Setup Guides · HubSpot

HubSpot Email Authentication: Sending Domain & DKIM

HubSpot's authentication is simpler than most - one required record set, delivered as CNAMEs so you never touch a raw key. Connect an email sending domain and HubSpot hands you two DKIM CNAME records (hs1._domainkey and hs2._domainkey) that sign your mail with d=yourdomain.com - enough to pass DMARC on its own once you've published a DMARC policy. SPF and DMARC stay yours to publish, and SPF only aligns if you add a custom return-path (Enterprise). This guide is the exact records, why the targets are account-specific, and the failures we keep finding in audits.

Last updated 11 September 2026 · applies to HubSpot Marketing Email (all paid tiers)

What HubSpot authenticates for you (and what it does not)

  • DKIM - HubSpot does this for you. Two CNAME records point at HubSpot-hosted keys; HubSpot generates and rotates the key material behind them, so you never hold or rotate a raw DKIM key. This is the one record set required to send authenticated mail from your domain.
  • SPF - recommended, and yours. HubSpot's docs call SPF "not strictly required" but advise adding it. On the shared network SPF passes against HubSpot's own return-path domain, so it does not align to you - DKIM carries DMARC. You add the SPF include to your domain's single v=spf1 record.
  • DMARC - entirely yours. HubSpot never publishes DMARC ("unique to your business needs and your DNS provider"). You add _dmarc.yourdomain.com yourself.

The upshot: DKIM alone gets you a DMARC pass (once a DMARC policy is published) because the signature's d= is your own domain. A complete setup is the two DKIM CNAMEs + your SPF include + your own DMARC record - and, if you need SPF to align too, a custom return-path subdomain on Enterprise.

What you need

  • A HubSpot account with access to Settings → Content → Domains & URLs → Email Sending.
  • Access to your domain's public DNS - and, on Cloudflare, the ability to set records to DNS only (grey cloud).
  • A sending domain (or subdomain) that matches your From address and is not already in use for another purpose such as hosting your website.

The setup, step by step

1 Start "Connect sending domain"

Click the Settings gear, then in the left sidebar go to Content → Domains & URLs, open the Email Sending tab, and click Connect sending domain (top right). Enter the domain your marketing email will send From.

The sending domain must not already host your website

HubSpot's rule: "you can only authenticate an email sending domain that's not currently in use for another purpose, such as hosting your website." If your root domain already serves your site through HubSpot, connect a subdomain for email instead (HubSpot's example is info.yourdomain.com) - and make sure that subdomain matches the domain in your From address, or DMARC won't align.

HubSpot names four record types, but you add three

HubSpot describes the connection as "four separate DNS record types: MX, DKIM, SPF, and DMARC," but doesn't explain the MX inline. On the standard shared-IP setup you actively publish only DKIM, SPF and DMARC (DKIM as two CNAMEs, SPF and DMARC as TXT), and the MX concern is your domain's inbound MX: HubSpot recommends removing any null MX record (MX 0 .), which some inbox providers read as "this domain refuses all mail," and leaving MX unset if the domain only sends. It's different on a dedicated IP - there HubSpot has you publish an MX record (priority 0) that processes bounces, spam reports and unsubscribes. So: if your portal shows an MX entry, publish exactly what it shows; if it shows none, there's nothing to add.

2 Publish the two DKIM CNAME records

HubSpot guides you to set up DKIM with two CNAME records. The hosts look like this; the targets are hosted on hubspotemail.net and are generated for your account and domain:

Type   Host                              Value
CNAME  hs1._domainkey.yourdomain.com     [exact target from HubSpot]
CNAME  hs2._domainkey.yourdomain.com     [exact target from HubSpot]

Publish both - one alone leaves DKIM unverified, and the domain stays "Not authenticated". Because these are CNAMEs to HubSpot-hosted keys, HubSpot rotates the keys for you; you never manage the key material.

Copy the Host and target exactly from the portal - don't reuse an example

HubSpot does not print the literal DKIM targets in its documentation, and the selector sometimes carries an account token (for example hs1-[accountid]._domainkey). Published examples on the web disagree with each other. Use the exact Host and Required data values HubSpot shows on the Connect sending domain screen - a guessed literal will silently fail to authenticate.

3 Add (or merge) the SPF include, and publish DMARC

HubSpot also shows an SPF include to add to your domain. It is account-specific - HubSpot's own example is partitioned, like include:123456.spf03.hubspotemail.net - so copy the exact value it gives you and merge it into your existing v=spf1 record; never add a second SPF record:

Type  Host             Value
TXT   yourdomain.com   v=spf1 include:[HubSpot's exact include] include:_spf.google.com ~all

Then publish your own DMARC record - HubSpot won't - starting in monitoring mode:

Type  Host                    Value
TXT   _dmarc.yourdomain.com   v=DMARC1; p=none; rua=mailto:[email protected]

Collect the aggregate reports, confirm your HubSpot mail (and every other sender) passes aligned, then move the policy through p=quarantine to p=reject. If your domain already has a DMARC record, keep it - don't overwrite an enforced policy with p=none; just confirm HubSpot's mail passes aligned under it. Our DMARC enforcement guide walks that path, and the Postbox DMARC Monitor reads the reports for you.

4 If you use Cloudflare, set the CNAMEs to DNS only

Publish everything at your DNS host. On Cloudflare, the two DKIM CNAMEs must be DNS only (grey cloud) - a proxied (orange) CNAME can't be resolved to HubSpot's key and DKIM never verifies. Watch for a DNS UI that auto-appends your domain to the host or target (producing ...hubspotemail.net.yourdomain.com); enter the values exactly as HubSpot shows them.

5 Verify - and reach "Authenticated"

HubSpot auto-checks after you add the records, and you can re-verify manually. HubSpot defines three states precisely: Not authenticated (none of the methods verified yet), Partially authenticated (DKIM is verified, but SPF or DMARC still isn't), and Authenticated (DKIM, SPF and DMARC all verified). So if you land on "Partially authenticated", your DKIM CNAMEs are working and the outstanding item is your SPF or DMARC record - complete those next. HubSpot notes DNS records "usually take between 10 and 70 minutes to update, but can take as long as 48 hours", so a fresh failure often just means you checked too early.

How SPF, DKIM and DMARC line up here

  • DKIM - the CNAMEs live at hsN._domainkey.yourdomain.com, so the signature's d= is your organizational domain. With the From address on the same domain, DKIM aligns (relaxed, DMARC's default) - this is the path that passes DMARC without any SPF work.
  • SPF - on the shared network the envelope-from (return-path) is HubSpot's domain: SPF passes but is not aligned to you, so it does nothing for DMARC. A custom return-path subdomain (Enterprise) moves the envelope-from under your domain and gives you SPF alignment too.
  • DMARC - passes when either SPF or DKIM aligns; HubSpot satisfies that through DKIM immediately. HubSpot also notes that a sending subdomain counts as authenticated for DMARC when a DMARC record exists at your root domain - so an organizational-domain policy covers the subdomain by inheritance, and you don't need a separate _dmarc on the subdomain. See our SPF, DKIM and DMARC guide for how the three fit together, and keep alignment relaxed - adkim=s can break a subdomain send.

Custom return-path and dedicated IP

Two upgrades change the DNS picture. A custom return-path (a branded bounce subdomain such as bounce.yourdomain.com) makes SPF align to your domain and "help[s] prove that your emails come from a trusted source"; it requires Marketing Hub Enterprise, or Marketing Hub Professional/Enterprise with the Dedicated IP or Transactional Email add-on, and HubSpot shows the exact records in-portal. A dedicated IP is a Professional/Enterprise add-on, "a good fit for accounts that send a high volume of email" (HubSpot publishes no numeric threshold); it obliges you to publish the records HubSpot lists for it - an A record (mapping your dedicated IP to the domain), an MX record (priority 0, which processes bounces, spam reports and unsubscribes), an SPF TXT and the DKIM CNAME - and to warm the IP. If you set a custom PTR on a dedicated IP, configure forward-confirmed reverse DNS (the PTR resolves to a hostname whose A/AAAA resolves back to the same IP) or Gmail can reject with 550 5.7.25 - see our SMTP error codes reference. Most senders should stay on shared IPs until volume justifies the warmup.

Gmail and Yahoo bulk-sender rules

Google and Yahoo now require bulk senders to have DKIM, SPF and DMARC fully set up on the sending domain, and non-compliant mail can bounce - HubSpot flags this as the reason to complete all three records rather than stopping at DKIM. The two CNAMEs authenticate you, but the Gmail and Yahoo rules expect a visible SPF and a published DMARC policy on the sending domain too. Once you're at an enforced DMARC policy (p=quarantine or p=reject), you can add BIMI to display your logo at supporting inbox providers - see our BIMI setup guide.

The failures we keep finding

Only one of the two DKIM CNAMEs published

Both hs1._domainkey and hs2._domainkey must resolve - with one missing, DKIM never verifies and the domain stays Not authenticated (not "Partially", which means DKIM is done but SPF or DMARC isn't). Re-open the Connect sending domain screen and confirm both hosts and targets match exactly.

DKIM CNAMEs left proxied on Cloudflare

An orange-clouded CNAME resolves to Cloudflare, not to HubSpot's key, so DKIM never verifies. Set both DKIM CNAMEs to DNS only.

Adding a second SPF record

A domain may have only one SPF TXT record; a second produces a permerror that can fail SPF entirely. Merge HubSpot's include into your existing v=spf1 record instead of creating a new one.

Pasting a guessed DKIM or SPF target

The DKIM targets and the SPF include are account-specific, and the examples floating around the web disagree. Copy the exact values from your portal - a plausible-looking literal will silently misconfigure.

Connecting a domain already used for website hosting

HubSpot refuses a sending domain "currently in use for another purpose, such as hosting your website". Connect a dedicated email subdomain that matches your From address instead.

Expecting HubSpot to publish DMARC

It never does. A HubSpot-authenticated domain with no _dmarc record has no DMARC policy at all, which fails the Gmail and Yahoo bulk-sender rules. Publish your own, starting at p=none.

Verify it end to end

HubSpot showing Authenticated means the records exist - it doesn't prove a real send passes. Confirm on an actual message:

  • Send a HubSpot marketing email to a seed address, then run it through Postbox Mailtester and confirm DKIM pass with d=yourdomain.com and DMARC pass (aligned) - plus SPF aligned if you set a custom return-path.
  • Or read the received message's Authentication-Results header: dkim=pass header.d=yourdomain.com and dmarc=pass. If DKIM shows a d= that isn't your domain, either the CNAMEs aren't resolving to HubSpot's key or the wrong sending domain is selected - re-check step 2 and the connected domain.

Frequently asked questions

What DNS records does HubSpot need to authenticate email?

The required set is DKIM: two CNAMEs (hs1._domainkey and hs2._domainkey) pointing to HubSpot-hosted keys. HubSpot also recommends an SPF include (merged into your single v=spf1 record) and a DMARC TXT at _dmarc, both of which you own. The DKIM targets and SPF include are account-specific - copy the exact values from the Connect sending domain screen. (HubSpot's flow also names an "MX" record type; that's a prompt to remove any null MX record, not a record you add.)

Does HubSpot require SPF and DMARC, or just DKIM?

Only DKIM is functionally required; HubSpot calls all three "not strictly required" but recommends them. On the shared network your mail passes DMARC via DKIM alignment even without your SPF. Add SPF and DMARC anyway - Gmail and Yahoo's bulk rules expect the full set, and DMARC is what stops spoofing of your domain.

Why is my HubSpot domain stuck on "Partially authenticated"?

Because DKIM verified but your SPF or DMARC hasn't. HubSpot defines "Partially authenticated" as DKIM correctly set up and verified while SPF or DMARC is still incomplete - so publish or fix those TXT records (one SPF record only, not proxied, DMARC at _dmarc) and give DNS 10-70 minutes, up to 48 hours. If instead DKIM itself won't verify because one of the two CNAMEs is missing or wrong, the domain stays "Not authenticated", not "Partially".

Does HubSpot set up DMARC for me?

No - the DMARC policy "is unique to your business needs and your DNS provider". Publish _dmarc.yourdomain.com yourself, starting at p=none. Your HubSpot mail passes DMARC via DKIM alignment, so you can enforce safely once every other sender aligns too.

Can I get SPF alignment with HubSpot?

Not on the shared network - SPF aligns to HubSpot's return-path domain, and DKIM carries DMARC. To align SPF you connect a custom return-path subdomain (e.g. bounce.yourdomain.com), which requires Marketing Hub Enterprise, or Marketing Hub Professional/Enterprise with the Dedicated IP or Transactional Email add-on; HubSpot shows the exact records in-portal.

Do I need a dedicated IP with HubSpot?

Most senders don't. HubSpot sends from shared IPs by default; a dedicated IP is a Professional/Enterprise add-on "a good fit for accounts that send a high volume of email" (no published threshold), and it requires SPF + an MX on the return-path subdomain plus IP warmup. Get DKIM + SPF + DMARC right first.

Sources (HubSpot Knowledge Base): Overview of email authentication · Manage email authentication · Use a DMARC policy with HubSpot · Custom return-path · Connect a dedicated IP.

Not sure your HubSpot mail is actually aligned?

Chat with us!