Understanding SendGrid (Twilio) Email Authentication
SendGrid by Twilio uses Automated Security (CNAME-based SPF and DKIM) where a custom subdomain (e.g. em.yourdomain.com) handles Return-Path alignment.
When SendGrid (Twilio) delivers outbound emails on your behalf, recipient mail transfer agents (MTAs) at Google, Yahoo, Microsoft, and corporate mail gateways inspect the sender identity. Without a published SPF record explicitly permitting SendGrid (Twilio)'s IP ranges, these emails trigger SPF Softfail (~all) or Hardfail (-all), severely degrading domain reputation and inbox placement.
Required DNS Records for SendGrid
Publish the following DNS records in your domain registrar or DNS management console (Cloudflare, AWS Route 53, GoDaddy, Namecheap):
| Type | Host / Name | Value / Target | TTL | Purpose |
|---|---|---|---|---|
| TXT | @ | v=spf1 include:sendgrid.net ~all | 3600 | Direct API root SPF authorization. |
| CNAME | s1._domainkey | s1.domainkey.u123456.sendgrid.net | 3600 | Primary DKIM key. |
| CNAME | s2._domainkey | s2.domainkey.u123456.sendgrid.net | 3600 | Secondary DKIM key. |
Step-by-Step Setup Instructions
Log into SendGrid > Settings > Sender Authentication > Domain Authentication.
Enter your root domain. SendGrid generates 3 CNAME records.
Add the two DKIM CNAMEs (s1/s2._domainkey) and the Return-Path CNAME (em.domain.com).
Add "include:sendgrid.net" to your root SPF record.
Verify in SendGrid.
Common SendGrid SPF Configuration Mistakes
× DMARC Alignment Failure
Cause: Sending with From: user@domain.com while Return-Path is shared.
Fix: Complete CNAME Domain Authentication.
Frequently Asked Questions
What is the SPF include for SendGrid?
The SPF mechanism is "include:sendgrid.net".
What is SendGrid Automated Security and do I still need to add SPF manually?
SendGrid's Automated Security uses 3 CNAME records — two DKIM keys and one Return-Path/CNAME — to handle SPF and DKIM automatically. However, if you are sending from a root domain (not a subdomain) without Automated Security enabled, you must manually add include:sendgrid.net to your root SPF record.
Why does SendGrid require a custom Return-Path for DMARC alignment?
By default, SendGrid uses its own Return-Path domain (like em.yourdomain.com) which creates SPF alignment under sendgrid.net, not your own domain. DMARC requires the SPF-checked domain to align with your From: domain. The Return-Path CNAME creates alignment under your domain.
What are the two DKIM selectors SendGrid assigns?
SendGrid generates two CNAME DKIM records: s1._domainkey and s2._domainkey (the numbers vary by account, e.g. s1.domainkey.u12345.sendgrid.net). Both must be published for DKIM to pass verification.
Can I send from multiple domains with a single SendGrid account?
Yes. SendGrid allows multiple domain authentications under one account. Each domain gets its own CNAME set. You then specify which authenticated domain to use when creating a sender identity or API call.
How do I check if my SendGrid SPF and DKIM are correctly set up?
Run the SPF Checker with your root domain on IncogSay to verify include:sendgrid.net resolves. Then use the DKIM Checker with your domain and selector s1 to verify the CNAME chain resolves to a valid DKIM key.