In Mailchimp, open Account & billing, go to the Domains tab, verify your domain and click Start authentication. You then add two DKIM records (k2._domainkey pointing to dkim2.mcsv.net and k3._domainkey pointing to dkim3.mcsv.net) and a DMARC record at your DNS provider, and Mailchimp checks them for you.
Why authentication matters
Until you authenticate, Mailchimp signs your campaigns with its own domain. Gmail and Yahoo can see the email came through Mailchimp, but they can't confirm it came from yourbusiness.com. That gap is a common reason campaigns land in the Spam folder.
Authentication fixes this with DKIM. DKIM is a digital signature that proves an email came from your domain and wasn't changed on the way. Once your records are live, Mailchimp signs with yourbusiness.com, and that signature matches your From address. That match is called alignment, and it is what DMARC checks. Gmail and Yahoo require it from bulk senders.
You can only authenticate a domain you own. Free addresses such as @gmail.com or @yahoo.com can't be authenticated, so send from an address like hello@yourbusiness.com.
Before you start
You need:
- Your Mailchimp login, with access to Account & billing.
- A login for your DNS provider. DNS is the public address book for your domain. It usually lives where you bought the domain, with your website host, or with Cloudflare.
- Access to an inbox at your domain, for the verification email.
Step 1: Verify your domain
Mailchimp first checks that you can receive email at the domain.
- Click your profile icon and choose Account & billing.
- Click the Domains tab.
- In the Email Domains section, click Add & Verify Domain.
- Enter an address at your domain, such as hello@yourbusiness.com, and click Send Verification Email.
- Click Verify Domain Access in the email, or type the code into the pop-up in Mailchimp and click Verify.
The link and code expire after seven days. Verifying doesn't change how your email is delivered. It unlocks the next step.
Step 2: Start authentication
On the Domains tab, click Start authentication for yourbusiness.com. Mailchimp offers two routes.
Automatic. Mailchimp uses a service called Entri to sign in to your DNS provider and add the records for you. Click Continue, then Log in, and sign in to your DNS provider. When it works, you see a message that the records have been created. Skip to Step 5.
Manual. Choose to set the records up yourself and click Next. Keep the Mailchimp tab open and sign in to your DNS provider in another tab.
Step 3: Add the two DKIM records
Add these two CNAME records. A CNAME record points one name at another, so Mailchimp can manage the signing key for you.
| Type | Name (Host) | Value (Points to) |
|---|---|---|
| CNAME | k2._domainkey.yourbusiness.com | dkim2.mcsv.net |
| CNAME | k3._domainkey.yourbusiness.com | dkim3.mcsv.net |
Many DNS providers add your domain to the end of the name for you. If you type the full name and end up with k2._domainkey.yourbusiness.com.yourbusiness.com, edit the record so the name is just k2._domainkey, and do the same for k3._domainkey.
If your DNS is on Cloudflare, set both records to "DNS only", not proxied. A proxied record hides the value that Gmail and Yahoo need to read.
Go back to Mailchimp and click Next.
Step 4: Add a DMARC record
Mailchimp also asks for a DMARC record. DMARC tells receiving mailboxes what to do with email that claims to be from your domain but fails these checks, and sends you reports about it.
If you don't have one yet, add this record. It starts in monitoring mode (p=none), so nothing changes for your email yet:
| Type | Name (Host) | Value |
|---|---|---|
| TXT | _dmarc.yourbusiness.com | v=DMARC1; p=none; rua=mailto:dmarc-reports@yourbusiness.com |
Change the rua address to a mailbox you read. Once reports show all your genuine email passing, move to p=quarantine.
If you already have a DMARC record, keep it and don't add a second one. A domain must have exactly one, and two records cancel each other out. Click Next.
Step 5: Wait for Mailchimp to check the records
Mailchimp validates the records. Most DNS changes show up within a few minutes, but they can take up to 48 hours. When it's done, the Domains tab shows your domain as authenticated.
How to check it worked
Mailchimp's status tells you the records exist. It doesn't show how Gmail, Yahoo or Outlook treat a real campaign. For that, send a real email from Mailchimp and check:
- DKIM passes for yourbusiness.com, not for mcsv.net.
- DMARC passes, aligned through DKIM.
The free test does this in one step. Send a test campaign from Mailchimp to your private test address and you get a verdict for Gmail, Google Workspace, Outlook.com, Microsoft 365 and Yahoo, with the exact record to fix if something is missing.
Common problems
- Records still not found after a day. Check for the doubled name, a typo, an extra space at the end of the value, or a proxied record on Cloudflare.
- Two DMARC records. Delete one. If they had different settings, merge them into a single record.
- Your From address uses another domain. Authentication only covers the domain you set up. If a campaign or audience sends from @anotherdomain.com, authenticate that domain too, or change the From address.
- SPF. Mailchimp's current steps don't ask you to change your SPF record. Mailchimp handles bounces through its own domain, and your alignment comes from the DKIM signature.
If authentication passes and campaigns still reach the Spam folder, the cause is more likely complaints or list quality. Gmail and Yahoo both expect a spam complaint rate below 0.3%.
Checked against: Mailchimp, Set up email domain authentication · Mailchimp, Verify an email domain · Mailchimp, About email domain authentication · Google Workspace Admin Help, Email sender guidelines.