ontiscal.com
Brevo · Domain Authentication

Authenticate a Custom Sending Domain in Brevo

This guide explains how to connect and authenticate a custom sending domain in Brevo by publishing the required DNS records. A correctly configured domain helps you send marketing emails with a branded identity and a more reliable technical setup.

Why authenticate a sending domain

Branded sender identity

Instead of sending from a generic address, you can use professional sender addresses tied to your own domain. This improves consistency across landing pages, outreach emails, and campaign flows.

Clear authorization signals

A verified sender domain helps align your email infrastructure with your brand and gives email providers clearer signals about who is allowed to send on behalf of that domain. It also reduces setup friction when you want to run campaigns through a dedicated sending environment.

Organized campaign infrastructure

Many marketers and businesses prefer using a dedicated domain or subdomain for campaigns so that promotional activity stays organized and easier to manage, separate from transactional or corporate mail flows.

DNS records Brevo requires

Brevo normally generates the exact DNS entries needed for your account and domain. The values below are example formats only — always copy the live values shown in your own Brevo dashboard.

Record TypePurposeHost / NameValue Format
TXTBrevo domain verification codebrevo-code.yourdomain.combrevo-code:xxxxxxxxxxxxxxxxxxxxxxxx
TXTDKIM signature keymail._domainkey.yourdomain.comv=DKIM1; k=rsa; p=YOUR_PUBLIC_KEY
TXTDMARC policy_dmarc.yourdomain.comv=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com
TXTSPF authorization@ or root domainv=spf1 include:spf.brevo.com ~all
include:spf.brevo.com

Step-by-step authentication

  1. Open domain settings in Brevo. Log in, go to the sender and domain settings area, and open the section to add a custom sending domain.
  2. Enter your domain. After saving, Brevo generates the DNS records required for verification.
  3. Access your DNS zone. Sign in to the provider that manages your DNS, such as Cloudflare, Namecheap, GoDaddy, or DirectAdmin.
  4. Publish the TXT records. This usually includes the Brevo verification code, the DKIM record, the DMARC record, and an SPF configuration or update.
  5. Merge SPF carefully. If an SPF record already exists on the domain, edit that existing record rather than adding a second one — a domain should keep a single SPF TXT record with all required includes merged correctly.
  6. Run the authentication check. Return to Brevo and verify. If records are correct and propagation has completed, Brevo confirms the domain as authenticated.
Example host values: mail._domainkey · _dmarc · @

DMARC policy strategy

A monitoring policy (p=none) can help you observe traffic before moving to stricter enforcement. Once your sending sources are confirmed and stable, you can harden the policy to quarantine or reject.

Common pitfalls

Frequently asked questions

Can I use my main domain instead of a subdomain?
Yes, in many cases, but some senders prefer a dedicated subdomain for better separation between website identity and campaign infrastructure.
Should hostnames include the full domain?
Some DNS panels want only the prefix, while others auto-append the domain. Review the final saved hostname carefully after creating each record.
Should DMARC start strict?
Many users begin with a softer monitoring policy first and move to stricter enforcement after confirming that valid email traffic is authenticating correctly.
When should I start sending campaigns?
Start after Brevo confirms authentication and after checking that the domain records are published correctly and consistently.

Contact ontiscal.com if you want to rent quality and aged domain names configured through custom DNS records working for email platforms like Resend or Brevo.