Skip to content

Scan your domain with 35 DNS and email security checks at zerohook.org.

For your provider

Mailchimp

Mailchimp's domain-authentication help asks for two DKIM CNAME records and one DMARC TXT record at _dmarc when you authenticate manually. The values are copied from the Domains page in the Mailchimp account.

Mailchimp's help article on mcsv.net explains that campaign mail uses a Mailchimp-controlled envelope address on domains such as mcsv.net or mailchimpapp.net until the From domain is authenticated with DKIM. That article recommends domain authentication and DMARC configuration.

DKIM-first setup

Mailchimp's authentication help lists manual steps: add two DKIM CNAME records, then add the DMARC TXT record Mailchimp shows with host _dmarc. The article distinguishes domain authentication from domain verification, which Mailchimp requires but says does not by itself change delivery.

When Mailchimp sends with its own bounce domain, SPF evaluation for marketing mail may occur on that Mailchimp domain rather than on your apex SPF record. DMARC alignment for the visible From domain still depends on DKIM and the policy at _dmarc under RFC 7489.

Campaign envelope

Mailchimp's mcsv.net help article describes Mailchimp-controlled envelope domains until the From domain is authenticated with DKIM.

Marketing mail may pass SPF on Mailchimp's bounce domain while DMARC for the visible From domain still depends on aligned DKIM and the _dmarc policy under RFC 7489.

Entri-based automated authentication in Mailchimp's help article follows the same record types as the manual Domains workflow.