Selector s1 · SPF include:sendgrid.net — verify yours below, pre-filled for SendGrid.
SendGrid → Settings → Sender Authentication → Authenticate Your Domain. SendGrid issues three CNAMEs: em#### (return-path), plus s1._domainkey and s2._domainkey pointing at *.wl###.sendgrid.net targets.
With "Automated Security" on (the default), SendGrid rotates keys behind the CNAMEs — your DNS never changes. If you disabled it, you have a static TXT selector instead and rotation is on you.
Your SPF TXT record on the root domain must contain include:sendgrid.net. A minimal correct record: v=spf1 include:sendgrid.net ~all. Stacking multiple ESPs? Each include costs DNS lookups against the limit of 10 — count yours here.
DKIM alone doesn't inbox. Run the full domain grade to confirm SPF, DMARC, MX and blacklist status in one shot — Gmail and Microsoft require alignment across all of them for cold outreach in 2026.
Other providers: Google Workspace · Microsoft 365 · Mailchimp / Mandrill · Zoho Mail · Any domain