All platforms
CRM-matched DNS
Campaign Monitor · 3 TXT · DKIM · SPF · DMARC
Campaign Monitor DNS Checker
Campaign Monitor sends from your domain using its own required records
, 3 TXT covering DKIM, SPF, DMARC. A generic SPF test
cannot see whether they match. We check your live DNS against
Campaign Monitor’s spec, host by host, character by character.
Free, no account.
domain only, we strip email and protocol automatically
What Campaign Monitor requires
Campaign Monitor: 1 TXT for DKIM (cm selector) + 1 TXT for SPF + 1 TXT for DMARC. Universal cm._domainkey selector. This is the exact table our verifier checks
your DNS against, not a generic template.
| Type | Host | Required value | Purpose |
| TXT | cm._domainkey | v=DKIM1; k=rsa; p=YOUR_PUBLIC_KEY_FROM_CAMPAIGN_MONITOR | DKIM |
| TXT | @ | v=spf1 include:_spf.createsend.com ~all | SPF |
| TXT | _dmarc | v=DMARC1; p=none; rua=mailto:[email protected] | DMARC |
How Campaign Monitor authenticates
Campaign Monitor gives you the DKIM public key directly, and you publish it as a TXT record at the selector host shown above. Keys above 255 characters arrive as multiple quoted strings; your DNS panel and any verifier must treat the concatenation as one key.
For SPF, Campaign Monitor needs its include (_spf.createsend.com) present in the ONE SPF record your domain is allowed to publish. If you already have an SPF record, this include is merged into it, never added as a second record; two SPF records is an automatic PermError everywhere.
DMARC is yours, not the platform's: one record at _dmarc governs every sender on the domain. If another tool already publishes it, do not add a second; the spec row above shows the minimum this platform expects to find.
Mistakes we see on Campaign Monitor domains
Pasting the key with the quote marks, line breaks or a trailing semicolon your provider's UI wrapped around it. The record must be the bare key material in the k=/p= structure shown.
Adding Campaign Monitor's SPF as a second TXT record next to an existing v=spf1. Receivers see two records and hard-fail both.
Why a generic checker misses this
A standard DNS tool tells you your SPF parses and your DMARC exists. It has no
idea Campaign Monitor is in the picture. It cannot tell you a required CNAME points at
the wrong target, a selector is missing, or the include chain never reaches
Campaign Monitor’s servers, which are precisely the failures that put
Campaign Monitor mail in spam while every generic check shows green.
Common questions
What DNS records does Campaign Monitor require?
Campaign Monitor requires 3 DNS records: 3 TXT, covering DKIM, SPF, DMARC. The exact hosts and values are in the table above, they come from the same spec table our verifier checks against.
Why does a normal SPF checker pass my domain but Campaign Monitor mail still fails?
A generic checker only tests whether your SPF record parses. It does not know which include Campaign Monitor needs, which CNAME targets its DKIM keys live behind, or which selector names it signs with. We compare your live DNS against Campaign Monitor’s required records character by character, so a missing include or a typo in a CNAME target is called out by name.
Will adding these records break my existing email?
The DKIM CNAMEs and the DMARC record are additive. SPF is the one to be careful with: a domain must publish exactly one SPF record, so if you already have one, merge the new include into it rather than adding a second record, two SPF records is an automatic PermError.
Keep going