HubSpot
HubSpot's email-authentication article generates two DKIM CNAME records, an SPF TXT record, and a DMARC TXT record when you connect a marketing sending domain. HubSpot's troubleshoot article says the SPF record should include include:shared.hubspot.com.
The record
v=spf1 include:shared.hubspot.com ~all
HubSpot recommends a dedicated email subdomain rather than reusing the subdomain that hosts website content. If an SPF TXT record already exists for the sending domain, HubSpot's troubleshoot page says to append HubSpot's include to that same record instead of publishing a second SPF TXT.
Four record types
HubSpot's manage-authentication flow also lists MX for the connected sending domain as part of the connection checklist. Copy each host and value from HubSpot's domain settings into the DNS provider.
HubSpot's DMARC troubleshooting section says only one TXT record at _dmarc may start with v=DMARC1, matching RFC 7489's expectation that receivers discover a single policy record.
Merge SPF
HubSpot's troubleshoot article appends include:shared.hubspot.com to an existing SPF TXT instead of creating a second v=spf1 record.
HubSpot recommends an email subdomain that is not already used to host website or blog content.
Dedicated IP customers follow additional A, MX, and CNAME steps documented in HubSpot's knowledge base.