SendGrid: DKIM Selector & SPF Setup

Selector s1 · SPF include:sendgrid.net — verify yours below, pre-filled for SendGrid.

SendGrid DKIM setup

SendGrid → Settings → Sender Authentication → Authenticate Your Domain. SendGrid issues three CNAMEs: em#### (return-path), plus s1._domainkey and s2._domainkey pointing at *.wl###.sendgrid.net targets.

With "Automated Security" on (the default), SendGrid rotates keys behind the CNAMEs — your DNS never changes. If you disabled it, you have a static TXT selector instead and rotation is on you.

SendGrid SPF record

Your SPF TXT record on the root domain must contain include:sendgrid.net. A minimal correct record: v=spf1 include:sendgrid.net ~all. Stacking multiple ESPs? Each include costs DNS lookups against the limit of 10 — count yours here.

Verify all three pillars

DKIM alone doesn't inbox. Run the full domain grade to confirm SPF, DMARC, MX and blacklist status in one shot — Gmail and Microsoft require alignment across all of them for cold outreach in 2026.

SendGrid rotates keys. Records drift. Interns edit DNS.

Aurelius re-verifies your DKIM, SPF, DMARC and blacklist status continuously and emails you on any regression. Free for 2 domains.

Start monitoring free