In HubSpot, click the settings icon, go to Content, then Domains & URLs, open the Email Sending tab and click Connect sending domain. Enter an address you send marketing email from, confirm the domain, and add every DNS record HubSpot shows (two DKIM records plus SPF, DMARC and MX records) at your DNS provider.
Why connecting your domain matters
When you send marketing email from HubSpot, Gmail and Yahoo check whether the email really comes from yourbusiness.com. They use three checks:
- DKIM, a digital signature that proves the email came from your domain and wasn't changed on the way.
- SPF, a DNS record that lists the servers allowed to send email for your domain.
- DMARC, a DNS record that tells mailboxes what to do when those checks fail, and sends you reports.
Gmail and Yahoo require all three from bulk senders, and at least one of SPF or DKIM must match your From address. Connecting your sending domain sets this up for HubSpot email. HubSpot also says you can't use your own domain in the From address until the domain is connected with DKIM.
Connecting a sending domain is available on Starter, Professional and Enterprise plans of Marketing Hub, Sales Hub, Service Hub and Content Hub.
Before you start
- A HubSpot login that can open Settings and change domain settings.
- A login for your DNS provider. DNS is the public address book for your domain. It is usually where you bought the domain, your website host, or Cloudflare.
Step 1: Start the connection
- Click the settings icon in the top navigation bar.
- In the left menu, go to Content, then Domains & URLs.
- Click the Email Sending tab.
- Click Connect sending domain in the top right.
- Enter an email address you use for marketing email, such as news@yourbusiness.com, and click Next.
- Check that the sending domain shown is correct and click Next.
Step 2: Choose automatic or manual setup
HubSpot may offer to sign in to your DNS provider and add the records for you. If it does and you have that login, this is the quickest route.
Otherwise choose No, I'll set it up manually. HubSpot then shows a table of records, with Host and Required data columns and a copy button for each value.
Step 3: Add the records at your DNS provider
Copy each record into your DNS provider exactly as HubSpot shows it. You'll see four kinds:
| Record | Type | What it does |
|---|---|---|
| DKIM | Two CNAME records | Lets HubSpot sign your email with yourbusiness.com |
| SPF | TXT | Allows HubSpot's servers to send for your domain |
| DMARC | TXT | Your domain's policy and reports |
| MX | MX | Part of HubSpot's sending setup; add it as shown |
The DKIM names and the SPF value are unique to your account, so copy them from HubSpot rather than from an example. Some records may sit on a subdomain HubSpot chooses, not on yourbusiness.com itself. Use the host names HubSpot shows, every time.
Many DNS providers add your domain to the end of the name automatically. If a record ends up with yourbusiness.com twice in its name, edit it so the name matches HubSpot's Host column without the repeat.
If your DNS is on Cloudflare, set the CNAME records to "DNS only", not proxied, so receivers can read them.
If the host already has an SPF record
This is where most setups go wrong. A domain or subdomain can only have one SPF record. If the host HubSpot names already has one, don't add a second. Add HubSpot's value, after include:, to the existing record, before the ~all or -all at the end. For example:
v=spf1 include:_spf.google.com include:123456.spf03.hubspotemail.net ~all
The number in the HubSpot part is your own account's value. Two SPF records on the same host break SPF completely.
If you already have a DMARC record
Keep it and don't add a second one. A domain must have exactly one DMARC record. HubSpot notes that a subdomain counts as authenticated when your main domain has a DMARC record, because subdomains inherit it.
If you don't have one, add the record HubSpot shows, or start with this monitoring record, which changes nothing for your email yet:
| Type | Name (Host) | Value |
|---|---|---|
| TXT | _dmarc.yourbusiness.com | v=DMARC1; p=none; rua=mailto:dmarc-reports@yourbusiness.com |
Change the rua address to a mailbox you read. Once reports show all your genuine email passing, move to p=quarantine.
Step 4: Wait, then check the status
HubSpot says DNS changes usually take 10 to 70 minutes, and can take up to 48 hours. Wait at least 20 minutes, then go back to Content, Domains & URLs, Email Sending. Your domain shows one of three statuses:
- Not authenticated: none of the checks are set up yet.
- Partially authenticated: DKIM is verified, but SPF or DMARC is still missing.
- Authenticated: DKIM, SPF and DMARC are all verified.
Aim for Authenticated.
How to check it worked
HubSpot's status confirms the records exist. It doesn't show how Gmail, Yahoo or Outlook treat a real email. Send a real marketing email from HubSpot and check:
- DKIM passes for yourbusiness.com, not only for a HubSpot domain.
- DMARC passes, with SPF or DKIM aligned with your From address.
The free test does this from one email. Send a HubSpot test email to your private test address and you get a verdict for Gmail, Google Workspace, Outlook.com, Microsoft 365 and Yahoo, with the exact record to fix if something is missing.
Common problems
- Stuck on Partially authenticated. Usually SPF. Look for a second SPF record on the same host, or an include value pasted into the wrong record.
- Records not found. Check for a doubled domain in the name, a typo, or a trailing space.
- Different From domains. Each domain you send from needs its own connection. If one team sends from @yourbusiness.com and another from @yourbrand.com, connect both.
- Still in the Spam folder after it passes. Then the cause is more likely complaints or list quality. Gmail and Yahoo both expect a spam complaint rate below 0.3%.
Checked against: HubSpot Knowledge Base, Connect your email sending domain · HubSpot Knowledge Base, Manage your email authentication · Google Workspace Admin Help, Email sender guidelines · Yahoo Sender Hub, Sender best practices.