Mail setup

SPF, DKIM and DMARC with Mailchimp and Mandrill.

The records Mailchimp and Mandrill needs, where to find them, and the failure specific to this provider.

SPF

Add include:servers.mcsv.net to your existing SPF record. Do not create a second record: two SPF records mean neither works, and that is the most common mistake in this whole area.

DKIM

Found in the Mailchimp account, under Website, then Domains, or in Mandrill's settings for transactional.

Mailchimp authenticates the sending domain with a CNAME pair. Mandrill, the transactional side, has its own separate configuration.

Mailchimp and Mandrill publishes keys under a Mailchimp-provided selector, which is what an external check looks for.

DMARC

DMARC is the same regardless of provider, because it is your instruction rather than theirs. Start at v=DMARC1; p=none; rua=mailto:you@yourdomain.com, read the reports, authorise everything legitimate, and only then tighten. The DMARC guide covers the order, and the order is what stops you blocking your own invoices.

Worth knowing with Mailchimp and Mandrill

Mailchimp accounts frequently outlive the campaigns they were created for. If you no longer send newsletters, remove the include rather than leaving it consuming an SPF lookup.

Watch the lookup count

Every include costs one of your ten SPF lookups, and so does every include inside it. Adding a third or fourth sender is where domains typically cross the limit, after which the whole record fails silently. See the lookup guide before adding another.

Check yours

Check whether your mail is actually passing.

Plain answers rather than policy strings. Free, no account.

Using a different mail provider?

The records differ per provider, and so do the mistakes.

HubSpot · MailerLite · SMTP2GO · Titan · Zoho Mail · Namecheap Private Email

All 20 in this set