Skip to main content
EmailToolBox LogoEmailToolBox
HomeAll ToolsSuper Lookup
Email Health CheckEmail DeliverabilityEmail Blacklist CheckerEmail Header AnalyzerSPF CheckerDKIM CheckerDMARC CheckerMX Lookup
View All Tools
SPF CheckerDKIM CheckerDMARC CheckerSPF GeneratorDMARC GeneratorBIMI CheckerMTA-STS Checker
Guides
中文

Related Tools

MX Lookup
Check mail servers
Email Blacklist Checker
Check IP reputation
DNS Lookup
DNS record queries
SPF Checker
Validate SPF records
DMARC Checker
Check and analyze DMARC records
Email Header Analyzer
Analyze email headers
DKIM Checker
Verify DKIM signatures
WHOIS Lookup
Domain registration info
SMTP Test
Test SMTP connectivity
SSL Certificate Lookup
Check SSL certificates
DNS Propagation Checker
Check DNS propagation
Ping Test
Test network connectivity
Traceroute
Trace network path
Subnet Calculator
Calculate IP subnets
What Is My IP
Check your IP address

Need Help?

Our tools are designed to be intuitive, but if you need assistance, we're here to help.

DocumentationContact Support

About Our Tools

Professional-grade email and DNS diagnostic tools trusted by IT professionals worldwide.

Free to UseNo RegistrationReal-time Results
EmailToolBox LogoEmailToolBox

EmailToolBox is a free suite of email testing, deliverability and domain diagnostics tools. Check your email health, validate SPF/DKIM/DMARC, look up DNS records and monitor blacklist status in seconds - no signup required.

  • Free to use
  • No signup required
  • Instant results
  • Real-time DNS checks
  • Privacy-focused

Email Diagnostics

  • Email Health Check
  • Email Deliverability
  • Email Blacklist Checker
  • Email Header Analyzer
  • Email Verifier
  • HTML Email Validator
  • Email Preview Simulator
  • Spam Test
  • Email Health Report

Email Authentication

  • SPF Checker
  • DKIM Checker
  • DMARC Checker
  • DMARC Report Analyzer
  • SPF Generator
  • DMARC Generator
  • BIMI Checker
  • MTA-STS Checker

DNS & Infrastructure

  • MX Lookup
  • DNS Lookup
  • TXT Record Lookup
  • CNAME Record Lookup
  • NS Lookup
  • DNS Propagation
  • PTR/rDNS Record Lookup
  • SMTP Test
  • WHOIS Lookup

Resources

  • Email Guides
  • All Tools
  • FAQ
  • Contact Us
  • About
  • Privacy Policy
  • Terms of Service

Friend Links

  • Favicon Generator
  • Email Testing tools
  • Morse Code Translator
  • Password Remover
  • Regex Cheat Sheet
  • free barcode generator
  • Free Online PDF Tools
  • fast chart
  • refnet
  • world market hours

© 2026 EmailToolBox - Email Testing, Deliverability & Domain Diagnostics. All rights reserved.

    1. Home
    2. Guides
    3. Brevo (Sendinblue) SPF & DKIM Setup: Enterprise-Grade Guide
    Categories
    Related Guides

    How to set up SPF records

    Complete SPF record setup guide, including syntax explanation and best practices

    DANE SMTP Configuration Guide

    Configure DANE for SMTP with TLSA records to enforce secure delivery

    How to Configure MTA-STS in Cloudflare

    Set up MTA-STS policy with Cloudflare for secure SMTP delivery

    Brevo (Sendinblue) SPF & DKIM Setup: Enterprise-Grade Guide

    End-to-end SPF, DKIM, and DMARC configuration for Brevo (Sendinblue), with validation, alignment, rotation, and enterprise best practices to maximize deliverability.
    4 min read
    Updated 2025-10-24
    Tutorials
    brevosendinbluespfdkim

    Brevo (Sendinblue) SPF & DKIM Setup: Enterprise Guide

    This guide helps you configure SPF, DKIM, and DMARC alignment for Brevo (formerly Sendinblue), ensuring authenticated mail and strong deliverability across major inbox providers.

    Why It Matters

    • SPF authorizes Brevo’s sending infrastructure to send on your domain’s behalf.
    • DKIM cryptographically signs your mail, proving it wasn’t altered and enabling DMARC alignment.
    • DMARC uses SPF/DKIM results and alignment to enforce policy (monitor, quarantine, reject) against spoofing.

    Prerequisites

    • Access to your DNS provider (e.g., Cloudflare, Route 53, GoDaddy).
    • Admin access in Brevo to add and authenticate domains.
    • Clear sending domain strategy (root domain vs subdomain, e.g., mail.example.com).

    Step-by-Step: Configure in Brevo

    1. Add your domain in Brevo: In Brevo, go to Settings Senders & IP Domains (sometimes labeled as Authentication). Add the domain you will send from and choose to authenticate it.
    2. Publish SPF:
      • Create one TXT record at the root of the sending domain (e.g., example.com).
      • Use the include value provided in Brevo’s dashboard. Historically this has been include:spf.sendinblue.com; newer setups may use include:spf.brevo.com. Always follow the value Brevo shows for your account.
      • Example (adjust to your needs):
        Host: @
        Type: TXT
        Value: v=spf1 include:spf.brevo.com -all
      • If you still see include:spf.sendinblue.com, it’s acceptable; do not include both. Keep a single include.
      • Ensure there is only one SPF TXT record for the domain. Merge content if you have multiple ESPs.
    3. Publish DKIM:
      • Brevo provides one or more selectors and record types (TXT or CNAME) to publish.
      • Add the selector at <selector>._domainkey.example.com with the exact value Brevo provides.
      • Example (illustrative; use Brevo’s actual value):
        Host: mail._domainkey
        Type: TXT
        Value: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFA... (truncated)
      • If Brevo requires CNAME-based DKIM, create the CNAME hosts Brevo shows and point them to the targets it specifies.
      • Prefer 2048-bit keys when available; plan periodic key rotation.
    4. Verify ownership: After DNS propagation (TTL), click Verify in Brevo. You should see SPF and DKIM as Valid/Authenticated.
    5. Send test messages: Use a seed list (Gmail, Outlook, Yahoo). In Gmail, open “Show originalto confirm SPF=PASS, DKIM=PASS, and DMARC=PASS with alignment.

    DMARC Alignment and Policy

    • Publish a DMARC record at _dmarc.example.com. Start with monitoring:
    Host: _dmarc
    Type: TXT
    Value: v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com; ruf=mailto:dmarc-forensic@example.com; fo=1
    • Ensure alignment:
      • DKIM: the d= signing domain should match or be a subdomain of the visible From domain.
      • SPF: the envelope-from (Return-Path) domain should match or be aligned with the From domain if relying on SPF alignment.
    • Gradually enforce policy: move to p=quarantine, then p=reject once authentic traffic aligns and passes consistently.

    DNS Record Examples

    Examples below are illustrative; always prefer records shown in your Brevo dashboard.

    SPF:   v=spf1 include:spf.brevo.com -all
    Alt:   v=spf1 include:spf.sendinblue.com -all
    DKIM:  Host: mail._domainkey
           Type: TXT
           Value: v=DKIM1; k=rsa; p=MIIBIjAN... (truncated)

    Advanced Configuration

    • Subdomain strategy: Use a dedicated subdomain (e.g., mail.example.com) to isolate marketing traffic.
    • Multiple ESPs: Merge includes into a single SPF record; avoid duplicates. Consider SPF flattening if mechanisms exceed limits.
    • Key rotation: Rotate DKIM keys annually or after personnel/vendor changes; maintain at least two selectors for smooth cutovers.
    • BIMI readiness: Enforce DMARC at quarantine/reject, publish a compliant SVG logo, and consider a VMC to unlock wider adoption.

    Troubleshooting

    • SPF not passing: Check for duplicate TXT records, wrong include domain, or missing Brevo sending IP authorization.
    • DKIM pending: Confirm selector host is correct and not auto-suffixed by the DNS UI; wait for TTL, and ensure no extra quotes/whitespace in the TXT value.
    • DMARC not aligned: If the d= DKIM domain differs from From, enable DKIM alignment in Brevo by signing with your domain; for SPF, align the envelope-from or rely on DKIM alignment.
    • Propagation delays: Some DNS providers take up to several hours; re-verify later.

    Best Practices

    • Keep a single SPF record; merge mechanisms when adding services.
    • Prefer DKIM alignment as primary DMARC pass path; treat SPF as complementary.
    • Monitor DMARC aggregate reports; remediate sources failing alignment before tightening policy.
    • Document selectors, rotation windows, and change approvals in your runbook.

    Validation & Screenshots

    1. Gmail: Show original
      • Open a test email in Gmail click the three dots Show original.
      • Confirm headers show: SPF: PASS, DKIM: PASS, DMARC: PASS.

      Gmail Show original entry

      Gmail original headers example with PASS

    2. Outlook (Microsoft 365): Message Header Analyzer
      • Download the message (.eml) or copy headers visit Microsoft Message Header Analyzer.
      • Verify authentication results and DKIM domain alignment (d=) with From domain.

      Microsoft Header Analyzer input

    3. Platform tools
      • SPF Checker: evaluate SPF record and includes.
      • DKIM Checker: check selector record resolution.
      • DMARC Analyzer: review policy and alignment expectations.

    FAQ

    Can I use both include:spf.sendinblue.com and include:spf.brevo.com?

    No. Use only one include whichever Brevo shows in your dashboard. Having both can bloat SPF and risk evaluation errors.

    Do I need a dedicated subdomain for Brevo?

    Not required, but recommended for traffic isolation and reputation control. If used, authenticate the subdomain in Brevo and publish SPF/DKIM there.

    When should I move DMARC to reject?

    After 2 weeks of stable aggregate reports with aligned, authenticated traffic and no legitimate sources failing. Move from p=none p=quarantine p=reject.

    Does a dedicated IP improve deliverability?

    It can, if you maintain low complaint rates, consistent cadence, and proper warm-up. Authentication remains foundational.

    Was this guide helpful?

    Brevo (Sendinblue) SPF & DKIM Setup: Enterprise-Grade Guide - EmailToolBox