Complete domain authentication

SendGrid generates account-specific DNS records. With automated security, these commonly include a branded return path and DKIM selectors. Publish the exact values from your account.

  • Match the authenticated domain to the From domain used by the application.
  • Confirm both generated DKIM selectors resolve.
  • Check whether a branded return path provides aligned SPF.

Watch for fallback identity

If SendGrid cannot match a From address to a valid authenticated domain, it can fall back to a provider domain. That may authenticate but will not necessarily align with your visible From domain.

Review the first reports

Confirm SendGrid traffic is signed with the expected domain and separate it from other services using the same From domain.

Further readingSendGrid domain authenticationSendGrid DMARC guidance