How do I authenticate my domain in Zoho Campaigns?

Updated 9 October 2026 · 6 min read

Verified

In Zoho Campaigns, verify a sender address at your domain, then go to Settings → Domain Authentication, click Setup next to your domain, and copy the SPF and DKIM TXT records it shows into your DNS. When the records are live, click Verify Domain, then add a DMARC record so your campaigns meet Gmail and Yahoo's bulk sender rules.

Why authentication matters

Until your domain is authenticated, Gmail and Yahoo can see your campaign came through Zoho, but they can't confirm it came from yourbusiness.com. Zoho's own help notes that Gmail shows "via" next to the sender name for unauthenticated domains, and mailbox providers treat those emails as suspicious.

Authentication fixes this with two records:

  • SPF is a DNS record listing the servers allowed to send email for your domain. Zoho's record adds its Campaigns servers to that list.
  • DKIM is a digital signature on every email, checked against a key in your DNS. Once it's set up, Zoho signs your campaigns with yourbusiness.com.

That DKIM signature matches the domain in your From address. The match is called alignment, and it's what DMARC checks. Gmail and Yahoo require it from bulk senders.

Zoho Campaigns also says that if your domain already publishes a DMARC record, you must authenticate the domain before you can send.

Before you start

You need:

  • Your Zoho Campaigns login, with access to Settings.
  • A login for your DNS provider. DNS is the public address book for your domain. It usually lives where you bought the domain, with your website host, or with Cloudflare.
  • An inbox at your domain, for the verification email.

Step 1: Add and verify a sender address

Zoho Campaigns only sends from verified addresses, and it doesn't allow free addresses such as @gmail.com or @yahoo.com.

  1. From the navigation toolbar, choose Settings.
  2. Under Deliverability, click Manage Senders.
  3. Click Add Sender in the top-right corner.
  4. Enter an address at your domain, such as hello@yourbusiness.com, and click Send Verification Email.
  5. Open the email from Zoho Campaigns and click Verify your email address.

Once the address is verified, your domain appears on the Domain Authentication page.

Step 2: Copy the SPF and DKIM records

  1. Go to Settings → Domain Authentication. It's under Deliverability.
  2. Click Setup at the far right of your domain's row.
  3. Zoho shows two TXT records. Click Copy next to each one.

Zoho Campaigns has more than one version of its interface, so the menus can look slightly different. If you can't see this path, look for "Domain Authentication" in Settings.

Step 3: Add the SPF record

Add Zoho's include to the SPF record for yourbusiness.com. If you don't have an SPF record yet, add a TXT record like this, using the exact record Zoho shows:

TypeName (Host)Value
TXT@v=spf1 include:zcsend.net ~all

A domain can only have one SPF record. If you already have one, don't add a second. Edit it and add include:zcsend.net next to the other services. For example, if you also use Google Workspace:

v=spf1 include:_spf.google.com include:zcsend.net ~all

include:zcsend.net is the value for accounts in Zoho's US data center. Zoho's help lists a different value for each of its other data centers:

Zoho data centerSPF include
USinclude:zcsend.net
Europeinclude:eu.zcsend.net
Australiainclude:au.zcsend.net
Indiainclude:zcsend.in
Japaninclude:sender.zcsend.jp
Canadainclude:zcsend.ca
Saudi Arabiainclude:zcsend.sa
Chinainclude:zcsend.net.cn

Use the value Zoho Campaigns shows you in Step 2.

Step 4: Add the DKIM record

TypeName (Host)Value
TXT72247._domainkeythe full DKIM value Zoho shows

The number at the start is your selector, a name for this key. Zoho generates it, so yours will differ from 72247. Copy it exactly.

Many DNS providers add your domain to the end of the name for you. If you type the full name and end up with 72247._domainkey.yourbusiness.com.yourbusiness.com, edit the record so the name is just the selector and ._domainkey.

Paste the whole DKIM value with no line breaks or missing characters. A cut-off key makes DKIM fail.

Step 5: Verify your domain

  1. Go back to Settings → Domain Authentication.
  2. Click Setup next to your domain.
  3. Click Verify Domain.

Zoho says DNS changes usually update within 24 to 48 hours. If the records can't be found yet, Zoho shows the reasons. Fix anything it lists, wait a little, and try again.

Step 6: Add a DMARC record

DMARC tells receiving mailboxes what to do with email that claims to be from your domain but fails SPF and DKIM, and sends you reports about it. Gmail and Yahoo require a DMARC record from bulk senders, and p=none is enough.

If you don't have one yet, add this record:

TypeName (Host)Value
TXT_dmarcv=DMARC1; p=none; rua=mailto:dmarc-reports@yourbusiness.com

Change the rua address to a mailbox you read. p=none starts in monitoring mode, so nothing changes for your email yet. Once reports show all your genuine email passing, move to p=quarantine.

If you already have a DMARC record, keep it and don't add a second one. A domain must have exactly one.

Optional: Set up a custom return path

By default, bounces from your campaigns go to a Zoho address. SPF then passes for Zoho's domain, not for yourbusiness.com, so only DKIM lines up for DMARC. A custom return path puts the bounce address on your own domain, so SPF lines up too.

Set it up after SPF and DKIM are verified:

  1. Go to Settings and choose Custom Return Path under Deliverability.
  2. Click Setup for your domain.
  3. Enter a host name such as bounce.yourbusiness.com in the Host Name to Add field.
  4. Copy the CNAME record Zoho shows and add it at your DNS provider. A CNAME record points one name at another.
  5. Click Verify Domain.

How Zoho Campaigns fits Gmail and Yahoo's bulk sender rules

If you send close to 5,000 or more emails a day to Gmail addresses, Gmail treats you as a bulk sender. Yahoo doesn't give a number. Bulk senders need SPF and DKIM, a DMARC record that passes with alignment, one-click unsubscribe, and a spam complaint rate below 0.3%.

Zoho Campaigns says it already adds a one-click unsubscribe header to every email. The authentication part is up to you, and that's what the steps above cover.

How to check it worked

The Domain Authentication page tells you the records exist. It doesn't show how Gmail, Yahoo or Outlook treat a real campaign. For that, send a real email from Zoho Campaigns and check:

  • DKIM passes for yourbusiness.com, not for a Zoho domain.
  • DMARC passes, aligned through DKIM, and through SPF too if you set up a custom return path.

The free test does this in one step. Send a test campaign from Zoho Campaigns to your private test address and you get a verdict for Gmail, Google Workspace, Outlook.com, Microsoft 365 and Yahoo, with the exact record to fix if something is missing.

If authentication passes and campaigns still reach the Spam folder, the cause is more likely complaints or list quality.

Checked against: Zoho Campaigns Help, How to authenticate your domain · Zoho Campaigns Help, How to setup SPF and DKIM TXT records for your domain · Zoho Campaigns Help, How to add sender address · Zoho Campaigns Help, How to create a custom return-path address · Zoho Campaigns Help, Configuring an email campaign · Zoho Campaigns, Google and Yahoo's latest email authentication requirements · Google Workspace Admin Help, Email sender guidelines.

Questions people ask

What SPF value does Zoho Campaigns use?

For accounts in Zoho's US data center it's include:zcsend.net. Other data centers use their own value, such as include:eu.zcsend.net in Europe. If you already have an SPF record, add the include to it rather than creating a second record.

How long does Zoho Campaigns domain verification take?

Adding the records takes a few minutes. Zoho says DNS changes usually update within 24 to 48 hours, so if Verify Domain fails at first, wait and try again.

Can I send Zoho Campaigns emails from a Gmail or Yahoo address?

No. Zoho Campaigns doesn't allow public domain sender addresses such as @gmail.com or @yahoo.com. Send from an address at a domain you own, such as hello@yourbusiness.com, and authenticate that domain.

Do I need a custom return path?

It's optional but worth doing. With Zoho's default bounce address, SPF passes for Zoho's domain, not yours. A custom return path on your own domain lets SPF line up with your From address too, alongside DKIM.

I also use Zoho Mail. Do I need two SPF records?

No. A domain can only have one SPF record. Put both includes in it, for example v=spf1 include:zohomail.com include:zcsend.net ~all, using the values for your Zoho data center.