Short answer
Connect your sending domain in HubSpot under Settings, Content, Domains and URLs, Email Sending, then publish the DKIM, SPF and DMARC records it gives you in your DNS. HubSpot shows the domain as authenticated only when all three verify. Gmail and Yahoo expect bulk senders to have SPF, DKIM and DMARC in place.
Why it matters
Without authentication, mailbox providers can't tell your HubSpot email from someone spoofing your domain. Unauthenticated email lands in spam or gets rejected, and since 2024 Gmail and Yahoo require SPF, DKIM and DMARC from senders who send in bulk to their users.
Steps
- In HubSpot, open Settings, then Content, then Domains and URLs, and choose the Email Sending tab.
- Select Connect sending domain and enter the domain you send from, for example
vantagepoint.ioor a subdomain such asmail.yourfirm.com. - Copy the records HubSpot shows into your DNS provider:
- DKIM: two CNAME records.
- SPF: add HubSpot's
include:value to your existing SPF TXT record. Don't create a second SPF record; a domain can only have one. - DMARC: a TXT record at
_dmarc. Start withp=noneand a reporting address, then move toquarantineorrejectonce reports show only legitimate senders.
- Return to HubSpot and verify. DNS changes can take a few hours to appear.
Common problems
- Two SPF records. Merge them into one. The
v=spf1tag and theallmechanism appear once. - Too many SPF lookups. SPF allows 10 DNS lookups. Every
include:for HubSpot, Microsoft 365, Salesforce and other senders counts. - DMARC at reject on day one. You may block your own billing system or CRM. Read the reports first.
- Sending from a subdomain. A subdomain inherits the root domain's DMARC policy if it has none of its own.
For regulated firms
List every system that sends as your domain (CRM, marketing, billing, custodian notices, portals) and give each one a named owner. Ask IT or your managed service provider to own the DNS records, so changes go through change control.
Official documentation
Frequently asked questions
Where do you connect an email sending domain in HubSpot?
In Settings, under Content, then Domains and URLs, on the Email Sending tab. Select Connect sending domain and follow the steps to add the DNS records.
What DMARC policy should we start with?
Start with p=none and a reporting address so you can see who sends as your domain. Move to quarantine and then reject once the reports show only systems you approve.
Salesforce, HubSpot, Anthropic and OpenAI change their products often. Check the official documentation before you rely on a specific setting, limit or price.
