Why SPF and DKIM Matter with Brevo’s Dedicated IP

You’ve just switched to a dedicated IP in Brevo—and that’s a powerful step toward control. But with that control comes a new reality: your sender reputation now rests entirely on your shoulders.

No longer sharing space with other senders means you can’t rely on their behavior to shield you. If your emails are marked as spam or blocked, it’s not a “them” problem anymore. It’s yours.

SPF and DKIM aren’t optional extras. They’re the foundation of email authentication, proving to inbox providers that your messages are real and authorized.

Without them, even well-crafted campaigns can fail to land in inboxes—or get rejected outright. The result? High bounce rates, poor deliverability, and lost engagement.

Key takeaways

  • With a dedicated IP in Brevo, your sender reputation is no longer shared—making proper SPF and DKIM configuration essential, not optional.
  • SPF and DKIM work together to authenticate your outbound emails, reducing the chance of spam filtering or rejection by receiving servers.
  • Failing to set up either protocol can lead to high bounce rates, inbox placement drops, and long-term damage to your domain’s deliverability.

What Happens If SPF and DKIM Are Misconfigured?

If SPF and DKIM are misconfigured, your emails are more likely to be marked as spam or blocked entirely by receiving servers. Even small errors — like a typo in a record or a missing selector — can trigger rejection, especially when using a dedicated IP. Without valid authentication, your sender reputation degrades quickly, hurting deliverability over time.

Real-World Consequences of Poor Authentication

  • Messages may fail to reach recipients altogether, triggering immediate hard bounces.
  • Receiving servers use SPF and DKIM as primary checks — missing or invalid records signal potential fraud or poor practices.
  • Even minor mistakes, like incorrect DNS syntax or mismatched domains, can result in greylisting or spam classification.
  • On a dedicated IP, reputation is critical. A single failed authentication can cause a sharp drop in inbox placement.
  • Reputable email providers like Google and Microsoft use these checks as part of their spam filtering stack, per industry standards described in RFC 7208 (SPF) and RFC 6376 (DKIM).

Why This Matters More on a Dedicated IP

With a dedicated IP, your sender reputation is independent and must be built from scratch. Misconfiguration doesn’t just cause one bounce — it harms long-term deliverability. Once a reputation is damaged, recovery takes weeks, even with perfect future sending.

Let’s say you send 10,000 emails a day from a new IP. If SPF or DKIM fails on even 1% of them — that’s 100 messages — and the receiving server logs that, your IP can be flagged or throttled. You’re not just risking delivery; you’re risking your entire sending domain’s future.

Brevo’s dedicated IP requires strict alignment between email origin, SPF domain, and DKIM selector. A single mismatch breaks the chain. Use tools like MailTester’s email checker to validate each address before sending, and test inbox placement with real inboxes to catch authentication issues early. Proactive verification avoids the cost of failed delivery and reputation harm.

How SPF and DKIM Work Together on Brevo

SPF and DKIM are foundational email authentication protocols that work as a team to verify your domain's legitimacy and email integrity when using a Brevo dedicated IP. SPF confirms the sending server is authorized by your domain, while DKIM adds a digital signature to prove the message wasn’t altered in transit. Together, they signal to recipient mail servers that your emails are trustworthy, which is critical for maintaining deliverability on a dedicated IP.

SPF: Authorizing the Sending Server

SPF checks which servers are allowed to send emails on behalf of your domain. When you set up SPF in your DNS records, you list the IP addresses or servers—like Brevo’s—authorized to send from your domain. If an email comes from a server not in that list, it fails SPF and may be flagged as spam.

With Brevo’s dedicated IP, you’ll add Brevo’s outbound IP ranges to your SPF record. You can find these on Brevo’s official documentation or support pages—just ensure you don’t exceed the 10 DNS lookup limit, which can cause SPF failures.

DKIM: Ensuring Message Integrity

While SPF validates the sender, DKIM ensures the content hasn't changed. When Brevo sends your email, it adds a digital signature using a private key. Recipients’ mail servers then use your domain’s public key—published in DNS—to verify that the signature matches and that the message was unaltered.

DKIM is essential on a dedicated IP because it builds long-term sender reputation. Email providers track consistent DKIM signatures as a sign of responsible sending. A failed DKIM check can hurt your deliverability even if SPF passes.

Both protocols are non-negotiable for a dedicated IP. You can test your SPF and DKIM setup with tools like MXToolbox or RFC 7208 (SPF) and RFC 6376 (DKIM), both of which are industry-standard references.

For a real-world edge, validate the health of your sending list before deployment. Use MailTester’s bulk email verification to catch invalid or risky addresses before they damage your sender reputation.

Step-by-Step: Configure SPF for Your Brevo Dedicated IP

Log in to your domain registrar’s DNS panel, find the TXT record section, and create a new record with your domain (e.g., example.com) as the name and v=spf1 include:spf.brevo.com ~all as the value. Save it and wait 10–60 minutes for DNS propagation. Confirm it’s live using a tool like MxToolbox or a public DNS checker. Proper SPF setup prevents spoofing and improves sender reputation—critical when using a dedicated IP with Brevo.

Why SPF Matters for Dedicated IPs

With a dedicated IP, your sending reputation is entirely your responsibility. Without a properly configured SPF record, email providers may reject your messages or mark them as spam. SPF tells receiving servers: “This domain authorizes Brevo to send emails on its behalf.” It’s one of the foundational checks in email authentication, and its absence can harm deliverability.

  1. Log in to your domain registrar's DNS management panel. This could be Namecheap, GoDaddy, Cloudflare, or another provider. You need access to edit DNS records directly.
  2. Locate the TXT record section. Look for a field labeled “TXT,” “Text,” or “Custom Record.” This is where you’ll add email authentication data.
  3. Create a new TXT record with your domain as the name. Use your root domain, like example.com, not www.example.com. Some registrars allow empty or “@” as the name; use whatever your platform expects.
  4. Set the value to v=spf1 include:spf.brevo.com ~all. This tells receiving servers that only Brevo’s infrastructure is authorized to send emails from your domain. The ~all means “soft fail” for any other source—recommended for new setups or if you’re not yet ready to block all unauthorized senders.
  5. Save the record and wait 10–60 minutes. DNS changes propagate globally at different speeds. Waiting ensures the change is visible worldwide before testing.
  6. Verify the record using a public DNS checker. Tools like MxToolbox or DNS Checker let you confirm the TXT record is published and correctly formatted. A misconfigured SPF can break email deliverability.

What to Watch For

Don’t stack multiple SPF records. A domain can have only one SPF TXT record—any duplicates cause authentication failures. If your domain already has an SPF record, merge Brevo's include into it instead of creating a second one.

For deeper verification, check if your email infrastructure is performing as expected. Use MailTester’s inbox placement tester to simulate real-world delivery and confirm that your SPF configuration contributes to strong inbox placement. You can also verify individual addresses before sending with the email checker.

Step-by-Step: Configure DKIM with Brevo’s Dedicated IP

You can configure DKIM for your Brevo dedicated IP by adding a TXT record to your domain's DNS settings. This tells receiving mail servers that emails from your domain are authenticated and not spoofed. Let's walk through it.

  1. Log in to your Brevo account. You need admin-level access to manage sending domains and DNS settings.
  2. Navigate to Settings > Sending Domains. This section manages all domains used for sending via Brevo, including those tied to your dedicated IP.
  3. Select your domain. Choose the domain you're using with your dedicated IP. Only verified domains can be associated with a dedicated IP.
  4. Click 'Add DKIM'. Brevo generates a public key for your domain’s SPF/DKIM record. Copy this key exactly as shown — any change breaks verification.
  5. Go to your domain registrar’s DNS management panel. This could be Cloudflare, GoDaddy, Namecheap, or another provider. Access to DNS settings is required.
  6. Create a new TXT record. Set the name (host) to default._domainkey.yourdomain.com using your actual domain. This is the standard DKIM selector format defined in RFC 6376.
  7. Paste the DKIM public key. Include the entire key value provided by Brevo. Make sure it’s not truncated and contains no extra spaces.
  8. Save the DNS record. DNS propagation can take up to 48 hours, though it’s often faster. Avoid rechecking too soon.
  9. Return to Brevo and confirm DKIM. After propagation, click “Verify” in Brevo’s interface. It will query DNS to confirm the record exists and is correct.

Why DKIM Matters with a Dedicated IP

DKIM proves your emails haven’t been altered in transit. With a dedicated IP, your sender reputation is entirely dependent on your email practices. Proper DKIM configuration reduces the risk of your messages being marked as spam or rejected outright.

Spam filters use DKIM as one of several checks. If it fails, even well-intentioned campaigns can end up in junk folders. According to industry standards, unauthenticated emails have a significantly higher chance of being blocked.

Once DKIM is active, your messages carry a digital signature that receivers verify. This improves deliverability and helps maintain your sender reputation over time.

After setup, run an inbox placement test to validate the end result. Use MailTester’s inbox placement checker to see how your emails appear in real inboxes across providers like Gmail, Outlook, and Yahoo.

Next: Test Your Configuration

Don’t assume it works immediately. Use tools like MxToolbox to verify your DKIM record is visible in public DNS.

Once confirmed, start small. Send test emails to known addresses and check their headers for the DKIM signature. A successful result means your email authentication is active.

With DKIM in place, you’re one step closer to consistent inbox placement with your dedicated IP.

How Brevo’s Dedicated IP Affects Authentication Requirements

With a dedicated IP in Brevo, you’re on the hook for strong authentication—SPF and DKIM must be set up correctly and maintained, because there’s no shared IP safety net. Unlike shared sending environments, where deliverability can still succeed even with weak authentication, a dedicated IP requires clean, consistent DNS records to avoid being flagged as spam. You’re not just sending through Brevo’s infrastructure—you’re representing your domain, and poor setup directly impacts your sender reputation.

Why Authentication Matters More on Dedicated IPs

When you use a shared IP, platforms like Brevo can absorb some of the risk—their reputation covers minor misconfigurations. But with a dedicated IP, your sending reputation is isolated. One failed authentication attempt can harm access for all messages from that IP. This is why proper SPF and DKIM aren’t optional—they’re required to maintain trust with receiving mail servers.

SPF tells receiving servers which IPs are allowed to send on your domain's behalf. DKIM signs each message cryptographically, proving it hasn’t been altered in transit. Together, they form a core part of modern email security standards defined by RFC 7208 and RFC 6376. A mismatch or missing record breaks this trust and can land your emails in spam folders or block them entirely.

Your DNS Is the Gatekeeper—No Exceptions

Brevo handles the mail server side, but your DNS setup is what determines whether emails are accepted or rejected. If your SPF record is missing, too broad, or conflicts with other records, messages may be rejected or marked as suspicious. Same with DKIM: if the key is invalid or the signing fails, the message fails verification.

Even small changes—like updating your sending infrastructure or adding a new third-party service—can break SPF if not reflected in your DNS. That’s why it’s not enough to set it once. You need to monitor your DNS records regularly, especially after infrastructure changes. Tools like MXToolbox can help test SPF and DKIM alignment in real time.

Before sending with a dedicated IP, run a full list check to catch high-risk or invalid addresses. Invalid emails can trigger red flags even if your authentication is solid. Use MailTester’s bulk verification to clean your list and spot potential issues before they hurt deliverability.

Authentication isn’t a one-time setup. It’s ongoing hygiene. Keep SPF and DKIM valid, monitor your domain's reputation with tools like Spamhaus, and ensure your sending practices align with industry standards. That’s how you turn your dedicated IP into a durable asset, not a delivery liability.

Common Mistakes That Break SPF and DKIM

You’re likely breaking SPF or DKIM if you have multiple SPF records, use incorrect hostnames in DKIM, or fail to wait for DNS propagation. These errors cause deliverability failures, even with a dedicated IP. Let’s fix them before you send.

SPF Errors That Cause Rejection

  • Having more than one SPF record in DNS: only the first one is evaluated. Use include: to combine multiple sources instead.
  • Using a malformed or incomplete mechanism like v=spf1 ~all without adding Brevo’s SPF include: include:spf.brevo.com. This breaks SPF alignment entirely.
  • Forgetting that SPF has a 10 mechanism limit — including too many third-party services (like email platforms, marketing tools, or backup providers) can push you over the limit.

DKIM and DNS Pitfalls to Avoid

  • Using the wrong hostname in your DKIM record. It’s not default._domainkey — it must be default._domainkey.yourdomain.com. The domain part is critical.
  • Copying an outdated DKIM selector or value. Brevo generates a unique key for each domain. If you reuse an old one or misconfigure the text record, DKIM fails validation.
  • Testing too soon after DNS changes. DNS propagation can take up to 48 hours. You’ll get false failures if you check before the record is live.
  • Using a non-unique selector. If your domain uses a selector like mail or dkim without customizing it, you risk collisions with other services if those selectors are shared.

When in doubt, use a DNS checker like MXToolbox or RFC 7208 to validate your SPF and DKIM records. These tools show real-time DNS status and highlight syntax errors.

Before you send your first campaign with Brevo's dedicated IP, verify your DNS setup with MailTester’s inbox placement test. It checks if your SPF, DKIM, and DMARC are properly configured and visible to receivers. Real-time feedback helps you fix configuration leaks before they hurt your sender reputation.

How MailTester Can Verify Your SPF and DKIM Setup

With MailTester, you can test if your Brevo domain’s SPF and DKIM configurations work as intended by simulating real inbox delivery attempts. You’ll catch issues before they hurt your sender reputation, even after setting up a dedicated IP. Use inbox placement testing, bulk verification, and real-time checks to validate both your technical setup and the quality of your email list.

Test Real-World Delivery Before Sending

You’ve configured SPF and DKIM on your Brevo dedicated IP—great. But do they actually work when a real inbox sees your message? MailTester’s inbox placement tester sends a test email to major providers like Gmail, Outlook, and Yahoo, and reports whether it lands in the inbox, spam, or gets blocked. It tells you if your authentication setup is recognized, whether your domain reputation is healthy, and if your message structure (headers, content) triggers filters.

Some ISPs evaluate multiple factors beyond just SPF and DKIM, including sending volume, engagement, and feedback loops. Testing with MailTester gives you a realistic preview of how your messages are treated in 2024’s cluttered inbox environments. For context, tools like Spamhaus track abuse patterns that affect deliverability, but you can’t see how your own messages fare unless you test.

Prevent Reputation Damage With Clean Lists

Even with perfect authentication, sending to invalid, catch-all, or disposable email addresses harms your sender reputation. Each bounce or non-delivery affects your overall score. MailTester’s bulk list verification flags these risks before you send—whether you’re using Brevo, SendGrid, or another platform.

You’ll see which addresses are invalid, which might be catch-alls (meaning they accept any email), and which come from domains like Mailinator or TempMail—commonly used for fake signups. Removing these before sending keeps your bounce rate low and maintains inbox placement. Use bulk verification to clean up your list and reduce waste.

For automated workflows, you can integrate MailTester’s real-time API to check addresses as users sign up. This is especially useful in high-volume applications where sending to invalid emails is a real risk. With a simple API call, you get verdicts like “valid,” “catch-all,” or “risky” before the first email is sent. See the API documentation for implementation examples.

Why Sender Reputation Depends on Proper Authentication

SPF and DKIM aren’t just technical formalities—they’re core signals that receiving mail servers use to judge whether you’re a trustworthy sender. A single authentication failure can lower your sender reputation, especially with a dedicated IP, where every bounce or rejection counts. Over time, repeated issues can lead to inbox filtering or outright blocking.

How Authentication Directly Impacts Sender Reputation

  • Mail servers check SPF and DKIM results in real-time for every incoming message. A failed check adds negative weight to your sender reputation score.
  • Consistent failures—even on a few messages—signal poor list hygiene or misconfiguration, which can trigger automated filters.
  • With a dedicated IP, your reputation is isolated. Unlike shared IPs, there’s no “good neighbor effect” to absorb minor issues. A few failures can trigger blocklists or degrade inbox placement.
  • Even if your content is perfect, poor authentication will cause your emails to land in spam or get rejected outright.
  • Reputation is built over time: consistent success improves it, but failures accumulate damage that’s hard to reverse.

What Happens When SPF or DKIM Fails

Here’s what a failure looks like in practice:

  • If SPF fails, the server checks whether the sending IP is authorized in your domain’s TXT record. If not, the message is flagged.
  • If DKIM fails, the server verifies the digital signature against your public key. A mismatch means the message was altered or forged.
  • Both failures are red flags. Many receiving systems penalize senders with repeated issues, especially on dedicated IPs.
  • Even temporary failures (like a DNS outage) can leave traces in your reputation history.

Using a tool like MailTester’s integration with Brevo helps verify your list’s health before sending, reducing the risk of sending to addresses that will trigger reputation issues. It catches invalid or catch-all emails early.

Think of SPF and DKIM as the foundation of your sending credibility. Even with a dedicated IP, poor authentication erodes trust faster than you might expect. The system is designed to protect users—your ability to send successfully depends on proving you’re a reliable source.

For deeper insight into how mail servers evaluate sending reputation, see RFC 7208 (SPF specification) and RFC 6376 (DKIM specification). These standards define how receivers validate messages and weigh their authenticity in real-time.

Final Steps: Check, Test, and Maintain Your Setup

You’ve set up SPF and DKIM with your Brevo dedicated IP. Now verify it works: check DNS records with a tool like MxToolbox, send test emails to Gmail, Outlook, and Yahoo to spot spam flags, review Brevo’s bounce reports, and run monthly list hygiene with MailTester to catch invalid or risky addresses before they hurt your deliverability.

  1. Validate DNS records using a third-party tool. Use MxToolbox or a similar service to confirm SPF and DKIM records are published and queryable. This ensures email providers can authenticate your messages. A misconfigured record causes rejection or spam marking, even with a dedicated IP.
  2. Send test emails to major inboxes. Send a plain-text email from your Brevo account to a Gmail, Outlook, and Yahoo address. Check if it lands in the inbox or gets flagged as spam. This test exposes hidden issues like poor reputation or misaligned authentication.
  3. Review bounce reports in Brevo. Monitor your account’s bounce logs daily for a week after setup. Hard bounces indicate invalid addresses; soft bounces often signal temporary issues. Clean your list promptly—persistent bounces harm your sender reputation.
  4. Run monthly list hygiene with MailTester. Use MailTester’s bulk verification to scan your entire list. It checks for syntax errors, role accounts, disposable domains, and catch-all addresses. A clean list improves inbox placement and reduces bounces. Run a bulk verification to find and remove weak addresses before sending.

Why This Matters

Authentication is only effective if it’s correct, readable, and consistently maintained. Even with a dedicated IP, email services still reject messages from unverified sources. SPF and DKIM don’t auto-fix poor list quality. That’s why regular checks and cleanups are essential.

Spam filters rely on behavioral signals. Sending to invalid or risky addresses raises red flags. Major providers like Google and Microsoft track delivery patterns across millions of users. A single high bounce rate can trigger throttling or IP blacklisting.

Think of this setup as a firewall. The firewall works only if it’s properly installed, tested, and kept clear of garbage. Brevo provides the infrastructure; you must verify its integrity and maintain your data quality. It’s not a one-time step.

“List hygiene is not optional—it’s foundational to consistent deliverability.” — Industry-standard practice, validated by multiple email operations teams.

Monthly checks with a tool like MailTester ensure your list stays compliant and trusted. Use the real-time API to validate addresses at the point of capture, or send a full list for auditing. No credit expires—so you can keep verifying without pressure.

The Bottom Line: Authenticity is Non-Negotiable on a Dedicated IP

SPF and DKIM are not optional add-ons. They are mandatory for any Brevo dedicated IP setup. Without them, your emails are unlikely to reach inboxes and may be flagged or blocked.

A single misconfiguration—like a missing TXT record or incorrect selector—can trigger delivery failures or harm your sender reputation. This is especially risky with a dedicated IP, where your reputation is isolated and heavily weighted.

Authentication is the foundation of deliverability. Missteps here lead to immediate consequences.

Use MailTester to validate your email list health and confirm your SPF and DKIM records are correctly published. It’s the most reliable way to ensure your messages land in inboxes, not spam folders.

Sources

Keep reading

Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.

Frequently asked questions

Does Brevo handle SPF and DKIM automatically?

No. Brevo provides the authentication records, but you must publish them in your DNS. You manage the domain configuration.

How long does DNS propagation take?

Typically 10 to 60 minutes, but can take up to 4 hours depending on your DNS provider and TTL settings.

Can I use multiple SPF records?

No. Only one SPF record is allowed per domain. Use include mechanisms to combine multiple sources.

What if my DKIM record fails to verify?

Check the hostname (must be default._domainkey.yourdomain.com), ensure the public key is correct, and confirm it was saved as a TXT record.

How does a dedicated IP change my email deliverability needs?

You manage all reputation signals—authentication, list hygiene, engagement, and bounce rates—on your own.

How often should I test my SPF and DKIM records?

Verify after setup and periodically every 3 to 6 months, or after any DNS change.

Can I use MailTester to test my domain’s SPF and DKIM?

Yes. Use inbox placement testing or the real-time API to verify both delivery and authentication alignment.

Do disposable email addresses hurt sender reputation?

Yes. Sending to disposable domains can trigger spam filters and damage sender reputation, especially at scale.

What is a catch-all email address, and why is it risky?

A catch-all accepts all incoming email, even invalid addresses. It often indicates poor list hygiene and can harm deliverability.

How does MailTester’s 98.9% accuracy help with deliverability?

High accuracy reduces sending to invalid or risky addresses, keeping your sender reputation clean and improving inbox placement.

Can I test my email list before sending with Brevo?

Yes. Use MailTester’s bulk verification to clean your list before importing into Brevo, reducing bounces and improving deliverability.

What’s the difference between a dedicated IP and a shared IP?

A shared IP is used by multiple senders; a dedicated IP is exclusive to you. With a dedicated IP, your reputation is your own responsibility.