1. Why Mailchimp authentication matters in 2026
Since February 2024, Google and Yahoo require every domain sending bulk email - including through Mailchimp - to authenticate with SPF, DKIM, and DMARC. Send unauthenticated, and your campaigns don't just risk the spam folder; they can be rejected outright. For a marketing list, that's invisible failure: your open rates quietly collapse and you assume the content was weak, when really the mail never arrived.
Mailchimp made this easier than most platforms - but it also does authentication differently from senders like HubSpot, and that difference is the source of most confusion. If you've set up another CRM before, some of your instincts here will be wrong. This guide walks the exact records, in order, and flags the Mailchimp-specific traps.
Mailchimp authenticates your domain with two DKIM CNAME records. It does not require an SPF record for standard campaigns, because it reaches DMARC compliance through DKIM alignment alone. Add a DMARC TXT record yourself, and you're done. The SPF step everyone obsesses over is usually unnecessary - and occasionally harmful.
2. Step one: verify your domain in Mailchimp
Before Mailchimp will let you authenticate - or even use your domain as a "From" address - it makes you prove you own it. In your Mailchimp account, go to Settings → Domains and start the verification flow. Mailchimp sends a confirmation email to an address on that domain (for example, [email protected]); click the link inside to confirm ownership.
You cannot authenticate a free mailbox provider here. Gmail, Yahoo, Outlook.com and similar can't be authenticated because you don't control their DNS - you must send from a domain you own. This is the single most common reason a small sender can't get authenticated at all.
3. Step two: add the DKIM CNAME records (the important part)
This is where Mailchimp does the real work. After verification, Mailchimp's Domains page generates two CNAME records with selectors unique to your domain. They look like the example below - but your exact values will differ, so always copy them from your own Mailchimp dashboard, never from a guide.
k2._domainkey CNAME dkim2.mcsv.net
k3._domainkey CNAME dkim3.mcsv.net
Add both at your DNS provider (Cloudflare, GoDaddy, Namecheap, etc.) exactly as shown. Two details cause almost every failure here:
Trap 1 - the doubled domain. Many DNS panels automatically append your domain to the host field. So if you type k2._domainkey.yourdomain.com into a panel that already adds .yourdomain.com, you end up with k2._domainkey.yourdomain.com.yourdomain.com - and it silently never resolves. When in doubt, enter just k2._domainkey as the host and let the panel complete it.
k2._domainkey.yourdomain.com.yourdomain.com
k2._domainkey
Trap 2 - pasting a CNAME as a TXT. DKIM for Mailchimp is a CNAME, not a TXT record (this differs from some other platforms, which publish DKIM as a long TXT key). If your DNS panel asks for the record type, choose CNAME. Pasting the value into a TXT record is a frequent, frustrating mistake.
4. Step three: SPF - usually skip it (here's why)
This is the section that contradicts most other guides, so read carefully. For standard Mailchimp marketing campaigns, you do not need to add Mailchimp to your SPF record. Mailchimp signs your mail with DKIM using your own domain, and DMARC only requires that either SPF or DKIM passes and aligns. Since Mailchimp's DKIM aligns to your domain, DMARC passes on DKIM alone.
Why does this matter? Because SPF has a hard limit of ten DNS lookups. Every include: in your SPF record consumes lookups. If you reflexively add a Mailchimp include you don't need - on top of Google Workspace, your CRM, and your help-desk tool - you can blow past ten lookups and break SPF for all your senders. Adding SPF you don't need is worse than leaving it out.
If you use Mailchimp Transactional (formerly Mandrill) for receipts, password resets, and other system mail, you do need an SPF include - commonly include:spf.mandrillapp.com. And if your own Mailchimp dashboard explicitly shows an SPF record to add, follow it. Otherwise, leave SPF alone.
v=spf1 include:spf.mandrillapp.com include:_spf.google.com ~all
Note the word merge. You may only have one SPF record per domain. If you already have one for Google Workspace or another sender, add the Mailchimp include into that existing record - never publish a second SPF record. Two SPF records cause SPF to fail entirely.
5. Step four: publish your DMARC record
Mailchimp's authentication gets your mail signed, but it doesn't publish DMARC for you - you do that yourself. DMARC is a single TXT record at the _dmarc subdomain that tells receiving servers what to do when a message fails authentication, and where to send reports.
v=DMARC1; p=none; rua=mailto:[email protected]
Start with p=none - this is "monitor mode." It changes nothing about delivery but starts collecting reports so you can confirm your DKIM is aligning correctly before you tighten the policy. After a couple of weeks of clean reports, move to p=quarantine, and eventually p=reject for full protection against spoofing.
Setting p=reject before you've confirmed every legitimate sender aligns is how people accidentally block their own invoices and newsletters. Walk the policy up: none → quarantine → reject, watching reports at each step.
6. Step five: verify it actually worked
Back in Mailchimp's Settings → Domains page, click Check Status. Your domain should flip to Authenticated. If it's still pending, give DNS time to propagate - usually minutes, up to 48 hours worst case - then re-check.
But here's the catch every marketer should internalize: Mailchimp's "Authenticated" badge only confirms your two DKIM CNAMEs resolve. It does not check that you have a DMARC policy, that your domain isn't blacklisted, or that your list is clean. "Authenticated" in Mailchimp is necessary, not sufficient.
Don't take one platform's word for it. Run your domain through our CRM DNS Verifier - it checks your published records against Mailchimp's exact specification, record by record, and flags DKIM that signs the wrong domain, a missing DMARC policy, or SPF that's quietly over the lookup limit.
Verify my Mailchimp DNS →7. Authenticated but still landing in spam?
If Mailchimp says authenticated and your campaigns still hit spam, authentication isn't your problem - reputation or list quality is. Check, in order: (1) sender reputation - is your domain or IP on a blocklist? Run a blacklist sweep. (2) content triggers - are subject lines or body content setting off filters? Run a spam score check. (3) list quality - are you mailing old, invalid, or trap addresses? A dirty list tanks reputation fast; clean it with our List Cleaner.
Authentication gets you to the door. Reputation and list hygiene decide whether you're let in.
8. Frequently asked questions
Does Mailchimp need an SPF record?
include:spf.mandrillapp.com. Adding an unnecessary SPF include can push you over the 10-lookup limit, so only add it if Mailchimp's dashboard tells you to.What DNS records does Mailchimp require for authentication?
k2._domainkey and k3._domainkey), plus a recommended DMARC TXT record at _dmarc. Add the two CNAMEs exactly as Mailchimp shows them under Settings → Domains, then publish your own DMARC record. Mailchimp does not require an SPF record for standard sending.How long does Mailchimp domain authentication take to verify?
Why is my Mailchimp domain authenticated but emails still go to spam?
p=none DMARC policy, sending from a free domain, a blacklisted domain or IP, spammy content, and stale recipient lists. Authentication opens the door; reputation and list hygiene keep you in the inbox.