Skip to main content
CRM Setup · 12 min read

SPF, DKIM and DMARC for Pipedrive in 2026.

The exact DNS records Pipedrive needs, where to publish them, and the Cloudflare proxy trap that silently breaks verification. Short version: Pipedrive has no mail server of its own, so DKIM - not SPF - is what makes DMARC pass.

Updated May 2026·By EmailSheriff

1. Why Pipedrive authentication matters in 2026

If you send Campaigns or sales mail through Pipedrive, Google and Yahoo's 2024 rules apply: authenticate with SPF, DKIM, and DMARC or risk the spam folder. Pipedrive has one defining characteristic that shapes the whole setup - and most guides skip it.

The Pipedrive-defining fact

Pipedrive doesn't run its own mail server and sends using its own return-path domain. That means SPF will not align with your From: domain - so SPF alone can't make DMARC pass. With Pipedrive, DKIM is the authentication that matters. Get DKIM aligned and you can pass DMARC on DKIM alone.

DKIM
The protocol that carries Pipedrive DMARC alignment
DNS-only
Required Cloudflare proxy setting for the CNAME records
10
Maximum DNS lookups allowed in a single SPF record
48 hr
Worst-case DNS propagation after you publish a record

2. Where to start in Pipedrive

Click the Campaigns icon, open the Settings tab, and find Domain Authentication. Click + Domain, enter your sending domain, and click Get DNS Records. Pipedrive generates the CNAME records for DKIM (and a DMARC TXT suggestion) with values unique to your domain - always copy them from your own account.

3. Publish the DKIM CNAME records

Pipedrive provides DKIM as CNAME records. Add them at your DNS provider exactly as shown.

DNS · Pipedrive DKIM CNAME records (example - use your own values)
pdmark1._domainkey CNAME pdmark1.dkim.pipedrive.compdmark2._domainkey CNAME pdmark2.dkim.pipedrive.com
Cloudflare users: turn the proxy OFF

This is the single most common Pipedrive failure. On each CNAME record in Cloudflare, set the proxy status to DNS-only (grey cloud, not orange). With the proxy on, Cloudflare returns its own servers instead of Pipedrive's CNAME target, and verification fails every time.

4. SPF: optional, and won't carry DMARC

You can add Pipedrive's SPF include if their wizard offers one, merged into your single SPF record - but understand it won't align, so it isn't what makes DMARC pass. Keep one SPF record, stay under ten lookups, and don't add includes you don't need.

DNS · only if you already use SPF elsewhere (merged, single record)
v=spf1 include:_spf.google.com ~all

5. Publish your DMARC policy

DNS · TXT record at _dmarc.yourdomain.com
v=DMARC1; p=none; rua=mailto:[email protected]

Start at p=none, confirm your DMARC reports show 100% DKIM alignment on Pipedrive mail, then tighten to p=quarantine and finally p=reject.

6. Verify in Pipedrive

Back in Domain Authentication, click Refresh status. Green checkmarks confirm each record resolved (up to 48 hours, usually faster). Then send a test campaign and check a DMARC report to confirm DKIM alignment is passing.

Confirm it independently

Run your domain through our CRM DNS Verifier - it checks your records against Pipedrive's spec, confirms DKIM is aligning, and catches the Cloudflare-proxy mistake that silently breaks verification.

7. Authenticated but still landing in spam?

Look beyond authentication: (1) is your domain or IP blacklisted? Run a blacklist sweep. (2) is your content tripping filters? Run a spam score check. (3) is your list stale? Clean it with our List Cleaner.

8. Frequently asked questions

Does Pipedrive need an SPF record?
Pipedrive doesn't run its own mail server and sends using its own return-path domain, so an SPF include won't align with your From: domain - meaning SPF alone won't make DMARC pass. The reliable path is DKIM: Pipedrive gives you CNAME records that sign mail with your domain, and DKIM alignment carries DMARC to a pass. You can achieve DMARC compliance with Pipedrive on DKIM alone.
Where do I set up authentication in Pipedrive?
In Pipedrive, click the Campaigns icon, go to the Settings tab, open Domain Authentication, and click + Domain. Enter your domain and click Get DNS Records - Pipedrive then shows the CNAME (DKIM) and TXT records to publish. After adding them to your DNS provider, click Refresh status to verify.
Why must I turn off the Cloudflare proxy for Pipedrive CNAME records?
If you use Cloudflare, the orange-cloud proxy must be OFF (DNS-only / grey cloud) on Pipedrive's CNAME records. With the proxy on, Cloudflare routes the lookup through its own servers instead of returning the raw CNAME target, which breaks Pipedrive's verification. Set each CNAME to DNS-only and re-check.
Why is Pipedrive authenticated but emails still go to spam?
Authentication confirms your DKIM resolves - it doesn't guarantee placement. Common causes: a missing or p=none DMARC policy, a blacklisted domain or IP, spammy content, or a stale list. Confirm 100% DKIM alignment in your DMARC reports, then check reputation and list hygiene.

Keep your sending healthy

CRM DNS Verifier
Forensic verification for Pipedrive, ActiveCampaign, HubSpot, Salesforce and more - finds the exact misconfigurations that break authentication.
Full Audit
All 6 deliverability checks on a domain in 30 seconds, graded A-F. Catches SPF lookup overflow and DKIM alignment issues.
DNS Checker
SPF · DKIM · DMARC · MX with plain-English explanations. Includes a 10-lookup counter for SPF.