Understanding Postmark (ActiveCampaign) Email Authentication
Postmark uses a custom Return-Path CNAME (pm.bounces.yourdomain.com) for 100% DMARC SPF alignment.
When Postmark (ActiveCampaign) delivers outbound emails on your behalf, recipient mail transfer agents (MTAs) at Google, Yahoo, Microsoft, and corporate mail gateways inspect the sender identity. Without a published SPF record explicitly permitting Postmark (ActiveCampaign)'s IP ranges, these emails trigger SPF Softfail (~all) or Hardfail (-all), severely degrading domain reputation and inbox placement.
Required DNS Records for Postmark
Publish the following DNS records in your domain registrar or DNS management console (Cloudflare, AWS Route 53, GoDaddy, Namecheap):
| Type | Host / Name | Value / Target | TTL | Purpose |
|---|---|---|---|---|
| CNAME | pm-bounces | pm.mtasv.net | 3600 | Postmark Return-Path. |
Step-by-Step Setup Instructions
In Postmark > Sender Signatures > Domains > Add Domain.
Add DKIM TXT record at [selector]._domainkey.
Add CNAME for pm-bounces pointing to pm.mtasv.net.
Verify DNS in Postmark.
Common Postmark SPF Configuration Mistakes
× Missing Return-Path CNAME
Cause: Only adding DKIM.
Fix: Add the pm-bounces CNAME.
Frequently Asked Questions
What is Postmark's SPF include string?
Postmark uses "include:spf.mtasv.net".
What is the Postmark Return-Path CNAME and why is it essential?
Postmark requires a CNAME record at pm-bounces.yourdomain.com pointing to pm.mtasv.net. This sets a custom Return-Path header, ensuring SPF is checked against your domain (not Postmark's shared domain), which is required for DMARC SPF alignment.
What DKIM selector does Postmark use?
Postmark assigns a date-based DKIM selector (e.g. 20200301pm) for each verified sender domain. The DKIM TXT record is published at [selector]._domainkey.yourdomain.com. Postmark provides the exact selector and key value in the domain settings page.
Does Postmark guarantee 100% inbox placement?
Postmark focuses exclusively on transactional email (not marketing bulk mail) and maintains extremely low complaint rates. Their shared sending pools have high reputation scores, but inbox placement ultimately depends on your content quality, recipient engagement, and proper SPF/DKIM/DMARC setup.
Can I use a subdomain with Postmark for sending?
Yes, and it is recommended for teams that already have corporate email on the root domain. Set up Postmark on a subdomain (e.g. mail.yourdomain.com or app.yourdomain.com). This isolates transactional delivery reputation from corporate inbox reputation.
How do I check Postmark's SPF and DKIM are working?
Use IncogSay's SPF Checker to verify include:spf.mtasv.net resolves correctly. Use the DKIM Checker with your domain and Postmark's selector to confirm the TXT record is published and the key parses without errors.