SPF · DKIM · DMARC
Set up SPF, DKIM and DMARC on Mailchimp
Mailchimp does not replace your mail host — it sends alongside it. Add its SPF include, publish the two DKIM CNAMEs, set DMARC, then click Authenticate.
Before you start
What Mailchimp needs from your DNS.
Mailchimp is a sending platform, not your mailbox host, so authenticating it means adding to the DNS you already have rather than swapping anything out. You keep sending normal mail through Google Workspace, Microsoft 365 or whoever hosts your inbox, and you tell the world that Mailchimp is also allowed to send as your domain. Get that wrong and your campaigns land in spam or bounce outright.
The work is three records at your DNS host. SPF gains one include so Mailchimp's servers are authorised, DKIM is delegated through two CNAME records that point at Mailchimp so it can sign and rotate keys for you, and DMARC ties it together on your root domain. Mailchimp uses CNAME delegation rather than a pasted public key, which is why you copy the two CNAME values straight from the Domains page instead of generating anything yourself.
Since February 2024 Google and Yahoo require bulk senders to Gmail and Yahoo inboxes to pass SPF, DKIM and DMARC. Authenticating your domain in Mailchimp is no longer optional polish — an unauthenticated domain is throttled or blocked at exactly the receivers your campaigns need to reach.
The records to publish
Copy these into your DNS.
Add each record at your DNS provider — the company where your domain is registered, not Mailchimp. Then run the checker to confirm every one resolves.
SPF record
v=spf1 include:servers.mcsv.net ~all
You almost certainly already have an SPF record for your mailbox host. Do not publish a second one — edit the existing line and insert include:servers.mcsv.net before the terminating ~all or -all, e.g. v=spf1 include:_spf.google.com include:servers.mcsv.net ~all. Two SPF records is a permerror that voids both.
DKIM (CNAME 1) record
dkim.mcsv.net
Mailchimp delegates DKIM rather than giving you a key to paste. Copy the exact Name and Value for CNAME 1 from your Mailchimp Domains page — the host is typically k1._domainkey and the target dkim.mcsv.net, but confirm both against what Mailchimp shows for your account. Some DNS panels append your domain twice; if k1._domainkey.example.com.example.com appears, shorten the name to k1._domainkey.
DKIM (CNAME 2) record
dkim2.mcsv.net
The second delegation record. Copy the exact Name and Value for CNAME 2 from your Domains page — usually k2._domainkey pointing to dkim2.mcsv.net. Both CNAMEs must resolve before Mailchimp will mark the domain authenticated.
DMARC record
v=DMARC1; p=none; rua=mailto:[email protected]
Published once on your root domain, covering every sender including Mailchimp. Start at p=none to watch alignment without risk, then raise to quarantine and reject once your reports show Mailchimp and your mailbox host both aligning. Point rua at an address you read.
Step by step
The whole setup, in order.
- 1 Start domain authentication in Mailchimp. In Mailchimp go to your profile, then Settings, then Domains, and choose to authenticate the domain you send from. Mailchimp will display the two DKIM CNAME records and the DMARC TXT record, each with a Name (Host) and Value you copy.
- 2 Add Mailchimp to your existing SPF. At your DNS host, open the SPF TXT record you already have for your mailbox provider and insert include:servers.mcsv.net just before the terminating ~all or -all. If, and only if, you have no SPF record at all, publish v=spf1 include:servers.mcsv.net ~all at the root.
- 3 Publish the two DKIM CNAMEs. Add both CNAME records exactly as Mailchimp shows them — k1._domainkey and k2._domainkey pointing to Mailchimp's targets. These are CNAMEs, not TXT records; picking the wrong type is the most common reason authentication never completes.
- 4 Publish DMARC on the root domain. Add the _dmarc TXT record at your root domain. Begin at p=none with a working rua address so you break nothing while you confirm every legitimate sender aligns.
- 5 Click Authenticate, then verify. Return to the Mailchimp Domains page and run Check Status. Propagation can take up to 48 hours depending on your DNS provider. Once it passes, run a full check here to confirm SPF stays under the 10-lookup limit, both DKIM CNAMEs resolve, and DMARC is graded.
Where it goes wrong
The mistakes specific to Mailchimp.
Confirm it worked
Do not trust it until you have checked it.
DNS takes a few minutes to propagate. Once it has, run a full check: it reads all three records live, counts your SPF lookups, confirms the Mailchimp DKIM selector resolves, and grades your DMARC policy — the exact things that decide whether Gmail and Outlook trust your mail.
Common questions
About Mailchimp, specifically.
Set it once. Know it stays set.
A DKIM key rotates, a vendor changes its SPF, an IP gets listed — and your carefully-configured domain quietly breaks. Monitoring watches all of it and tells you the day it changes.