Setup guide

SPF · DKIM · DMARC

Set up SPF, DKIM and DMARC on Brevo

The records that let Brevo send as your domain — publish the Brevo code and DKIM it generates, add DMARC, then have Brevo verify.

Before you start

What Brevo needs from your DNS.

Brevo sends on your behalf, so it does not replace your mailbox provider — it adds to whatever already authenticates your domain. Authentication in Brevo rests on two things: a Brevo code that proves you own the sending domain, and DKIM that signs every message Brevo sends so receivers can trust it came from you unaltered. You add both at your DNS host, not inside Brevo.

The catch is that Brevo generates the Brevo code and DKIM values uniquely for your domain. You will not find them in any guide — you add your domain on the Domains page, and Brevo shows you the exact records to copy. DKIM usually arrives as two CNAME records (shown as DKIM 1 and DKIM 2); some accounts get a single TXT record instead. Nothing signs your mail until those records resolve and you click to authenticate.

Since February 2024, Gmail and Yahoo require anyone sending in bulk to publish SPF, DKIM and DMARC, and Microsoft is following. On Brevo that means authenticating your domain is not optional housekeeping — it is the gate to the inbox, and an unauthenticated domain will see its Brevo mail filtered or rejected.

The records to publish

Copy these into your DNS.

Add each record at your DNS provider — the company where your domain is registered, not Brevo. Then run the checker to confirm every one resolves.

Brevo code record

host  @ type  TXT

value generated by Brevo

Brevo generates a unique string beginning brevo-code: for your domain. Add it as a TXT record at the root of the sending domain. It only proves ownership — it does not sign mail — so publishing it is necessary but not sufficient on its own.

SPF record

host  @ type  TXT
v=spf1 include:spf.brevo.com mx ~all

SPF is not required to authenticate a domain in Brevo (DKIM alignment carries authentication on shared IPs); it is provided when you set up a dedicated IP and is worth adding for SPF alignment. If an SPF record already exists, merge include:spf.brevo.com and the mx mechanism into that single line — never publish a second SPF record.

DKIM record 1 record

host  brevo1._domainkey type  CNAME

value generated by Brevo

Brevo displays the exact record name and CNAME target on the Domains page — copy both verbatim. The two CNAMEs are typically named brevo1._domainkey and brevo2._domainkey. On Cloudflare, leave these DNS-only (grey cloud) and switch off CNAME flattening, or the target is rewritten and DKIM breaks.

DKIM record 2 record

host  brevo2._domainkey type  CNAME

value generated by Brevo

The second half of the DKIM key pair. Add exactly as Brevo shows it. Some accounts are issued a single DKIM TXT record instead of these two CNAMEs — in that case add only that one TXT record and ignore the CNAME rows.

DMARC record

host  _dmarc type  TXT
v=DMARC1; p=none; rua=mailto:[email protected]

One DMARC record at the root domain. Start at p=none to watch reports without affecting delivery, then raise to quarantine and reject once every legitimate sender aligns. Point rua at an address you read. If your account already has a DMARC record, Brevo will not overwrite it — keep yours rather than adding a second.

Step by step

The whole setup, in order.

  1. 1 Add your domain to Brevo. In Brevo, open the account dropdown and go to Settings, then Senders, Domains, IPs, then Domains. Click Add a domain and enter the sending domain — the part after the @ in the address you send from. If it is already listed, click Authenticate next to it.
  2. 2 Choose how to authenticate. Automatic authentication logs in to your DNS provider from Brevo and adds every record for you. If that is not available or you manage DNS yourself, choose Authenticate the domain yourself to see the Brevo code, DKIM and DMARC records to copy.
  3. 3 Publish the Brevo code and DKIM records. At your DNS host, add the Brevo code TXT at the root, then add the two DKIM CNAME records (or the single DKIM TXT) exactly as Brevo displays them. On Cloudflare, keep the DKIM CNAMEs DNS-only and disable CNAME flattening.
  4. 4 Add DMARC, and merge SPF if needed. Publish the _dmarc TXT record at the root, starting at p=none. If you send from a dedicated IP or want SPF alignment, merge include:spf.brevo.com mx into your existing SPF record rather than publishing a new one.
  5. 5 Verify in Brevo, then wait. Back in Brevo, click Authenticate this email domain at the bottom of the records page. DNS can take up to 48 hours to propagate; a green Value matched appears next to each record once Brevo detects it.
  6. 6 Confirm the full picture. Once Brevo shows the domain authenticated, run a full check here to confirm the Brevo code resolves, both DKIM records are found and valid, SPF stays under the 10-lookup limit, and DMARC is graded.

Where it goes wrong

The mistakes specific to Brevo.

Cloudflare proxying or flattening the DKIM CNAMEs An orange cloud (proxy) or CNAME flattening rewrites the DKIM target, so Brevo never sees its own value. Set the DKIM records to DNS-only and deactivate CNAME flattening.
A second SPF record Publishing v=spf1 include:spf.brevo.com mx ~all alongside an existing SPF record is a permerror that voids both. Merge every sender into one SPF line, keeping a single ~all at the end.
Expecting SPF to do the authenticating Brevo authenticates a shared-IP domain through the Brevo code and DKIM, not SPF. Adding only an SPF record and skipping the Brevo code or DKIM leaves the domain unauthenticated.
Replacing your mailbox provider's records Brevo adds to your setup; it does not take it over. Keep your existing MX and any SPF include for your mailbox host, and merge Brevo in rather than overwriting them.
A 1024-bit DKIM key Brevo issues a 1024-bit key by default. To move to 2048-bit you must ask Brevo support to enable it; the new value begins sib2k, and you then have to update the DKIM record in your DNS.
Verifying too soon Clicking Authenticate minutes after publishing shows a failure that is only propagation. Brevo allows up to 48 hours — give it time before concluding anything is wrong.

Confirm it worked

Do not trust it until you have checked it.

DNS takes a few minutes to propagate. Once it has, run a full check: it reads all three records live, counts your SPF lookups, confirms the Brevo DKIM selector resolves, and grades your DMARC policy — the exact things that decide whether Gmail and Outlook trust your mail.

Common questions

About Brevo, specifically.

What is the Brevo SPF record? v=spf1 include:spf.brevo.com mx ~all. SPF is not strictly required to authenticate a domain in Brevo — it is provided with a dedicated IP and helps SPF alignment — but if you add it, merge include:spf.brevo.com and mx into your existing SPF line rather than publishing a second record.
What is the Brevo DKIM record or selector? Brevo generates DKIM per-domain, usually as two CNAME records shown as DKIM 1 and DKIM 2 (typically brevo1._domainkey and brevo2._domainkey), or occasionally a single DKIM TXT record. Copy the exact name and value from the Domains page — they are unique to your domain.
Why is my Brevo DKIM failing? Usually the DKIM CNAMEs are proxied or flattened on Cloudflare, the record name or target was not copied exactly, you have not clicked Authenticate this email domain in Brevo yet, or DNS has not propagated. Brevo can take up to 48 hours to detect the records.
What is the Brevo code and do I need it? The Brevo code is a TXT record beginning brevo-code: that proves you own the sending domain. It is required — Brevo will not authenticate the domain without it — but it only verifies ownership; DKIM is what actually signs your mail.
Do I need DMARC for Brevo? Yes if you send in bulk to Gmail or Yahoo, required since February 2024. Publish one _dmarc TXT record at your root domain, start at p=none with a report address, and raise it to quarantine then reject once your reports show every legitimate sender aligning.
Where do I add these records — in Brevo or at my registrar? At your DNS host: the registrar or provider that controls your domain's DNS. Brevo generates the Brevo code and DKIM values and shows them to you, but every record is published in your own DNS. Brevo can also add them automatically if you log in to your provider from Brevo.

Set it once. Know it stays set.

A DKIM key rotates, a vendor changes its SPF, an IP gets listed — and your carefully-configured domain quietly breaks. Monitoring watches all of it and tells you the day it changes.