DomainCanary Start free

SPF and DKIM by provider

SPF record for Mailchimp

Last updated 19 Sep 2026

Mailchimp sends campaigns and automations from your audience. Here is what to publish so it can do that as your domain, and what has to line up before DMARC will pass.

What to add. Two DKIM CNAME records and a DMARC TXT record, copied from your Mailchimp account. Nothing in your SPF record.

What signs your mail. DKIM records Mailchimp generates for your account.

A campaign sent from an unauthenticated domain, with your DMARC policy at p=reject, turns the whole send into 550 5.7.509 bounces.

You don't need an SPF include for Mailchimp

Leave your SPF record alone. Mailchimp's domain authentication steps ask for two CNAME records for DKIM and one TXT record for DMARC, and they don't mention SPF. I checked them on 2026-09-19.

You'll still find advice to add include:servers.mcsv.net. It doesn't help DMARC. Receivers check SPF against the envelope sender, and Mailchimp sets that to its own bounce domain, so an SPF pass is a pass for Mailchimp's domain and never aligns with yours. Your mail passes DMARC on the DKIM signature.

If the include is already in your record, it does no harm and it costs one of your ten lookups. Remove it when you're close to the limit.

Whatever you end up publishing, count the lookups afterwards. SPF allows ten DNS-querying mechanisms across the whole nested chain, and going over turns the record into a permerror that authorizes nothing. Our free SPF checker resolves the chain and gives you the number.

DKIM

Mailchimp calls this domain authentication and hands you CNAME records under _domainkey whose names start with k and which point at dkim hosts on mcsv.net. The exact pair depends on when your account was set up, so copy them from Website, Domains, Authenticate rather than from any page including this one.

Once they resolve, Mailchimp signs with d=example.com and DMARC has an aligned identifier to work with.

DMARC alignment with Mailchimp

DMARC passes when SPF or DKIM passes and the domain it authenticated matches the domain in your visible From address. A provider can pass both checks for its own domain and leave you failing. These are the Mailchimp specifics:

  • Mandrill, the transactional side, is a separate product with separate records. Doing Mailchimp does not do Mandrill.
  • Mailchimp will happily send from a free mailbox address. It fails DMARC at Gmail and Yahoo, both of which publish enforcing policies on their own consumer domains, so use an address on a domain you control.
  • Verifying an email address is not the same as authenticating a domain. The first proves you can read a mailbox. Only the second changes what receivers check.

The general case is covered in alignment, explained, and the header you read to prove it is on the dmarc=fail page.

Verify it

Substitute your domain, and run these after the TTL on anything you replaced has expired:

dig +short TXT example.com dig +short TXT _dmarc.example.com

Then send one message through Mailchimp to a Gmail address you control, open Show original, and look for dkim=pass with your domain in header.i. That single check is worth more than any number of DNS lookups, because it tests the thing receivers actually do.

Our SPF checker gives you the lookup count, the DKIM checker confirms a selector resolves and the key is long enough, and the DMARC checker reads your policy back to you. All three are free and none of them ask for an account.

Values here were checked against Mailchimp's own documentation, at Mailchimp help. Providers change DNS requirements without much announcement, so if their screen disagrees with this page, believe their screen and tell us.

A record can read correctly and still fail alignment once real mail moves through it. Receivers write that verdict into the reports they send. We read them for you, and paid plans email you the same day one names a new sender that failed, instead of holding it for Monday. See whether this sender passes. Your first domain is free.

Is Mailchimp authorized to send as your domain?

We look for include:servers.mcsv.net in your SPF record and count the lookups it costs you.

Free · No signup · The result names what to change

Questions

Why does Mailchimp mail fail DMARC even with include:servers.mcsv.net published?

Because SPF authenticates the envelope sender, which Mailchimp sets to its own bounce domain, so the pass never aligns with your From domain. Completing domain authentication so Mailchimp signs with your domain is the fix.