SPF record for Constant Contact
Last updated 2026-09-04
Constant Contact sends campaigns and automated email from your contact lists. Here is what to publish so it can do that as your domain, and what has to line up before DMARC will pass.
What to add. No include on your root SPF record. Constant Contact generates the records for you.
What signs your mail. DKIM records Constant Contact generates for your account.
You verify a single From address instead of the domain, so campaigns keep going out over Constant Contact's signing domain and DMARC keeps failing.
The SPF record
Constant Contact says you do not need one. Its self-authentication page, checked on 2026-09-04, says: "Receiving mail servers check our domain's SPF record, not yours, so you do not need to add Constant Contact IP addresses to your SPF record if you have one."
The bounce address on your campaigns sits at in.constantcontact.com, and SPF is
checked against the bounce address rather than the one your reader sees. So an SPF pass
belongs to Constant Contact and aligns with nothing of yours. The CNAME records they
generate are what make DMARC pass.
Whatever you end up publishing, count the lookups afterwards. SPF allows ten DNS-querying mechanisms across the whole nested chain, and going over turns the record into a permerror that authorises nothing. Our free SPF checker resolves the chain and gives you the number.
DKIM
Constant Contact generates the CNAME record names and values for your account, along with a DMARC record, and shows them once you start self-authentication. Copy them from that screen. A set copied from another account points at the wrong host and never verifies.
Confirm it afterwards by sending yourself a campaign and checking that the signature's
d= is your domain rather than Constant Contact's. That check works whatever
the records turn out to be called.
DMARC alignment with Constant Contact
DMARC passes when SPF or DKIM passes and the domain it authenticated matches the domain in your visible From address. A provider can pass both checks for its own domain and leave you failing. These are the Constant Contact specifics:
- Constant Contact signs with its own domain until self-authentication is finished, which fails DMARC alignment under any enforcing policy.
- The bounce address stays at
in.constantcontact.comafter you authenticate. That is fine for DMARC, because alignment on DKIM alone is a pass. - Lead Gen and CRM is a separate Constant Contact product with its own records, published
as CNAMEs at
_s1._domainkeyand_s2._domainkey.
The general case is covered in alignment, explained, and the header you read to prove it is on the dmarc=fail page.
Verify it
Substitute your domain, and run these after the TTL on anything you replaced has expired:
Then send one message through Constant Contact to a Gmail address you control, open Show original,
and look for dkim=pass with your domain in header.i. That single
check is worth more than any number of DNS lookups, because it tests the thing receivers
actually do.
Our SPF checker gives you the lookup count, the DKIM checker confirms a selector resolves and the key is long enough, and the DMARC checker reads your policy back to you. All three are free and none of them ask for an account.
Values here were checked against Constant Contact's own documentation, at Constant Contact knowledge base. Providers change DNS requirements without much announcement, so if their screen disagrees with this page, believe their screen and tell us.
A record can read correctly and still fail alignment once real mail moves through it. Receivers write that verdict into the reports they send. We read them for you, and paid plans email you the same day one names a new sender that failed, instead of holding it for Monday. See whether this sender passes. Your first domain is free.
Watch every sender on this domain
You published records for one sender, and the domain behind it usually carries several. One weekly summary covers them all. When a new source first shows up failing, we email you the same day. Starter is $19 a month for 3 domains.
Get the weekly digestNo card · Per-source totals kept for life · The free plan does not expire
Keep reading
Adding this to a domain that already sends? Our SPF record generator merges the include into the record you publish today rather than replacing it, the SPF checker resolves every include and counts the lookups, and the DKIM checker confirms the selector answers.