Skip to main content
← Back to all posts
CRM Setup · 14 min read

SPF, DKIM and DMARC for HubSpot in 2026.

The exact DNS records HubSpot needs, where to put them, and how to verify them. Includes the four mistakes that cause "verified" status with broken authentication - and the field-tested fix for each one.

By EmailSheriff · · 14 min read · Technical
5K+
Daily messages above which Google/Yahoo require DMARC
10
Maximum DNS lookups allowed in a single SPF record
4 hr
Interval at which HubSpot rechecks your DNS records
48 hr
Worst-case DNS propagation window after you publish a record

1. Why HubSpot authentication matters in 2026

If you're sending email through HubSpot and not setting up SPF, DKIM, and DMARC properly, your campaigns are going to spam - even if HubSpot's dashboard shows everything as "verified." This is one of the most common deliverability problems we see, and it has gotten dramatically worse since Google and Yahoo's February 2024 sender requirements took effect.

Here's what changed: any domain sending more than 5,000 messages per day to Gmail or Yahoo must now have SPF, DKIM, AND DMARC configured correctly. Below that threshold, DMARC isn't strictly required, but missing authentication still triggers spam-folder placement at every major inbox provider. There is no longer a "small sender" exception.

HubSpot makes this both easier and harder than it should be. Easier because their dashboard generates the exact DNS records you need and walks you through entering them. Harder because their verification only checks that records exist - not that they're correct for your specific configuration. We've seen "verified" HubSpot accounts where 60% of campaigns land in spam because of an SPF lookup-limit overflow that HubSpot's verification doesn't catch.

Bottom line

Setting up SPF/DKIM/DMARC for HubSpot is a 20-minute job if you know what you're doing - and a "why are my emails going to spam" debugging marathon if you skip a step. This guide is the no-shortcuts walkthrough.

2. SPF - the exact record and where to put it

SPF (Sender Policy Framework) tells receiving mail servers which IPs are authorized to send email on behalf of your domain. Without it, every receiving server treats your mail as "could be a spoof, treat with suspicion."

The HubSpot SPF include

HubSpot's required SPF include is _spf.hubspot.com. If your domain doesn't currently have any SPF record, you publish a TXT record at the root of your domain with this value:

DNS · TXT record at root
v=spf1 include:_spf.hubspot.com ~all

The ~all at the end is "soft fail" - receivers will accept mail from unauthorized IPs but mark it suspicious. Once you're confident your authentication is working correctly (typically after 2-4 weeks of monitoring), tighten this to -all (hard fail), which tells receivers to reject unauthorized mail outright.

If you already have an SPF record (most domains do)

This is where 80% of HubSpot SPF setups break. You cannot publish two separate SPF records on the same domain. RFC 7208 explicitly forbids it, and SPF will fail with a "permerror" if you try. You must merge the HubSpot include into your existing SPF record.

Wrong - two separate SPF records
v=spf1 include:_spf.google.com ~all v=spf1 include:_spf.hubspot.com ~all
Right - single merged SPF record
v=spf1 include:_spf.google.com include:_spf.hubspot.com ~all

The 10-DNS-lookup limit

SPF has a strict limit of 10 DNS lookups per evaluation. Each include: mechanism counts as one lookup, and many includes contain nested includes that count too. If you exceed 10, SPF fails with "permerror" and receivers treat your mail as unauthenticated.

This is the #1 silent killer of HubSpot deliverability for companies that send through multiple platforms. A typical "stack" - Google Workspace + HubSpot + Mailchimp + a transactional provider - can easily blow past 10 lookups. Use our DNS Checker to count lookups in your current SPF record before adding HubSpot.

3. DKIM - the two CNAME records HubSpot generates

DKIM (DomainKeys Identified Mail) cryptographically signs each message HubSpot sends, proving it came from your domain. HubSpot uses two DKIM selectors: hs1._domainkey and hs2._domainkey.

How to find your specific DKIM values

HubSpot generates DKIM records that are unique to your account. Don't copy values from other guides - yours will be different. To find them:

  1. In HubSpot, navigate to Settings → Domains & URLs → Email Sending Domains
  2. Click Connect a sending domain and enter your domain
  3. HubSpot displays two CNAME records to add - one for hs1._domainkey.yourdomain.com and one for hs2._domainkey.yourdomain.com
  4. The "value" of each CNAME points to a unique HubSpot subdomain (something like hs1-12345678._domainkey.hubspotemail.net)

The exact records to publish

DNS · CNAME records for DKIM
hs1._domainkey CNAME hs1-XXXXXXXX._domainkey.hubspotemail.net hs2._domainkey CNAME hs2-XXXXXXXX._domainkey.hubspotemail.net

Replace XXXXXXXX with the unique values HubSpot generated for your account. Both records must be CNAME (not TXT) - this is a common mistake. CNAME lets HubSpot rotate keys without you having to update DNS, which is why they recommend it.

4. DMARC - your enforcement policy

DMARC (Domain-based Message Authentication) is the policy layer that ties SPF and DKIM together. It tells receiving servers what to do when a message fails authentication, and it sends you reports on what's being sent claiming to be from your domain.

The starter DMARC record

For new HubSpot setups, start with a monitoring-only policy. This lets you collect data on your sending without risking legitimate mail being rejected:

DNS · TXT record at _dmarc.yourdomain.com
v=DMARC1; p=none; rua=mailto:[email protected]

Translation:

  • v=DMARC1 - version identifier (always this exact string)
  • p=none - "monitoring mode": don't reject anything, just send reports
  • rua=mailto:[email protected] - where to send aggregate reports (a real inbox you can read)

When to tighten enforcement

After 2-4 weeks of monitoring with p=none, review your DMARC reports. Once you're confident all legitimate sources are passing both SPF and DKIM, progress through the enforcement tiers:

  1. p=quarantine - failed authentication goes to spam folder. Use this for 2-4 more weeks.
  2. p=reject - failed authentication is rejected outright. The end-state policy.
Don't skip monitoring mode

Going straight to p=reject without first collecting data via p=none is the fastest way to break legitimate email flows you didn't know existed. Forwarders, mailing lists, and old transactional systems often send mail that looks suspicious to DMARC. Monitoring mode catches these before you start rejecting them.

5. Verification - how to confirm everything works

HubSpot's "verified" status is a starting point, not proof of correct configuration. Here's the layered verification approach we recommend:

Layer 1: HubSpot's own check

In HubSpot, go to Settings → Domains & URLs → Email Sending Domains and click Authenticate. HubSpot will check your SPF and DKIM CNAMEs and report status. This catches the most basic errors (typos, missing records).

Layer 2: Independent DNS verification

HubSpot only checks for the presence of records, not their correctness in context. Use our DNS Checker or Full Audit to verify:

  • SPF record is syntactically correct AND under the 10-lookup limit
  • DKIM CNAMEs resolve correctly to HubSpot's signing keys
  • DMARC record exists and is properly formatted
  • No conflicting records are causing alignment issues

Layer 3: End-to-end test send

Send a real campaign to a Gmail account you control. View the message, click the three-dot menu, and select "Show original." You should see:

Message headers · expected output
SPF: PASS with IP X.X.X.X (hubspot.com) DKIM: 'PASS' with domain yourdomain.com DMARC: 'PASS' with action='none'

All three must say PASS. If DKIM says PASS but with a domain other than yours (e.g. "hubspotemail.net"), you have a DKIM alignment problem - see mistake #3 below.

Verify your HubSpot setup in 30 seconds

Run a full audit on your sending domain. We check SPF lookups, DKIM alignment, DMARC policy, and the four common HubSpot misconfigurations - graded A-F with specific fixes.

Run the audit →

6. The four mistakes that break "verified" setups

HubSpot's verification passes for all four of these. Your inbox-placement does not.

Mistake #1: Two separate SPF records

Caused by adding the HubSpot SPF as a new record instead of merging it into your existing one. SPF returns "permerror" and authentication fails for ALL of your mail, not just HubSpot. Fix: delete the duplicate, merge all include: mechanisms into a single record.

Mistake #2: SPF over the 10-lookup limit

Common when stacking HubSpot on top of Google Workspace + Mailchimp + a transactional provider. SPF returns "permerror" silently - most logs don't surface this. Fix: use SPF flattening (services like Easyspf or Valimail), or remove unused include: mechanisms.

Mistake #3: DKIM alignment failure

HubSpot DKIM-signs every message - but if it signs with the domain hubspotemail.net instead of your own domain, DMARC alignment fails. This usually happens when you set up HubSpot's "Email Domains" but didn't connect a sending domain. Fix: in HubSpot, ensure the From address matches your authenticated sending domain exactly. Don't use HubSpot's default @your-account.hubspot.com address.

Mistake #4: Missing or weak DMARC

You set up SPF and DKIM, but skipped DMARC entirely (or published v=DMARC1; p=none three years ago and never tightened it). Modern receivers treat absent or weak DMARC as a deliverability red flag. Fix: publish DMARC with at least p=quarantine and a real reporting address. Move to p=reject within 6-8 weeks.

7. Provider-specific notes

Cloudflare

The fastest and most reliable for HubSpot setups. Use the DNS dashboard, set proxy status to "DNS only" (gray cloud) for these records - orange cloud breaks email DNS. Propagation typically completes in 1-5 minutes.

GoDaddy

The DNS interface is slower to propagate (15-60 minutes typical) and has known issues with TXT records that contain semicolons. If your DMARC record won't save, check that GoDaddy isn't auto-escaping the semicolons in p=quarantine; rua=....

Namecheap

Generally clean. Use "Advanced DNS" tab. Note that Namecheap's TTL is 30 minutes by default - change to 5 minutes during setup, then back to 30 once stable.

Route53 (AWS)

Use TXT record type for SPF and DMARC, CNAME for DKIM. Route53 propagates within seconds. Watch for billing - $0.50/month per hosted zone is easy to forget.

8. Troubleshooting common issues

"Pending" status after 48 hours

Almost always a typo in DKIM CNAME values. Re-copy from HubSpot dashboard exactly - including any trailing dots. Use a DNS checker to verify the CNAME resolves to the correct hostname.

Emails authenticated, still going to spam

Authentication is necessary but not sufficient. Check: (1) sender reputation - has your domain been flagged on RBLs? Run a blacklist sweep. (2) Content triggers - are subject lines or body content spammy? Run a spam score check. (3) List quality - are you sending to old addresses? Clean with our List Cleaner.

DMARC reports show authentication failures from unknown sources

This is normal during the first few weeks of p=none monitoring. Forwarded mail, mailing lists, and forgotten old systems all trigger reports. Investigate each unknown source - most are legitimate forwarders that need to be added to your SPF, but some are spammers spoofing your domain (which DMARC at p=reject will eventually stop).

9. Frequently asked questions

What SPF record do I need for HubSpot?
For HubSpot, your SPF record must include _spf.hubspot.com. The full TXT record looks like: v=spf1 include:_spf.hubspot.com ~all. If you already have an SPF record (most domains do), you must MERGE the HubSpot include into your existing record - never publish two separate SPF records. Multiple SPF records cause SPF to fail entirely.
How long does HubSpot DKIM take to verify?
DNS propagation typically takes 1-48 hours, but most providers (Cloudflare, Namecheap, GoDaddy) propagate in under 30 minutes. HubSpot rechecks every 4 hours after you click "Authenticate" in their dashboard. If status is still "pending" after 48 hours, your DKIM CNAME records were entered incorrectly - re-verify the values match exactly what HubSpot shows.
Why does HubSpot show "verified" but my emails still go to spam?
HubSpot's verified status only checks DNS records exist - it does not check that they are correct for your specific configuration. The four most common causes of "verified but still in spam" are: (1) missing DMARC policy, (2) SPF record exceeds the 10-DNS-lookup limit, (3) DKIM signing the wrong domain (alignment failure), and (4) sender domain mismatch with envelope From. Run a full audit on your sending domain to find which one applies.
Do I need DMARC for HubSpot?
Since 2024, yes - Google and Yahoo require DMARC for any domain sending more than 5,000 messages per day, including via HubSpot. Even below that threshold, DMARC is strongly recommended because it tells receiving servers what to do when authentication fails, which boosts deliverability across all major inbox providers.
+ Related tools
CRM DNS Verifier
Forensic verification for HubSpot, Salesforce, Mailchimp, Zoho - finds the exact misconfigurations that break authentication.
Full Audit
All 6 deliverability checks on a domain in 30 seconds, graded A-F. Catches SPF lookup overflow + DKIM alignment.
DNS Checker
SPF · DKIM · DMARC · MX with plain-English explanations. Includes 10-lookup counter for SPF.