Skip to content
English
  • There are no suggestions because the search field is empty.

How can I make sure my HubSpot email is properly connected to a domain?

Take these steps to ensure you meet the authentication requirements if you are using HubSpot Marketing Email.

Gmail, Yahoo and Microsoft (Outlook, Hotmail and Live.com) now require businesses that send marketing email to prove their emails are legitimate. Emails that don't meet these requirements may be sent to spam or rejected entirely.

The most important step is to connect your email sending domain to HubSpot. This sets up three types of email authentication:

  • DKIM: adds a digital signature showing your emails really come from your domain.
  • SPF: lists the services allowed to send email for your domain, such as HubSpot and Microsoft 365.
  • DMARC: tells inbox providers what to do with emails that fail authentication, and is now required for bulk senders.

What happens if you skip this? If your domain isn't connected, HubSpot changes your emails' From address to a HubSpot-managed domain, and your emails are more likely to land in spam.

Please note: connecting your domain requires changes to your DNS records. If you're not comfortable editing DNS, Gate 39 can do this for you. Contact us through the Customer portal.

What else inbox providers require

Along with authentication, Gmail, Yahoo and Microsoft expect bulk senders to:

  • Offer one-click unsubscribe. HubSpot adds this to marketing emails automatically, so don't remove the unsubscribe link from your templates.
  • Keep spam complaints low (under 0.3%) by only emailing people who opted in.
  • Honor unsubscribes promptly. HubSpot does this automatically.

Step 1: Start connecting your domain in HubSpot

  1. In HubSpot, click the settings icon in the top navigation bar.
  2. In the left sidebar, go to Content > Domains & URLs.
  3. Click the Email Sending tab.
  4. Click Connect sending domain.
  5. Enter the domain you send email from: the part after the @ in your From address, for example yourcompany.com. If you send from a subdomain such as info.yourcompany.com, connect that subdomain.
  6. Click Next. HubSpot will show the DNS records you need to add.

Step 2: Add the records to your DNS

  1. In a separate browser tab, log in to the provider that manages your domain's DNS, such as GoDaddy, Cloudflare or AWS Route 53.
  2. Copy each record from HubSpot into your DNS settings, matching the type, host and value exactly.

DKIM (CNAME records): add each CNAME record exactly as shown.

Using Cloudflare? Turn off proxying (set the records to DNS only) and CNAME flattening for these records, or they won't verify.

SPF (TXT record):

  • If you already have an SPF record (one that starts with v=spf1), don't create a second one. Two SPF records cause authentication to fail. Instead, add HubSpot's value to your existing record. For example:
    • Before: v=spf1 include:spf.protection.outlook.com -all
    • After: v=spf1 include:spf.protection.outlook.com include:[HubID].spf##.hubspotemail.net -all
  • If you don't have an SPF record, create a new TXT record. For example:
    • v=spf1 include:[HubID].spf##.hubspotemail.net ~all

Use the exact value from your HubSpot settings in place of [HubID].spf##, and make sure the record ends with ~all or -all.

DMARC (TXT record): if your domain doesn't already have a DMARC record, add the one HubSpot recommends, or start with a monitoring-only policy:

  • Host: _dmarc
  • Value: v=DMARC1; p=none; rua=mailto:[your reporting email]

p=none lets you monitor results without blocking any email. Once you're confident all your legitimate email passes authentication, you can work with Gate 39 to strengthen the policy.

  1. Save your DNS changes.

Step 3: Verify the connection

  1. Return to HubSpot and click Verify. DNS changes can take anywhere from a few minutes to 48 hours to take effect.
  2. On the Email Sending tab, check that your domain shows as connected or authenticated.
  3. To double-check, enter your domain in a free tool such as MXToolbox to confirm your SPF and DMARC records.

Tip: if you change the domain you send from, warm it up gradually by starting with smaller sends to your most engaged contacts, then increasing over a few weeks.

Related article: What is the best way to design my marketing emails?

Need help? Contact the Gate 39 team through the Customer portal.

 

References
[1] HubSpot – Manage email authentication in HubSpot (updated Mar 20, 2026)
[2] HubSpot – Add HubSpot to your SPF record
[3] HubSpot – Overview of email authentication
[4] HubSpot Community – Best practices for adding SPF record in HubSpot
[5] MailOver – Google, Yahoo & Microsoft Bulk Sender Requirements: 2026 Guide
[6] EmailWarmup – Gmail and Yahoo Bulk Sender Requirements (Updated for 2026)