100% Client-Side EngineZero data storage • No email signup required • 2026 Google & Yahoo Bulk Sender Compliant
Transactional Email API 2026 Google & Yahoo Compliant

Twilio SendGrid SPF & DMARC Setup Guide

Twilio SendGrid powers critical transactional notifications, receipts, and marketing blasts. To prevent spoofing and comply with 2026 inbox rules, SendGrid requires domain authentication via dedicated CNAMEs or the direct sendgrid.net include.

Transactional Email APIRFC 7208 & RFC 7489 Validated

Twilio SendGrid DNS Preset Generator

Enter your domain below to customize the exact SPF and DMARC TXT records required for Twilio SendGrid.

RFC 7208 DNS Lookup Cost1 of 10 Lookups

1 direct relay include query. When setting up SendGrid automated domain authentication, SendGrid creates a dedicated subdomain (e.g. em1234.yourdomain.com) for SPF alignment.

Lookup Budget1/10
RECORD 1: SPFHost: @ (or apex domain)Type: TXT
v=spf1 include:sendgrid.net ~all

⚠️ Important: If your domain already publishes an existing SPF record, merge include:sendgrid.net into that record. Never publish two separate SPF records.

RECORD 2: DMARCHost: _dmarc (or _dmarc.example.com)Type: TXT
v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@example.com; pct=100; adkim=r; aspf=r

This policy enforces p=quarantine (suspicious emails routed to spam) and directs daily XML compliance reports to dmarc-reports@example.com.

Live DNS Propagation Check for example.com

Query Cloudflare DNS-over-HTTPS in real-time to check if your domain already publishes valid records.

Using Twilio SendGrid alongside other platforms?Open Multi-Provider SPF Merger & Lookup Calculator
Step-by-Step Instructions

How to configure Twilio SendGrid in your DNS

Follow these 4 straightforward steps to publish your authentication records on Cloudflare, GoDaddy, Namecheap, or AWS Route 53.

1

Choose Authentication Strategy

For custom transactional applications, complete SendGrid Automated Domain Authentication (3 CNAME records). If sending directly from apex domain, add the SPF include.

2

Add SendGrid Include

Add include:sendgrid.net into your root SPF record.

v=spf1 include:sendgrid.net ~all
3

Publish SendGrid DKIM CNAMEs

Add the two CNAME records (s1._domainkey and s2._domainkey) generated in your SendGrid Sender Authentication dashboard.

4

Enforce DMARC Policy

Publish a DMARC policy under _dmarc.yourdomain.com to protect your transactional brand identity.

v=DMARC1; p=reject; rua=mailto:dmarc-reports@yourdomain.com; pct=100
Technical Q&A

Frequently Asked Questions for Twilio SendGrid

Technical answers regarding lookup limits, multiple records, and delivery errors.

Should I use include:sendgrid.net or SendGrid CNAMEs?▼
SendGrid Automated Domain Authentication (3 CNAME records) is superior because SendGrid manages SPF and DKIM on a dedicated subdomain, avoiding the 10-lookup limit on your root domain.
Why did my SendGrid emails start going to spam in 2026?▼
Google and Yahoo require a published DMARC policy with matching SPF or DKIM alignment. If you send with a "From" address of your custom domain but SendGrid is not aligned, delivery will fail.
Does sendgrid.net count toward the 10-lookup limit?▼
Yes, include:sendgrid.net counts as 1 DNS lookup toward your RFC 7208 total.

Common Providers Used with Twilio SendGrid

Send marketing and transactional emails alongside your corporate inbox.

View All 50+ Guides
Full Email Deliverability Suite

Need to combine multiple providers into one SPF record?

Our full in-browser engine merges SPF records, calculates RFC 7208 lookups in real-time, and generates custom DMARC policies.