Skip to main content
EmailToolBox LogoEmailToolBox
首页全部工具超级查询
邮件健康检查邮件投递测试邮件黑名单检测邮件头分析SPF 检测DKIM 检测DMARC 检测MX 查询
查看全部工具
SPF 检测DKIM 检测DMARC 检测SPF 生成器DMARC 生成器BIMI 检测MTA-STS 检测
指南
English

相关工具

MX 查询
检查邮件服务器
邮件黑名单检测
检查 IP 信誉
DNS 查询
DNS 记录查询
SPF 检测
验证 SPF 记录
DMARC 检测
查询并分析 DMARC 记录
邮件头分析
分析邮件头
DKIM 检测
验证 DKIM 签名
WHOIS 查询
域名注册信息
SMTP 测试
测试 SMTP 连通性
CERT 查询
检查 SSL 证书
DNS 传播
检查 DNS 传播
Ping 测试
测试网络连通性
Traceroute 路由追踪
追踪网络路径
子网计算器
计算 IP 子网
我的 IP 查询
查询您的 IP 地址

需要帮助?

我们的工具设计直观、易于使用,但如果您需要帮助,我们随时为您服务。

使用文档联系客服

关于我们的工具

专业级邮件与 DNS 诊断工具,深受全球 IT 专业人士信赖。

免费使用无需注册实时结果
EmailToolBox LogoEmailToolBox

EmailToolBox 是一套免费的企业邮箱测试、邮件投递与域名诊断工具。一键检查邮箱健康状态,验证 SPF/DKIM/DMARC,查询 DNS 记录并监测黑名单状态,无需注册,数秒出结果。

  • 免费使用
  • 无需注册
  • 即时结果
  • 实时 DNS 查询
  • 注重隐私

邮件诊断

  • 邮件健康检查
  • 邮件投递测试
  • 邮件黑名单检测
  • 邮件头分析
  • 邮箱验证
  • HTML 邮件验证
  • 邮件预览模拟器
  • 垃圾邮件测试
  • 邮件健康报告

邮件认证

  • SPF 检测
  • DKIM 检测
  • DMARC 检测
  • DMARC 报告分析
  • SPF 生成器
  • DMARC 生成器
  • BIMI 检测
  • MTA-STS 检测

DNS 与基础设施

  • MX 查询
  • DNS 查询
  • TXT 记录查询
  • CNAME 记录查询
  • NS 查询
  • DNS 传播
  • PTR/rDNS 记录查询
  • SMTP 测试
  • WHOIS 查询

资源

  • 邮件指南
  • 全部工具
  • 常见问题
  • 联系我们
  • 关于
  • 隐私政策
  • 服务条款

友情链接

  • Favicon Generator
  • Email Testing tools
  • Morse Code Translator
  • Password Remover
  • Regex Cheat Sheet
  • free barcode generator
  • Free Online PDF Tools
  • fast chart
  • refnet
  • world market hours

© 2026 EmailToolBox - 企业邮箱、邮件投递与域名诊断工具。保留所有权利。

    1. 首页
    2. 指南
    3. Brevo (Sendinblue) SPF & DKIM Setup: Enterprise-Grade Guide
    Categories
    Related Guides

    How to set up SPF records

    Complete SPF record setup guide, including syntax explanation and best practices

    DANE SMTP Configuration Guide

    Configure DANE for SMTP with TLSA records to enforce secure delivery

    How to Configure MTA-STS in Cloudflare

    Set up MTA-STS policy with Cloudflare for secure SMTP delivery

    Brevo (Sendinblue) SPF & DKIM Setup: Enterprise-Grade Guide

    End-to-end SPF, DKIM, and DMARC configuration for Brevo (Sendinblue), with validation, alignment, rotation, and enterprise best practices to maximize deliverability.
    4 min read
    Updated 2025-10-24
    Tutorials
    brevosendinbluespfdkim

    Brevo (Sendinblue) SPF & DKIM Setup: Enterprise Guide

    This guide helps you configure SPF, DKIM, and DMARC alignment for Brevo (formerly Sendinblue), ensuring authenticated mail and strong deliverability across major inbox providers.

    Why It Matters

    • SPF authorizes Brevo’s sending infrastructure to send on your domain’s behalf.
    • DKIM cryptographically signs your mail, proving it wasn’t altered and enabling DMARC alignment.
    • DMARC uses SPF/DKIM results and alignment to enforce policy (monitor, quarantine, reject) against spoofing.

    Prerequisites

    • Access to your DNS provider (e.g., Cloudflare, Route 53, GoDaddy).
    • Admin access in Brevo to add and authenticate domains.
    • Clear sending domain strategy (root domain vs subdomain, e.g., mail.example.com).

    Step-by-Step: Configure in Brevo

    1. Add your domain in Brevo: In Brevo, go to Settings Senders & IP Domains (sometimes labeled as Authentication). Add the domain you will send from and choose to authenticate it.
    2. Publish SPF:
      • Create one TXT record at the root of the sending domain (e.g., example.com).
      • Use the include value provided in Brevo’s dashboard. Historically this has been include:spf.sendinblue.com; newer setups may use include:spf.brevo.com. Always follow the value Brevo shows for your account.
      • Example (adjust to your needs):
        Host: @
        Type: TXT
        Value: v=spf1 include:spf.brevo.com -all
      • If you still see include:spf.sendinblue.com, it’s acceptable; do not include both. Keep a single include.
      • Ensure there is only one SPF TXT record for the domain. Merge content if you have multiple ESPs.
    3. Publish DKIM:
      • Brevo provides one or more selectors and record types (TXT or CNAME) to publish.
      • Add the selector at <selector>._domainkey.example.com with the exact value Brevo provides.
      • Example (illustrative; use Brevo’s actual value):
        Host: mail._domainkey
        Type: TXT
        Value: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFA... (truncated)
      • If Brevo requires CNAME-based DKIM, create the CNAME hosts Brevo shows and point them to the targets it specifies.
      • Prefer 2048-bit keys when available; plan periodic key rotation.
    4. Verify ownership: After DNS propagation (TTL), click Verify in Brevo. You should see SPF and DKIM as Valid/Authenticated.
    5. Send test messages: Use a seed list (Gmail, Outlook, Yahoo). In Gmail, open “Show originalto confirm SPF=PASS, DKIM=PASS, and DMARC=PASS with alignment.

    DMARC Alignment and Policy

    • Publish a DMARC record at _dmarc.example.com. Start with monitoring:
    Host: _dmarc
    Type: TXT
    Value: v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com; ruf=mailto:dmarc-forensic@example.com; fo=1
    • Ensure alignment:
      • DKIM: the d= signing domain should match or be a subdomain of the visible From domain.
      • SPF: the envelope-from (Return-Path) domain should match or be aligned with the From domain if relying on SPF alignment.
    • Gradually enforce policy: move to p=quarantine, then p=reject once authentic traffic aligns and passes consistently.

    DNS Record Examples

    Examples below are illustrative; always prefer records shown in your Brevo dashboard.

    SPF:   v=spf1 include:spf.brevo.com -all
    Alt:   v=spf1 include:spf.sendinblue.com -all
    DKIM:  Host: mail._domainkey
           Type: TXT
           Value: v=DKIM1; k=rsa; p=MIIBIjAN... (truncated)

    Advanced Configuration

    • Subdomain strategy: Use a dedicated subdomain (e.g., mail.example.com) to isolate marketing traffic.
    • Multiple ESPs: Merge includes into a single SPF record; avoid duplicates. Consider SPF flattening if mechanisms exceed limits.
    • Key rotation: Rotate DKIM keys annually or after personnel/vendor changes; maintain at least two selectors for smooth cutovers.
    • BIMI readiness: Enforce DMARC at quarantine/reject, publish a compliant SVG logo, and consider a VMC to unlock wider adoption.

    Troubleshooting

    • SPF not passing: Check for duplicate TXT records, wrong include domain, or missing Brevo sending IP authorization.
    • DKIM pending: Confirm selector host is correct and not auto-suffixed by the DNS UI; wait for TTL, and ensure no extra quotes/whitespace in the TXT value.
    • DMARC not aligned: If the d= DKIM domain differs from From, enable DKIM alignment in Brevo by signing with your domain; for SPF, align the envelope-from or rely on DKIM alignment.
    • Propagation delays: Some DNS providers take up to several hours; re-verify later.

    Best Practices

    • Keep a single SPF record; merge mechanisms when adding services.
    • Prefer DKIM alignment as primary DMARC pass path; treat SPF as complementary.
    • Monitor DMARC aggregate reports; remediate sources failing alignment before tightening policy.
    • Document selectors, rotation windows, and change approvals in your runbook.

    Validation & Screenshots

    1. Gmail: Show original
      • Open a test email in Gmail click the three dots Show original.
      • Confirm headers show: SPF: PASS, DKIM: PASS, DMARC: PASS.

      Gmail Show original entry

      Gmail original headers example with PASS

    2. Outlook (Microsoft 365): Message Header Analyzer
      • Download the message (.eml) or copy headers visit Microsoft Message Header Analyzer.
      • Verify authentication results and DKIM domain alignment (d=) with From domain.

      Microsoft Header Analyzer input

    3. Platform tools
      • SPF Checker: evaluate SPF record and includes.
      • DKIM Checker: check selector record resolution.
      • DMARC Analyzer: review policy and alignment expectations.

    FAQ

    Can I use both include:spf.sendinblue.com and include:spf.brevo.com?

    No. Use only one include whichever Brevo shows in your dashboard. Having both can bloat SPF and risk evaluation errors.

    Do I need a dedicated subdomain for Brevo?

    Not required, but recommended for traffic isolation and reputation control. If used, authenticate the subdomain in Brevo and publish SPF/DKIM there.

    When should I move DMARC to reject?

    After 2 weeks of stable aggregate reports with aligned, authenticated traffic and no legitimate sources failing. Move from p=none p=quarantine p=reject.

    Does a dedicated IP improve deliverability?

    It can, if you maintain low complaint rates, consistent cadence, and proper warm-up. Authentication remains foundational.

    Was this guide helpful?

    Brevo (Sendinblue) SPF & DKIM Setup: Enterprise-Grade Guide - EmailToolBox