Understanding Campaign Monitor (Marigold) Email Authentication
Campaign Monitor (by Marigold) requires sending domain authentication to satisfy RFC 7208 and RFC 6376 protocols, removing third-party sender headers.
When Campaign Monitor (Marigold) delivers outbound emails on your behalf, recipient mail transfer agents (MTAs) at Google, Yahoo, Microsoft, and corporate mail gateways inspect the sender identity. Without a published SPF record explicitly permitting Campaign Monitor (Marigold)'s IP ranges, these emails trigger SPF Softfail (~all) or Hardfail (-all), severely degrading domain reputation and inbox placement.
Required DNS Records for Campaign Monitor
Publish the following DNS records in your domain registrar or DNS management console (Cloudflare, AWS Route 53, GoDaddy, Namecheap):
| Type | Host / Name | Value / Target | TTL | Purpose |
|---|---|---|---|---|
| TXT | @ | v=spf1 include:sendmsg.cmail1.com ~all | 3600 | Campaign Monitor sending cluster. |
Step-by-Step Setup Instructions
In Campaign Monitor > Account Settings > Sending Domains > Add Domain.
Copy the DKIM TXT record generated for your domain.
Add "include:sendmsg.cmail1.com" to your existing SPF record.
Verify status in Campaign Monitor.
Common Campaign Monitor SPF Configuration Mistakes
× Deprecated include:cmail1.com used
Cause: Old documentation references.
Fix: Update to "include:sendmsg.cmail1.com".
Frequently Asked Questions
What is the official Campaign Monitor SPF include?
The current mechanism is "include:sendmsg.cmail1.com".
Why did Campaign Monitor's SPF include change from cmail1.com to sendmsg.cmail1.com?
Campaign Monitor updated its sending infrastructure and the SPF sub-record moved from include:cmail1.com to include:sendmsg.cmail1.com. Using the old include causes SPF SoftFail or PermError depending on how the old sub-record resolves. Always reference the current documentation or IncogSay's SPF Checker to confirm the live SPF record structure.
What DKIM record does Campaign Monitor provide?
Campaign Monitor generates a TXT DKIM record with the selector "cm", published at cm._domainkey.yourdomain.com. The key is a 2048-bit RSA public key retrieved from Campaign Monitor > Account Settings > Sending Domains.
What is the Marigold rebrand and does it affect Campaign Monitor authentication?
Campaign Monitor was rebranded under the Marigold group in 2023. The sending infrastructure, SPF include strings, and DKIM selector names remain unchanged under the Campaign Monitor product brand. Authentication records do not need to be updated due to the rebrand.
Can I send Campaign Monitor emails from a subdomain?
Yes. Campaign Monitor allows you to configure sending domains including subdomains. Use a dedicated sending subdomain (e.g. campaigns.yourdomain.com) to isolate marketing sender reputation from corporate inbox deliverability.
Does Campaign Monitor support DMARC alignment?
Yes. Once include:sendmsg.cmail1.com is in your SPF record and cm._domainkey DKIM is published and verified, Campaign Monitor emails align under your domain for both SPF and DKIM, satisfying DMARC p=reject enforcement.