Official DNS Guide • Customer Experience Automation & CRM

ActiveCampaign SPF Record Setup & Validator

Configure ActiveCampaign SPF records (include:emsd1.com) and CNAME DKIM keys for optimal inbox delivery.

Quick Answer • Exact ActiveCampaign SPF Syntax

To authorize ActiveCampaign to send emails on behalf of your domain, add include:emsd1.com to your domain's single DNS TXT SPF record before the terminating ~all mechanism. The standard record is v=spf1 include:emsd1.com ~all.

Live ActiveCampaign DNS Validator

Test your domain's published SPF, DKIM, and DMARC records via global DoH edge nodes in real time.

Zero-Log Client Evaluation

Understanding ActiveCampaign Email Authentication

ActiveCampaign requires custom domain authentication to satisfy Gmail and Yahoo 2024 deliverability standards.

When ActiveCampaign delivers outbound emails on your behalf, recipient mail transfer agents (MTAs) at Google, Yahoo, Microsoft, and corporate mail gateways inspect the sender identity. Without a published SPF record explicitly permitting ActiveCampaign's IP ranges, these emails trigger SPF Softfail (~all) or Hardfail (-all), severely degrading domain reputation and inbox placement.

Required DNS Records for ActiveCampaign

Publish the following DNS records in your domain registrar or DNS management console (Cloudflare, AWS Route 53, GoDaddy, Namecheap):

TypeHost / NameValue / TargetTTLPurpose
TXT@v=spf1 include:emsd1.com ~all3600ActiveCampaign SPF.

Step-by-Step Setup Instructions

1

In ActiveCampaign > Settings > Advanced > Manage Domains.

2

Click "Set up SPF/DKIM" and copy the DNS CNAME and TXT values.

3

Add "include:emsd1.com" to your SPF record.

4

Verify in ActiveCampaign.

Common ActiveCampaign SPF Configuration Mistakes

× DKIM Not Generated

Cause: Domain not saved in ActiveCampaign.

Fix: Save domain first, then copy keys.

Frequently Asked Questions

What is the SPF include for ActiveCampaign?

Use "include:emsd1.com" or "include:activecampaign.com".

What DKIM record does ActiveCampaign provide?

ActiveCampaign generates a CNAME DKIM record at dkim._domainkey.yourdomain.com. The CNAME points to ActiveCampaign's DKIM signing infrastructure. This CNAME-based approach allows ActiveCampaign to rotate keys without requiring DNS changes.

Do I need to authenticate my domain with ActiveCampaign for the 2024 Gmail requirements?

Yes. Gmail and Yahoo require all bulk senders (5,000+ emails/day) to have valid SPF, DKIM, and DMARC on their sending domain. ActiveCampaign's domain management settings allow you to configure all three. Without authentication, your campaigns risk being blocked or routed to spam.

Why does the ActiveCampaign DKIM not appear until the domain is saved?

ActiveCampaign generates DKIM keys on-demand when you add and save a domain in Settings > Advanced > Manage Domains. The DKIM key is provisioned server-side after the save action. If you navigate to DNS Records before saving, the key will not yet exist.

What happens to my ActiveCampaign emails if DMARC is set to p=reject without DKIM being verified?

If DMARC is enforced at p=reject and DKIM is not verified (or misconfigured), ActiveCampaign-sent emails will fail DMARC alignment and be rejected at the receiving server. Always verify SPF and DKIM pass in IncogSay before escalating your DMARC policy from p=none.

Can ActiveCampaign send from a subdomain?

Yes. ActiveCampaign supports custom sending domains including subdomains (e.g. campaigns.yourdomain.com). Using a subdomain isolates your campaign reputation from your corporate inbox domain, which is best practice for bulk email senders.