authenticate. HubSpot will check your SPF and DKIM CNAMEs and report status. This catches the most basic errors (typos, missing records).
Layer 2: Independent DNS verification
HubSpot only checks for the presence of records, not their correctness in context. Use our DNS Checker or Full Audit to verify:
- SPF record is syntactically correct AND under the 10-lookup limit
- DKIM CNAMEs resolve correctly to HubSpot's signing keys
- DMARC record exists and is properly formatted
- No conflicting records are causing alignment issues
Layer 3: End-to-end test send
Send a real campaign to a Gmail account you control. View the message, click the three-dot menu, and select "Show original." You should see:
SPF: PASS with IP X.X.X.X (hubspot.com)
DKIM: 'PASS' with domain yourdomain.com
DMARC: 'PASS' with action='none'
All three must say PASS. If DKIM says PASS but with a domain other than yours (e.g. "hubspotemail.net"), you have a DKIM alignment problem - see mistake #3 below.
Run a full audit on your sending domain. We check SPF lookups, DKIM alignment, DMARC policy, and the four common HubSpot misconfigurations - graded A-F with specific fixes.
6. The four mistakes that break "verified" setups
HubSpot's verification passes for all four of these. Your inbox-placement does not.
Mistake #1: Two separate SPF records
Caused by adding the HubSpot SPF as a new record instead of merging it into your existing one. SPF returns "permerror" and authentication fails for ALL of your mail, not just HubSpot. Fix: delete the duplicate, merge all include: mechanisms into a single record.
Mistake #2: SPF over the 10-lookup limit
Common when stacking HubSpot on top of Google Workspace + Mailchimp + a transactional provider. SPF returns "permerror" silently - most logs don't surface this. Fix: use SPF flattening (services like Easyspf or Valimail), or remove unused include: mechanisms.
Mistake #3: DKIM alignment failure
HubSpot DKIM-signs every message - but if it signs with the domain hubspotemail.net instead of your own domain, DMARC alignment fails. This usually happens when you set up HubSpot's "Email Domains" but didn't connect a sending domain. Fix: in HubSpot, ensure the From address matches your authenticated sending domain exactly. Don't use HubSpot's default @your-account.hubspot.com address.
Mistake #4: Missing or weak DMARC
You set up SPF and DKIM, but skipped DMARC entirely (or published v=DMARC1; p=none three years ago and never tightened it). Modern receivers treat absent or weak DMARC as a deliverability red flag. Fix: publish DMARC with at least p=quarantine and a real reporting address. Move to p=reject within 6-8 weeks.
7. Provider-specific notes
Cloudflare
The fastest and most reliable for HubSpot setups. Use the DNS dashboard, set proxy status to "DNS only" (gray cloud) for these records - orange cloud breaks email DNS. Propagation typically completes in 1-5 minutes.
GoDaddy
The DNS interface is slower to propagate (15-60 minutes typical) and has known issues with TXT records that contain semicolons. If your DMARC record won't save, check that GoDaddy isn't auto-escaping the semicolons in p=quarantine; rua=....
Namecheap
Generally clean. Use "Advanced DNS" tab. Note that Namecheap's TTL is 30 minutes by default - change to 5 minutes during setup, then back to 30 once stable.
Route53 (AWS)
Use TXT record type for SPF and DMARC, CNAME for DKIM. Route53 propagates within seconds. Watch for billing - $0.50/month per hosted zone is easy to forget.
8. Troubleshooting common issues
"Pending" status after 48 hours
Almost always a typo in DKIM CNAME values. Re-copy from HubSpot dashboard exactly - including any trailing dots. Use a DNS checker to verify the CNAME resolves to the correct hostname.
Emails authenticated, still going to spam
Authentication is necessary but not sufficient. Check: (1) sender reputation - has your domain been flagged on RBLs? Run a blacklist sweep. (2) Content triggers - are subject lines or body content spammy? Run a spam score check. (3) List quality - are you sending to old addresses? Clean with our List Cleaner.
DMARC reports show authentication failures from unknown sources
This is normal during the first few weeks of p=none monitoring. Forwarded mail, mailing lists, and forgotten old systems all trigger reports. Investigate each unknown source - most are legitimate forwarders that need to be added to your SPF, but some are spammers spoofing your domain (which DMARC at p=reject will eventually stop).
9. Frequently asked questions
What SPF record do I need for HubSpot?
_spf.hubspot.com. The full TXT record looks like: v=spf1 include:_spf.hubspot.com ~all. If you already have an SPF record (most domains do), you must MERGE the HubSpot include into your existing record - never publish two separate SPF records. Multiple SPF records cause SPF to fail entirely.