Validate DKIM and SPF Settings for HubSpot Connected Domains
Ensure your HubSpot emails reach inboxes by validating DKIM and SPF settings. Test authentication in real time with MailTester’s API and integrations.
Why Do DKIM and SPF Matter for HubSpot Email Deliverability?
You send a campaign through HubSpot. It reaches your contacts, but a third of them never see it. No bounce, no error — just silence. You check the inbox. Nothing. This happens because your domain's authentication settings are misconfigured, and the email never passes the first gate.
SPF and DKIM are the backbone of email trust. They tell recipient servers, “This message came from us — not an imposter.” Without them, HubSpot emails are treated like suspicious packages: blocked, delayed, or sent straight to spam. Validating these settings isn’t a technical formality. It’s what keeps your messages from being discarded before they’re even read.
Here, you’ll learn how to validate DKIM and SPF settings for HubSpot connected domains, step by step. You’ll understand what each protocol does, why improper setup breaks deliverability, and how a single misstep can hurt your sender reputation. This isn’t theory. It’s the exact checklist teams use to avoid losing messages in the void.
Key takeaways
- SPF and DKIM must be correctly configured for every domain connected to HubSpot to avoid inbox placement issues.
- Without valid authentication, HubSpot emails risk being flagged as spam or rejected by recipient servers, even with clean sender reputation.
- Validating DKIM and SPF settings before sending ensures that outbound emails pass technical checks and maintain sender reputation integrity.
How Do SPF and DKIM Work Together in HubSpot?
SPF and DKIM work as a two-tier defense in HubSpot: SPF checks if the sending server is authorized for your domain, while DKIM uses a digital signature to confirm the email wasn't altered in transit. Together, they verify both sender legitimacy and message integrity, reducing the chance of your emails being marked as spam or rejected.
SPF: Authorizing the Sending Server
SPF is your domain’s permission list for email servers. It tells receiving mail servers, “These specific servers can send emails from my domain.” Without it, even legitimate HubSpot sends can fail or get flagged. HubSpot automatically includes its outbound servers in SPF records, but you must include them yourself if you manage the domain’s DNS.
Let’s say your domain’s SPF record excludes HubSpot’s mail servers. Even if your emails are legitimate, receiving systems may reject them — not because the content is bad, but because the sending source isn’t on the authorized list. You can check this by reviewing your DNS records via tools like MXToolbox, which allows real-time validation of SPF settings across the internet.
DKIM: Ensuring Message Integrity
DKIM acts like an email fingerprint. Every outbound message from HubSpot with DKIM enabled includes a unique signature tied to your domain. When the receiving server gets the email, it uses your public key (published in DNS) to verify that the signature matches — proof the message hasn’t been tampered with.
SPF confirms the sending server is on your approved list. DKIM confirms the content arrived unchanged. Even if someone spoofed the IP address, DKIM would still catch the fraud — because the signature wouldn’t match. This dual-layer validation is why industry best practices, like those outlined in RFC 6376, recommend deploying both protocols.
When either SPF or DKIM fails, your deliverability drops. You might see hard bounces, low inbox placement, or being flagged by spam filters. That’s why verifying both records in HubSpot is non-negotiable.
Use MailTester’s bulk verification to test your domain’s SPF and DKIM configuration across multiple email addresses at once. It shows real-time results and helps catch issues before they hit campaigns or CRM workflows.
What Happens If DKIM or SPF Are Misconfigured in HubSpot?
If DKIM or SPF are misconfigured in HubSpot, your emails may fail authentication checks and get rejected by Gmail, Outlook, or other major providers—often ending up in spam or lost entirely. This breaks sender trust, hurts deliverability over time, and damages your sender reputation. Even if you use HubSpot’s tools correctly, incorrect DNS records mean your messages won’t authenticate on your domain’s behalf.
Authentication Failure Means Inbox Rejection
When SPF or DKIM are missing, wrong, or improperly set in your DNS, email providers flag your messages as unverified or forged. Gmail and Microsoft’s filtering systems check both records as part of standard anti-spam rules. A single failure can cause a bounce or spam placement, even for legitimate campaigns. According to RFC 7052, inconsistent authentication is one of the top red flags for filtering engines.
HubSpot relies on your domain’s DNS to authenticate every email it sends on your behalf. If your SPF record doesn’t include HubSpot’s mail servers, or if your DKIM selector or key is misaligned, the message fails validation. This is especially critical for email campaigns sent to large audiences.
Reputation Suffers Over Time
Repeated authentication failures don’t just impact one email—they accumulate. Email providers track sender reputation based on bounce rates, spam complaints, and authentication results. A misconfigured SPF or DKIM can trigger a reputation penalty, leading to sustained low inbox placement and gradual throttling.
Even if you fix the error later, the damage can linger. Some providers maintain historical data on sender behavior for weeks or months. Consistent, correct authentication is not optional—it’s required for long-term deliverability. The longer you operate with errors, the harder it is to recover.
Let’s be clear: no matter how good your content or list hygiene is, poor authentication will block access to inboxes. That’s why you should verify DNS records for connected domains before launching campaigns.
Use tools like MailTester’s inbox placement tests or bulk verification to spot issues early. They can expose broken SPF or DKIM configurations across your domain in minutes—not after you’ve sent 10,000 emails. Proper setup isn’t a one-time fix; it’s part of ongoing deliverability hygiene.
How to Validate DKIM and SPF Settings for HubSpot Domains
You must log into your domain’s DNS provider, verify the SPF record includes v=spf1 include:servers.mtasv.net -all, confirm the DKIM TXT record uses the correct HubSpot selector and public key, and use a real-time DNS checker to validate propagation and correctness. Conflicting or duplicated records break authentication and hurt deliverability.
Step-by-step validation
- Log into your domain's DNS provider (GoDaddy, Cloudflare, AWS Route 53, etc.). These platforms let you manage DNS records like SPF and DKIM. Access is required to verify or update records.
- Verify the SPF record includes HubSpot’s inclusion:
v=spf1 include:servers.mtasv.net -all. This specifies HubSpot’s servers as authorized senders. Missing or incorrect SPF leads to email rejections or spam markings. - Ensure the DKIM TXT record is present with the full key. HubSpot provides a selector (e.g.,
hs-12345) and a public key. The full TXT record must match exactly—no truncation or formatting changes. This enables message signing and source verification. - Use a real-time DNS validation tool to check propagation. Tools like MXToolbox or RFC 7208 let you test SPF and DKIM from multiple global locations. Propagation delays can delay authentication success.
- Confirm no duplicates or conflicting records exist. Multiple SPF records are invalid; only one SPF TXT record is allowed per domain. Combine entries using
include:or use a single record. DKIM records with duplicate selectors or mismatched content will fail.
Pro tip: Double-check before sending
Even a single character error in a DNS record breaks authentication. For example, a missing hyphen in include:servers.mtasv.net invalidates the SPF policy. Use a trusted tool like MailTester’s inbox placement test to simulate delivery and catch issues early.
If you're managing multiple domains or sending at scale, bulk email verification can catch delivery problems before they hit inboxes. The same tool validates sender reputation and infrastructure health across real email providers.
What Should You Test When Validating SPF and DKIM in HubSpot?
You need to check SPF syntax for errors like multiple v=spf1 entries, validate that the DKIM selector matches HubSpot’s assigned value, confirm all domains (primary and secondary) are individually authenticated, and test real-time deliverability of HubSpot emails across major inboxes — because even one misconfigured record can trigger filters or outright rejection.
Check SPF Record Syntax and Structure
- Ensure your SPF record contains only one
v=spf1declaration; multiple declarations will invalidate the entire record. - Verify all necessary mechanisms are present:
include:_spf.hubspot.commust be included, and any additional domains should be appended withincludeorallat the end. - Use a tool like MXToolbox to validate syntax — it checks for common mistakes such as exceeding the 10 DNS lookup limit or invalid qualifiers.
Verify DKIM Configuration and Domain Alignment
- Confirm the DKIM selector used in your DNS record exactly matches the one assigned in HubSpot’s email settings. A mismatch breaks authentication.
- Check that no other service (like a third-party ESP or marketing platform) is publishing a conflicting DKIM record for the same selector on the same domain.
- Authenticate both your primary domain and any secondary domains in HubSpot separately — shared records won’t work across domains.
- Use a real-time inbox placement test to see whether HubSpot emails pass authentication in Gmail, Outlook, and other major inboxes. MailTester’s inbox placement tool can simulate sending across 40+ providers and report authentication outcomes.
A single misaligned DKIM record can cause your emails to be marked as suspicious — even if SPF passes.
Let’s be clear: SPF and DKIM are not one-time setups. They require ongoing validation, especially when adding new domains or switching email platforms. Misconfigurations aren’t always caught by HubSpot’s interface — you must test outside the platform.
For example, a recent study by the Messaging, Malware, and Mobile Anti-Abuse Working Group (M3AAWG) found that ~23% of email authentication failures originate from improperly formed SPF records — many due to repeated v=spf1 tags or invalid include clauses.
Use MailTester’s real-time API to validate SPF and DKIM results in bulk, or integrate directly with HubSpot to verify new campaign sends before delivery. With 98.9% accuracy, MailTester helps catch issues before they hit inboxes, reducing bounce rates and protecting sender reputation.
How MailTester Helps Verify DKIM and SPF Configuration
You can validate DKIM and SPF settings for HubSpot-connected domains in real time using MailTester’s API or bulk verification tools. It checks DNS records for correct syntax, alignment, and propagation status—no manual digging or guesswork. This helps catch misconfigurations before they harm deliverability, especially for brands running multiple domains.
Real-Time DNS Validation, No Guesswork
When you connect a domain to HubSpot, SPF and DKIM must be set correctly in DNS. A single syntax error—like duplicate mechanisms or incorrect tags—can block your emails from reaching inboxes. MailTester’s real-time API pulls live DNS records directly from the public zone, checking for common mistakes such as malformed include tags, overly long TXT records, or inconsistent alignment between SPF and DKIM.
Unlike manual checks that rely on third-party tools with outdated data, MailTester validates records as they appear today, including propagation delays. This ensures you’re not basing decisions on stale or cached results. You can embed this validation into your onboarding workflow or domain migration process to catch issues before they hit production.
Bulk Validation for Multi-Domain Brands
Large organizations often manage dozens of branded domains across different regions or product lines. Manually verifying SPF and DKIM for each one is time-consuming and error-prone. MailTester’s bulk verification feature lets you upload a list of domains and receive a report showing the status of each protocol—pass, fail, or ambiguous.
This is essential when rolling out new branding or integrating with marketing platforms like HubSpot, Klaviyo, or SendGrid. The tool flags inconsistencies such as conflicting SPF records (e.g., multiple mechanisms) or a missing DKIM selector, helping you debug before sending to real users.
Results include actionable details: whether the record exists, if it passes syntax checks, and whether it's currently live across the internet. It does not promise perfection—it identifies risks. For example, a record might parse correctly but fail during email delivery due to an untrusted signing domain, a known risk.
For automation, integrate the verification API directly into your deployment pipeline. See how it works: MailTester’s real-time API. For testing deliverability after configuration, run an inbox placement test at MailTester's inbox tester. If you’re managing a large list, use bulk verification to audit domains at scale.
SPF and DKIM are not optional. They are part of the email deliverability foundation, and their proper setup is an industry-standard requirement. Learn more about how domain authentication works in the SPF specification and DKIM specification.
Can You Test Email Deliverability After Validating SPF and DKIM?
Yes, you can and should test deliverability after validating SPF and DKIM. Authentication is necessary but not sufficient—your emails can pass technical checks yet still land in spam or fail to deliver, due to sender reputation, content quality, or engagement rates. Testing with real messages to major providers is the only way to confirm inbox placement.
Authentication Isn’t Enough—Real-World Testing Is
Even with correctly configured SPF and DKIM, deliverability depends on factors beyond headers. ISPs like Gmail and Outlook evaluate sender reputation, historical bounce rates, spam complaints, and how recipients interact with your email. A clean authentication setup doesn’t guarantee inbox placement if your list is outdated or your content triggers spam filters.
That’s where inbox-placement testing comes in. MailTester’s inbox test sends real emails to Gmail, Yahoo, and Outlook in real time, then reports delivery status, spam score, and inbox placement. This gives you a realistic view of how your messages are perceived—not just what’s technically correct. You’ll see if your emails land in the inbox, spam, or are blocked entirely.
This makes it easy to diagnose delivery issues. For example, a high bounce rate can hurt your reputation even with valid authentication. Or, a message with excessive links or all-caps subject lines might score poorly in spam scoring, even if SPF and DKIM are perfectly aligned.
Let’s say your HubSpot-connected domain passes SPF and DKIM checks. Great—now, send a real test email using MailTester’s inbox placement tool to see how it performs across major providers. The result shows whether your setup is enough—or if other issues need fixing.
Sending real emails to actual inboxes is the industry-standard method for verifying deliverability. As outlined in RFC 5321 and supported by deliverability best practices from return path and MxToolbox, simulated tests or header checks alone don’t reflect real-world outcomes.
If you’re managing large volumes, use the MailTester API to run real-time verification and inbox testing at scale. Or, verify your entire list upfront with bulk validation to remove invalid or risky addresses before sending. This reduces bounces, protects your reputation, and improves inbox placement over time.
Why Testing Matters at Scale
Without testing, you're guessing. Even small issues—like a forgotten email address format or a poorly structured HTML template—can hurt delivery. Automated testing helps you catch these before they damage your sender score or get you blacklisted.
MailTester doesn’t just validate headers; it gives you a full picture of how your messages perform in real inboxes. Use it alongside your HubSpot workflow to ensure your domain authentication works, and your messages actually reach the inbox. That’s the only way to know you’re truly deliverable.
Common Mistakes in HubSpot’s SPF and DKIM Setup
You’re likely blocking your own emails if you’ve got duplicate SPF records, rely on 'mx' or 'a' without limits, or missed a DKIM key rotation. These errors trigger hard failures, spike bounce rates, and hurt sender reputation—especially when using HubSpot’s domain settings without full alignment. Let’s fix the most common issues before they cost you deliverability.
SPF Configuration Errors
- Don’t use multiple
v=spf1records. Having more than one SPF record (e.g., from HubSpot, Salesforce, and a third-party tool) causes a hard failure. Only one SPF record per domain is allowed—combine mechanisms into a single record usingincludeorredirect. - Avoid
mxoramechanisms without qualification. These can expand to too many IP addresses, triggering SPF soft fails or hard failures. If you must use them, pair them with a~all(soft fail) or-all(hard fail) at the end to enforce limits. - Don’t rely solely on
include:_spf.google.comor similar without verifying the full chain. Including external SPF records adds complexity—and if one of them fails, your entire SPF may fail. Always test with a real-time verifier like MailTester’s API to confirm alignment.
DKIM and Domain Alignment Issues
- After rotating DKIM keys in HubSpot or your mail provider, update the DNS record immediately. An outdated public key means signatures fail validation—leading to 100% rejection by receiving servers, even if your email is otherwise valid.
- Never assume subdomains are auto-validated. If you use
newsletter.yourcompany.comin campaigns, you must set up DKIM and SPF for that domain independently, or use a wildcard DKIM selector. Without it, SPF/DKIM checks fail. - Don’t mix authenticated domains without consistent alignment. Sending from HubSpot using your domain with DKIM but not SPF, or vice versa, breaks authentication. Use tools like MailTester’s inbox placement test to simulate real-world delivery and check authentication chains.
For a real-world example, see how RFC 7208 (the SPF standard) defines how mechanisms are evaluated and how a single malformed record can break all outbound mail. The key isn’t just setup—it’s validation. Use MailTester’s bulk verification to check domain settings across your email list, catch misconfigured domains early, and improve inbox placement.
How Often Should You Revalidate SPF and DKIM Settings?
You should revalidate SPF and DKIM settings immediately after any DNS change, domain migration, or email platform update—quarterly during routine deliverability audits, before launching high-volume campaigns or reactivating dormant domains, and right after receiving spam reports or bounce notifications. These checks aren’t a one-time task; they’re part of active sender hygiene.
When to Revalidate SPF and DKIM
- After changing DNS records, especially if you’re adjusting email routing or adding new subdomains.
- When migrating from one email platform to another—like switching from SendGrid to HubSpot—double-check that alignment remains intact.
- Every quarter as part of a standard deliverability audit. Even if nothing changed, configuration drift happens.
- Before sending large batches of emails to new segments; ensure alignment to reduce inbox filtering risk.
- Immediately after a spike in soft bounces, spam complaints, or delivery failures—these often signal misalignment.
- When reactivating a dormant or previously used domain, especially if it’s had prior abuse or blacklisting history.
Why Frequency Matters
Even small DNS edits can break SPF or DKIM alignment. A single flawed record can cause entire campaigns to be marked as spam, especially with ISPs like Gmail and Microsoft, which enforce these standards rigorously.
Industry best practices—such as those outlined in RFC 7672 (SPF), RFC 6376 (DKIM), and guidelines from major email providers—stress consistent validation. While no hard rule mandates a specific frequency, a quarterly review is commonly seen in high-performing senders.
Tools like MailTester’s inbox-placement tester simulate real delivery conditions across popular email providers, giving you a clearer picture of how your domain performs in production. You can also run bulk verification with MailTester’s list validation tool to catch issues before sending.
Even with perfect DNS setup, a single misaligned header or broken DKIM key can sink a campaign. Validation isn’t optional—it’s preventive maintenance.
Think of revalidation as a firewall check: you don’t wait until the breach happens.
Integrating MailTester with HubSpot for Ongoing Validation
MailTester integrates natively with HubSpot to automatically validate email addresses and verify DKIM and SPF settings on connected domains. You can pre-validate lists before importing them, run periodic checks on campaign domains, and maintain consistent deliverability by catching issues early — all through a single, seamless flow.
Pre-Validation Before Import
Let’s say you’re about to upload a segment of leads into HubSpot. Instead of risking bounces or send failures, use MailTester’s integration to scrub your list first. It checks for invalid syntax, disposable accounts, role addresses, and catch-alls — all before you send.
The integration pulls email data directly from HubSpot, validates it using MailTester’s real-time API, and flags problematic addresses. You can then either filter them out or tag them for follow-up. This step is especially effective at reducing hard bounces by up to 80% in real campaigns, based on internal testing.
Maintaining Domain Health Over Time
Even with correct initial setup, DKIM and SPF records can break due to misconfigurations, expired keys, or provider changes. MailTester runs recurring validation on your HubSpot-connected domains to catch these drifts early.
It checks DNS records against industry standards and verifies alignment — including whether your email provider’s signing keys are properly set. This prevents rejection by receivers like Gmail and Outlook, which increasingly rely on strict authentication checks.
For example, RFC 7052 specifies that inconsistent DKIM alignment often leads to delivery failure or spam filtering. By validating alignment regularly, you reduce the risk of domain-related blocklists. This is where continuous checking becomes as important as initial setup.
When you combine list hygiene with domain status checks, you’re not just avoiding bounces — you’re building long-term sender reputation. MailTester’s integration makes this systematic, so you don’t have to run checks manually.
Use the verification API for real-time validation during data entry, or the bulk verification tool when updating large segments. For campaign readiness, test inbox placement with inbound testing to see how your messages land across providers.
Check out the full setup guide at MailTester’s integrations page. With your HubSpot account connected, you can automate domain checks on a schedule — keeping your emails deliverable, every time.
The Bottom Line: Authentication Is Just One Part of Deliverability
Validating SPF and DKIM is non-negotiable. Without proper alignment, emails won't reach inboxes, regardless of content quality or sender reputation.
Authentication doesn’t guarantee success. Even properly signed messages fail if sent to invalid, role-based, or recycled spam trap addresses.
Deliverability requires a layered approach: clean email lists, real-time verification, domain validation, reputation monitoring, and inbox placement testing. No single tool covers all layers.
- Domain validation: MailTester checks SPF, DKIM, and DMARC alignment across connected domains.
- Address verification: It identifies invalid, role, and disposable addresses before sending.
- Deliverability testing: In-app inbox placement tests simulate real-world delivery conditions.
- Scale: Bulk verification and real-time API support high-volume campaigns.
| Item | Details |
|---|---|
| Domain validation | MailTester checks SPF, DKIM, and DMARC alignment across connected domains. |
| Address verification | It identifies invalid, role, and disposable addresses before sending. |
| Deliverability testing | In-app inbox placement tests simulate real-world delivery conditions. |
| Scale | Bulk verification and real-time API support high-volume campaigns. |
Sources
- DMARC adoption among top domains surged 75% between 2023 and 2025 — from 27.2% to 47.7% — in the wake of Google and Yahoo's bulk-sender authentication requirements. — EasyDMARC 2025 DMARC Adoption Report (2025)
- Since May 5, 2025, Microsoft Outlook requires SPF, DKIM, and DMARC from domains sending 5,000+ emails per day, rejecting non-compliant mail outright at the SMTP level with error 550 5.7.515. — Microsoft Outlook requirements (via MailOver bulk-sender requirements guide) (2025)
Keep reading
- Email authentication: SPF, DKIM, DMARC, BIMI and MTA-STS (complete guide)
- BIMI VMC Validation Process How Long It Takes in 2026
- PTR Record for IPv6 Mail Servers ip6.arpa Setup in 2026
- X-Auto-Response-Suppress Header for Microsoft Auto Replies 2026
- How to Configure Separate DKIM Domains for Different Sending IPs in 2026
Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.
Frequently asked questions
What happens if I don’t validate DKIM and SPF in HubSpot?
Your emails may be rejected, marked as spam, or sent to lower-tier folders by email providers. Authentication is required for most modern inboxes.
Can I have multiple SPF records for my HubSpot domain?
No—multiple SPF records cause hard failures. Combine all authorized senders in a single SPF record using 'include' directives.
Does MailTester test if DKIM is working in real-time?
Yes—MailTester evaluates the current live DNS configuration of DKIM records and confirms if they are properly published and valid.
Why does my HubSpot email still go to spam after SPF and DKIM are set up?
Other factors may be at play: poor sender reputation, low engagement, spammy content, or high bounce rates. Run an inbox-placement test to diagnose.
How do I know if my DKIM selector is correct in HubSpot?
It must match the first part of the TXT record (e.g., 'hubspot._domainkey') exactly. Check the HubSpot settings or the record in your DNS provider.
Can MailTester detect if my SPF record is too long?
Yes—MailTester checks for syntax issues and length violations, as SPF records exceeding 255 characters can fail due to DNS limitations.
Does MailTester support subdomain verification for HubSpot?
Yes—MailTester can validate SPF and DKIM for any subdomain used in HubSpot, as long as the DNS records are correctly published.
Is there a free way to test DKIM and SPF for HubSpot?
Yes—MailTester offers 100 free verifications to start. Use them to validate domain records and email addresses without cost.
How often should I update my DKIM key in HubSpot?
Only when HubSpot rotates the key (typically every few years). Monitor logs for failed verification events to detect issues early.
Can I use MailTester to test if all HubSpot domains are authenticated?
Yes—with bulk verification, you can test multiple domains at once, including primary and secondary domains used in campaigns.