1. Why Pipedrive authentication matters in 2026
If you send Campaigns or sales mail through Pipedrive, Google and Yahoo's 2024 rules apply: authenticate with SPF, DKIM, and DMARC or risk the spam folder. Pipedrive has one defining characteristic that shapes the whole setup - and most guides skip it.
Pipedrive doesn't run its own mail server and sends using its own return-path domain. That means SPF will not align with your From: domain - so SPF alone can't make DMARC pass. With Pipedrive, DKIM is the authentication that matters. Get DKIM aligned and you can pass DMARC on DKIM alone.
2. Where to start in Pipedrive
Click the Campaigns icon, open the Settings tab, and find Domain Authentication. Click + Domain, enter your sending domain, and click Get DNS Records. Pipedrive generates the CNAME records for DKIM (and a DMARC TXT suggestion) with values unique to your domain - always copy them from your own account.
3. Publish the DKIM CNAME records
Pipedrive provides DKIM as CNAME records. Add them at your DNS provider exactly as shown.
pdmark1._domainkey CNAME pdmark1.dkim.pipedrive.compdmark2._domainkey CNAME pdmark2.dkim.pipedrive.comThis is the single most common Pipedrive failure. On each CNAME record in Cloudflare, set the proxy status to DNS-only (grey cloud, not orange). With the proxy on, Cloudflare returns its own servers instead of Pipedrive's CNAME target, and verification fails every time.
4. SPF: optional, and won't carry DMARC
You can add Pipedrive's SPF include if their wizard offers one, merged into your single SPF record - but understand it won't align, so it isn't what makes DMARC pass. Keep one SPF record, stay under ten lookups, and don't add includes you don't need.
v=spf1 include:_spf.google.com ~all5. Publish your DMARC policy
v=DMARC1; p=none; rua=mailto:[email protected]Start at p=none, confirm your DMARC reports show 100% DKIM alignment on Pipedrive mail, then tighten to p=quarantine and finally p=reject.
6. Verify in Pipedrive
Back in Domain Authentication, click Refresh status. Green checkmarks confirm each record resolved (up to 48 hours, usually faster). Then send a test campaign and check a DMARC report to confirm DKIM alignment is passing.
Run your domain through our CRM DNS Verifier - it checks your records against Pipedrive's spec, confirms DKIM is aligning, and catches the Cloudflare-proxy mistake that silently breaks verification.
Verify my Pipedrive DNS →7. Authenticated but still landing in spam?
Look beyond authentication: (1) is your domain or IP blacklisted? Run a blacklist sweep. (2) is your content tripping filters? Run a spam score check. (3) is your list stale? Clean it with our List Cleaner.