Understanding Mailchimp (Intuit) Email Authentication
Mailchimp requires custom domain authentication for all senders with custom domains to ensure DMARC alignment.
When Mailchimp (Intuit) delivers outbound emails on your behalf, recipient mail transfer agents (MTAs) at Google, Yahoo, Microsoft, and corporate mail gateways inspect the sender identity. Without a published SPF record explicitly permitting Mailchimp (Intuit)'s IP ranges, these emails trigger SPF Softfail (~all) or Hardfail (-all), severely degrading domain reputation and inbox placement.
Required DNS Records for Mailchimp
Publish the following DNS records in your domain registrar or DNS management console (Cloudflare, AWS Route 53, GoDaddy, Namecheap):
| Type | Host / Name | Value / Target | TTL | Purpose |
|---|---|---|---|---|
| TXT | @ | v=spf1 include:servers.mcsv.net ~all | 3600 | Authorizes Mailchimp servers. |
| CNAME | k2._domainkey | dkim2.mcsv.net | 3600 | Mailchimp DKIM key 1. |
Step-by-Step Setup Instructions
Open Mailchimp > Domains > Start Authentication.
Copy the two CNAME DKIM records (k2._domainkey and k3._domainkey).
Add both CNAME records into your DNS zone.
Add "include:servers.mcsv.net" to your root SPF TXT record.
Click Authenticate in Mailchimp.
Common Mailchimp SPF Configuration Mistakes
× Duplicated Domain in Host
Cause: Entering k2._domainkey.domain.com in DNS.
Fix: Enter only k2._domainkey.
Frequently Asked Questions
What is the SPF include for Mailchimp?
The SPF mechanism is "include:servers.mcsv.net".
Why does Mailchimp use ?all (neutral) instead of ~all or -all?
Mailchimp's default SPF example uses ?all (neutral qualifier), which means unlisted senders are neither approved nor rejected. This is unusual — most providers recommend ~all (softfail) as a minimum. Once DMARC p=reject is published, the ~all vs ?all distinction becomes less critical, as DMARC enforcement takes precedence.
What DKIM records does Mailchimp require?
Mailchimp requires two CNAME DKIM records: k2._domainkey and k3._domainkey, pointing to dkim2.mcsv.net and dkim3.mcsv.net respectively. Both must be in DNS for domain authentication to show as Verified in Mailchimp.
Do I need to authenticate my domain to use Mailchimp in 2024?
Yes. Google and Yahoo's February 2024 bulk sender requirements mandate that senders of over 5,000 emails/day authenticate with DKIM, publish SPF, and have a DMARC record. Mailchimp accounts using unauthenticated free webmail (like @gmail.com) as the From address are blocked from bulk sending.
What happens if I create two SPF TXT records accidentally?
RFC 7208 Section 3.2 states that when multiple SPF TXT records exist on a domain, the result is a permanent error (PermError). Receiving servers cannot determine the correct SPF policy and will reject authentication entirely. Always merge all include mechanisms into a single TXT record.
Why does the DNS host field for Mailchimp DKIM show k2._domainkey.yourdomain.com but I should enter k2._domainkey?
Most DNS management portals automatically append your domain to relative hostnames. If you enter the full k2._domainkey.yourdomain.com, you'll create a double-domain error (k2._domainkey.yourdomain.com.yourdomain.com). Enter only k2._domainkey in the host/name field.