SPF record for HubSpot
Last updated 2026-08-26
HubSpot sends marketing email, sequences and workflow notifications. Here is what to publish so it can do that as your domain, and what has to line up before DMARC will pass.
What to add. No include on your root SPF record. HubSpot generates the records for you.
What signs your mail. DKIM records HubSpot generates for your account.
You connect the domain and the From address stays where it was, so nothing that goes out is covered by the records you just published.
The SPF record
HubSpot's include is account-specific: it carries an identifier for your portal in front of
a hubspotemail.net host, so there is no single correct value to print here and
a copied one from someone else's setup authorises the wrong thing. Take it from Settings,
Content, Domains and URLs, Email sending domain, at the point where HubSpot lists the DNS
records to publish.
What is worth knowing before you get there: it is one include, and it counts against your ten lookups like any other.
Whatever you end up publishing, count the lookups afterwards. SPF allows ten DNS-querying mechanisms across the whole nested chain, and going over turns the record into a permerror that authorises nothing. Our free SPF checker resolves the chain and gives you the number.
DKIM
HubSpot uses CNAMEs under _domainkey with selectors it generates for your
portal, pointing at hosts under hubspotemail.net. Publish exactly the pair the
connect-a-domain wizard shows, then let HubSpot verify. Verification usually completes in
minutes and HubSpot will tell you which record is still missing.
DMARC alignment with HubSpot
DMARC passes when SPF or DKIM passes and the domain it authenticated matches the domain in your visible From address. A provider can pass both checks for its own domain and leave you failing. These are the HubSpot specifics:
- HubSpot sends marketing mail from the connected sending domain, which is often a
subdomain. Relaxed DMARC alignment covers that, but strict alignment
(
adkim=s) does not, and setting strict alignment is a decision people make without realising it breaks every subdomain sender they have. - Sales sequences sent through a connected personal inbox go out through Google or Microsoft, not HubSpot, so they are covered by that provider's records instead.
- A domain can only be connected to one HubSpot account at a time.
The general case is covered in alignment, explained, and the header you read to prove it is on the dmarc=fail page.
Verify it
Substitute your domain, and run these after the TTL on anything you replaced has expired:
Then send one message through HubSpot to a Gmail address you control, open Show original,
and look for dkim=pass with your domain in header.i. That single
check is worth more than any number of DNS lookups, because it tests the thing receivers
actually do.
Our SPF checker gives you the lookup count, the DKIM checker confirms a selector resolves and the key is long enough, and the DMARC checker reads your policy back to you. All three are free and none of them ask for an account.
Values here were checked against HubSpot's own documentation, at HubSpot knowledge base. Providers change DNS requirements without much announcement, so if their screen disagrees with this page, believe their screen and tell us.
A record can read correctly and still fail alignment once real mail moves through it. Receivers write that verdict into the reports they send. We read them for you, and paid plans email you the same day one names a new sender that failed, instead of holding it for Monday. See whether this sender passes. Your first domain is free.
Watch every sender on this domain
You published records for one sender, and the domain behind it usually carries several. One weekly summary covers them all. When a report first names a new source failing, we email you the same day. Pro holds 5 domains for $19 a month.
Get the weekly digestNo card · 12+ months of history · The free plan does not expire
Keep reading
Adding this to a domain that already sends? Our SPF record generator merges the include into the record you publish today rather than replacing it, the SPF checker resolves every include and counts the lookups, and the DKIM checker confirms the selector answers.