Brevo (ex Sendinblue) SPF & DKIM Setup | EasyDMARC

Brevo (ex Sendinblue) SPF & DKIM Setup: Step by Step

4 Min Read
Brevo (ex Sendinblue) SPF & DKIM Setup: Step-by-Step featured image

If you are using Brevo and looking for a step-by-step guide to authenticate your email, then you’re in the right place. Email authentication is not only essential for secure email communication but also a crucial step in ensuring the successful delivery of your emails. Starting from February 2024 Google and Yahoo make email authentication mandatory for bulk email senders. So, if you don’t want your emails to be flagged as spam, rejected, or not delivered at all, follow this guide on Brevo SPF, DKIM, and DMARC configuration and ensure you’re all set.

The First Step Of Sender Verification On Brevo For SPF And DKIM


Your first step is to access the Domains page. To access the Domains page:
1
– click on your name at the top-right side of the screen.
2 – Select Senders & IP.
3 – Click on Domains.

Sender Verification On Brevo

In the Domains page, find or add the domain you want to authenticate and click on verify.

Sender Verification On Brevo

Once you click on the Verify button, Brevo will provide you with two DNS records: Brevo code and a DKIM record.

Sender Verification On Brevo

The Brevo code is just for your domain verification, you need to publish that TXT record in your DNS for your domain to be verified.

Now we’ll go into details about domain authentication and will explain how to add SPF and DKIM records in your DNS provider.

Brevo SPF Record Configuration

Note: There is no need to set up an SPF record for Brevo, as the “Envelope From” domain will always be handled by the servers of Brevo. For SPF to be aligned, you should have your “From address” domain in the “Envelope From” address.  Brevo uses “af.d.mailin.fr”, “kh.d.sender-sib.com” and other domains as the “Envelope From” domain, during the DMARC check, this “Envelope From” domain will not match with your “From address” domain, so SPF alignment will fail. This happens not only with Brevo but with the majority of Email Service Providers.
In case you add the include provided by Brevo (include:spf.sendinblue.com) in your SPF record, your SPF record will look like the one below,
v=spf1 include:zoho.com include:spf.sendinblue.com ~all

Also, keep in mind that DMARC requires either DKIM or SPF to be authenticated and aligned, so you will pass the DMARC check even without SPF alignment. SPF alignment failing won’t affect your email deliverability if you have DKIM in place. Thus, you need to set up only DKIM for Brevo.

Brevo DKIM Record Configuration

Brevo provides you with a DKIM TXT record to publish in your DNS zone.

Brevo DKIM Record Configuration

How to Add the Provided TXT Record in Your DNS?

Step 1:  Head to your DNS, create a new DNS record, and set the type to TXT.

Step 2: Copy the Hostname field to paste into the corresponding field in your DNS. For the TXT name/host, what you enter depends on your DNS host. Some require you to enter the full mail._domainkey.coco-tex.com, others only need the mail._domainkey part, as they automatically append your domain name in the end.

Step 3: In the Value/Content field, copy and paste the generated Value code under the DKIM record.
Like the one below (DNS Cloudflare),

Brevo DKIM Record Configuration

Once you finish publishing the TXT records in your DNS, go back to your Brevo account and click the Check Configuration button. If everything is done properly, a green check mark appears next to the Value fields for the DKIM record.

Brevo DKIM Record Configuration

Brevo DMARC Configuration with EasyDMARC

It’s important to note that DMARC compliance for Brevo is achieved via DKIM authentication and alignment only. Although you’ve not configured SPF, DMARC will still pass. 

So, after having SPF and DKIM in place, It’s time to authenticate with DMARC policy. DMARC is a complex protocol, but if you’ve decided to do it yourself, here is a checklist to follow:

  • Register on EasyDMARC,
  • Add your domain to our portal to generate a DMARC record with p=none,
  • Copy the record and update your DNS,
  • Wait for the DMARC reports to gather information on your outgoing email ecosystem and their email authentication results,
  • Prepare for long-term compliance and achieve full enforcement.

Later, you can test it with our Email Investigation tool:

Email investigation tool

If you’re still confused, contact us for detailed support and guidance along the way of your email authentication journey. 

Various authors from EasyDMARC teams have contributed to our blog during company's lifetime. This author brings everyone together.

Comments

guest
2 Comments
Inline Feedbacks
View all comments
David
David
Mar 1, 2024

Not adding SPF or adding the SPF record you suggested still results in alignment failure.

Hagop Khatchoian
Admin
Hagop Khatchoian
Mar 1, 2024
Reply to  David

David, thank you for your comment!
We’ve already stated in the article that achieving SPF alignment with Brevo is not possible.
Whether you include their SPF or not doesn’t matter, but our engineers included it as it’s also recommended in their steps.

succees We’re glad you joined EasyDMARC newsletter! Get ready for valuable email security knowledge every week.

succees You’re already subscribed to EasyDMARC newsletter. Continue learning more about email security with us