Related Tools
Need Help?
Our tools are designed to be intuitive, but if you need assistance, we're here to help.
About Our Tools
Professional-grade email and DNS diagnostic tools trusted by IT professionals worldwide.
Our tools are designed to be intuitive, but if you need assistance, we're here to help.
Professional-grade email and DNS diagnostic tools trusted by IT professionals worldwide.
Complete SPF record setup guide, including syntax explanation and best practices
Configure DANE for SMTP with TLSA records to enforce secure delivery
Set up MTA-STS policy with Cloudflare for secure SMTP delivery
This guide helps you configure SPF, DKIM, and DMARC alignment for Brevo (formerly Sendinblue), ensuring authenticated mail and strong deliverability across major inbox providers.
mail.example.com).example.com).include:spf.sendinblue.com; newer setups may use include:spf.brevo.com. Always follow the value Brevo shows for your account.Host: @
Type: TXT
Value: v=spf1 include:spf.brevo.com -all
include:spf.sendinblue.com, it’s acceptable; do not include both. Keep a single include.<selector>._domainkey.example.com with the exact value Brevo provides.Host: mail._domainkey
Type: TXT
Value: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFA... (truncated)
_dmarc.example.com. Start with monitoring:Host: _dmarc
Type: TXT
Value: v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com; ruf=mailto:dmarc-forensic@example.com; fo=1
d= signing domain should match or be a subdomain of the visible From domain.p=quarantine, then p=reject once authentic traffic aligns and passes consistently.Examples below are illustrative; always prefer records shown in your Brevo dashboard.
SPF: v=spf1 include:spf.brevo.com -all
Alt: v=spf1 include:spf.sendinblue.com -all
DKIM: Host: mail._domainkey
Type: TXT
Value: v=DKIM1; k=rsa; p=MIIBIjAN... (truncated)
mail.example.com) to isolate marketing traffic.d= DKIM domain differs from From, enable DKIM alignment in Brevo by signing with your domain; for SPF, align the envelope-from or rely on DKIM alignment.

No. Use only one include whichever Brevo shows in your dashboard. Having both can bloat SPF and risk evaluation errors.
Not required, but recommended for traffic isolation and reputation control. If used, authenticate the subdomain in Brevo and publish SPF/DKIM there.
After 2 weeks of stable aggregate reports with aligned, authenticated traffic and no legitimate sources failing. Move from p=none p=quarantine p=reject.
It can, if you maintain low complaint rates, consistent cadence, and proper warm-up. Authentication remains foundational.