100% Client-Side EngineZero data storage • No email signup required • 2026 Google & Yahoo Bulk Sender Compliant
Marketing & Sales CRM 2026 Google & Yahoo Compliant

HubSpot SPF & DMARC Setup Guide

HubSpot powers inbound sales and marketing emails. HubSpot automatically provisions custom CNAME records for DKIM and Return-Path, but accounts sending directly from root domains require the portal-specific SPF include.

Marketing & Sales CRMRFC 7208 & RFC 7489 Validated

HubSpot DNS Preset Generator

Enter your domain below to customize the exact SPF and DMARC TXT records required for HubSpot.

RFC 7208 DNS Lookup Cost2 of 10 Lookups

1 dedicated portal host + 1 fallback relay query (2 lookups total). HubSpot incorporates your unique Portal ID into its SPF include hostname and incurs 2 DNS lookups behind the scenes.

Lookup Budget2/10
RECORD 1: SPFHost: @ (or apex domain)Type: TXT
v=spf1 include:1234567.spf01.hubspotemail.net ~all

⚠️ Important: If your domain already publishes an existing SPF record, merge include:1234567.spf01.hubspotemail.net into that record. Never publish two separate SPF records.

RECORD 2: DMARCHost: _dmarc (or _dmarc.example.com)Type: TXT
v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@example.com; pct=100; adkim=r; aspf=r

This policy enforces p=quarantine (suspicious emails routed to spam) and directs daily XML compliance reports to dmarc-reports@example.com.

Live DNS Propagation Check for example.com

Query Cloudflare DNS-over-HTTPS in real-time to check if your domain already publishes valid records.

Using HubSpot alongside other platforms?Open Multi-Provider SPF Merger & Lookup Calculator
Step-by-Step Instructions

How to configure HubSpot in your DNS

Follow these 4 straightforward steps to publish your authentication records on Cloudflare, GoDaddy, Namecheap, or AWS Route 53.

1

Connect Sending Domain in HubSpot

In Settings > Website > Domains & URLs, click Connect a domain and choose Email Sending.

2

Add HubSpot DKIM CNAME Records

Publish the two 2048-bit CNAME records (hs1._domainkey and hs2._domainkey) generated for your domain.

3

Add Portal-Specific SPF Include

Add include:[YOUR_PORTAL_ID].spf01.hubspotemail.net into your root SPF record.

v=spf1 include:[YOUR_PORTAL_ID].spf01.hubspotemail.net ~all
4

Enforce DMARC Policy

Add your DMARC record to protect your brand identity across marketing and sales sequences.

v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@yourdomain.com; pct=100
Technical Q&A

Frequently Asked Questions for HubSpot

Technical answers regarding lookup limits, multiple records, and delivery errors.

Why does HubSpot use a portal-specific SPF include?▼
HubSpot generates a dedicated include containing your portal ID (e.g. 1234567.spf01.hubspotemail.net) to route and isolate email authentication to your specific IP cluster.
Can I connect HubSpot with Google Workspace on the same domain?▼
Yes! Merge both into a single SPF record: v=spf1 include:_spf.google.com include:[PORTAL_ID].spf01.hubspotemail.net ~all. This combination consumes 6 of your 10 allowed lookups.

Common Providers Used with HubSpot

Send marketing and transactional emails alongside your corporate inbox.

View All 50+ Guides
Full Email Deliverability Suite

Need to combine multiple providers into one SPF record?

Our full in-browser engine merges SPF records, calculates RFC 7208 lookups in real-time, and generates custom DMARC policies.