Brevo · Domain Authentication
Authenticate a Custom Sending Domain in Brevo
This guide explains how to connect and authenticate a custom sending domain in Brevo by publishing the required DNS records. A correctly configured domain helps you send marketing emails with a branded identity and a more reliable technical setup.
Why authenticate a sending domain
Branded sender identity
Instead of sending from a generic address, you can use professional sender addresses tied to your own domain. This improves consistency across landing pages, outreach emails, and campaign flows.
Clear authorization signals
A verified sender domain helps align your email infrastructure with your brand and gives email providers clearer signals about who is allowed to send on behalf of that domain. It also reduces setup friction when you want to run campaigns through a dedicated sending environment.
Organized campaign infrastructure
Many marketers and businesses prefer using a dedicated domain or subdomain for campaigns so that promotional activity stays organized and easier to manage, separate from transactional or corporate mail flows.
DNS records Brevo requires
Brevo normally generates the exact DNS entries needed for your account and domain. The values below are example formats only — always copy the live values shown in your own Brevo dashboard.
| Record Type | Purpose | Host / Name | Value Format |
| TXT | Brevo domain verification code | brevo-code.yourdomain.com | brevo-code:xxxxxxxxxxxxxxxxxxxxxxxx |
| TXT | DKIM signature key | mail._domainkey.yourdomain.com | v=DKIM1; k=rsa; p=YOUR_PUBLIC_KEY |
| TXT | DMARC policy | _dmarc.yourdomain.com | v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com |
| TXT | SPF authorization | @ or root domain | v=spf1 include:spf.brevo.com ~all |
include:spf.brevo.com
Step-by-step authentication
- Open domain settings in Brevo. Log in, go to the sender and domain settings area, and open the section to add a custom sending domain.
- Enter your domain. After saving, Brevo generates the DNS records required for verification.
- Access your DNS zone. Sign in to the provider that manages your DNS, such as Cloudflare, Namecheap, GoDaddy, or DirectAdmin.
- Publish the TXT records. This usually includes the Brevo verification code, the DKIM record, the DMARC record, and an SPF configuration or update.
- Merge SPF carefully. If an SPF record already exists on the domain, edit that existing record rather than adding a second one — a domain should keep a single SPF TXT record with all required includes merged correctly.
- Run the authentication check. Return to Brevo and verify. If records are correct and propagation has completed, Brevo confirms the domain as authenticated.
Example host values: mail._domainkey · _dmarc · @
DMARC policy strategy
A monitoring policy (p=none) can help you observe traffic before moving to stricter enforcement. Once your sending sources are confirmed and stable, you can harden the policy to quarantine or reject.
Common pitfalls
- Duplicate SPF records are one of the most common DNS mistakes — keep a single SPF TXT record that includes all authorized senders.
- Small differences in the host field can break validation; double-check whether the DNS manager expects a full hostname or only the prefix.
- Long DKIM public keys should be copied completely, without hidden line breaks or missing characters.
- Even correct records may need time — DNS propagation can still be in progress even when everything looks right.
Frequently asked questions
- Can I use my main domain instead of a subdomain?
- Yes, in many cases, but some senders prefer a dedicated subdomain for better separation between website identity and campaign infrastructure.
- Should hostnames include the full domain?
- Some DNS panels want only the prefix, while others auto-append the domain. Review the final saved hostname carefully after creating each record.
- Should DMARC start strict?
- Many users begin with a softer monitoring policy first and move to stricter enforcement after confirming that valid email traffic is authenticating correctly.
- When should I start sending campaigns?
- Start after Brevo confirms authentication and after checking that the domain records are published correctly and consistently.
Contact ontiscal.com if you want to rent quality and aged domain names configured through custom DNS records working for email platforms like Resend or Brevo.