All platforms
CRM-matched DNS Freshsales · 8 CNAME + 1 TXT · DKIM · SPF · LINK · DMARC

Freshsales DNS Checker

Freshsales sends from your domain using its own required records , 8 CNAME + 1 TXT covering DKIM, SPF, LINK, DMARC. A generic SPF test cannot see whether they match. We check your live DNS against Freshsales’s spec, host by host, character by character. Free, no account.

e$

domain only, we strip email and protocol automatically

What Freshsales requires

Freshsales: 4 CNAME for DKIM (s1-s4) + 1 CNAME for SPF + 3 CNAME for link tracking (SendGrid/fwclick). This is the exact table our verifier checks your DNS against, not a generic template.

TypeHostRequired valuePurpose
CNAMEXXXX._domainkeywlXXXXXXs1.domainkey.myfreshworks.comDKIM
CNAMEXXXX2._domainkeywlXXXXXXs2.domainkey.myfreshworks.comDKIM
CNAMEXXXX3._domainkeywlXXXXXXs3.domainkey.myfreshworks.comDKIM
CNAMEXXXX4._domainkeywlXXXXXXs4.domainkey.myfreshworks.comDKIM
CNAMEfwdkimspfmxN.domainkey.myfreshworks.comSPF
CNAMEXXXXXXXXsendgrid.netLINK
CNAMEfwtrack1sendgrid.netLINK
CNAMEfslinkfslink.fwclick.ioLINK
TXT_dmarcv=DMARC1; p=none; rua=mailto:[email protected]DMARC

Segments shown as XXXXXX are account-specific, Freshsales generates them for your account. The checker treats them as wildcards: the structure must match, the account part is yours.

How Freshsales authenticates

Freshsales handles DKIM by delegation: you publish 4 CNAME records (selectors XXXX, XXXX2, XXXX3, XXXX4) pointing into wlXXXXXXs1.domainkey.myfreshworks.com, and Freshsales hosts and rotates the actual signing keys on its side. You never see the public key, which also means a checker that only looks for TXT keys at _domainkey will wrongly report DKIM as missing here.

Note what is NOT in the table: Freshsales does not ask for an SPF include on this hostname. Its mail passes SPF on its own return-path domain, so adding one anyway does nothing for Freshsales and spends one of your ten SPF lookups.

The non-DKIM CNAMEs handle tracking or bounce domains. They carry no authentication themselves, but Freshsales's setup screen will not verify the domain until they resolve.

DMARC is yours, not the platform's: one record at _dmarc governs every sender on the domain. If another tool already publishes it, do not add a second; the spec row above shows the minimum this platform expects to find.

Mistakes we see on Freshsales domains

Publishing the CNAME target as a TXT record. The record type matters: a TXT with the right value still is not a delegation, and the key lookup dies at your zone.

Proxying the _domainkey CNAMEs through a CDN. They must resolve as plain DNS; an orange-clouded record answers with the CDN's addresses and the key disappears.

Why a generic checker misses this

A standard DNS tool tells you your SPF parses and your DMARC exists. It has no idea Freshsales is in the picture. It cannot tell you a required CNAME points at the wrong target, a selector is missing, or the include chain never reaches Freshsales’s servers, which are precisely the failures that put Freshsales mail in spam while every generic check shows green.

Common questions

What DNS records does Freshsales require?

Freshsales requires 9 DNS records: 8 CNAME + 1 TXT, covering DKIM, SPF, LINK, DMARC. The exact hosts and values are in the table above, they come from the same spec table our verifier checks against.

Why does a normal SPF checker pass my domain but Freshsales mail still fails?

A generic checker only tests whether your SPF record parses. It does not know which include Freshsales needs, which CNAME targets its DKIM keys live behind, or which selector names it signs with. We compare your live DNS against Freshsales’s required records character by character, so a missing include or a typo in a CNAME target is called out by name.

What do the XXXXXX parts in Freshsales’s records mean?

Those segments are account-specific, Freshsales generates them for your account and shows the exact values in its sending-domain setup screen. Our checker treats them as wildcards: the structure around them must match, the account-specific part is yours.

Will adding these records break my existing email?

The DKIM CNAMEs and the DMARC record are additive. SPF is the one to be careful with: a domain must publish exactly one SPF record, so if you already have one, merge the new include into it rather than adding a second record, two SPF records is an automatic PermError.

Keep going

All 25 platforms Full DNS check Build a record Run everything