InboxAudit

ActiveCampaign email authentication

Marketing automation and CRM platform for mid-market teams.

SPF record

Add ActiveCampaign to your domain's SPF record with this include:

include:emsd1.com

A complete record for a domain sending only through ActiveCampaign:

v=spf1 include:emsd1.com ~all

What it costs you

1 of your 10 DNS lookups. That is the cheapest an include can be — the record it points at contains only IP ranges, with no further includes to follow. Behind it are 5 IP ranges.

Live record

This is what emsd1.com published when this page was generated:

v=spf1 ip4:173.236.20.0/24 ip4:192.92.97.0/24 ip4:52.128.40.0/21 ip4:217.8.118.0/24 ip4:103.229.233.0/24 ~all

DKIM

Enable DKIM inside ActiveCampaign and publish the selector record it generates. DKIM matters more than SPF for deliverability, because a DKIM signature survives forwarding while SPF does not — see how selectors work.

DMARC

Neither SPF nor DKIM protects the address your recipients actually see until DMARC ties them to it. Once ActiveCampaign is authenticating, publish a DMARC record — start at p=none with a reporting address and tighten from there.

Generate a DMARC record →

Check it worked

DNS changes take minutes to hours to propagate. Once published, run the domain through the checker — it resolves the full include chain and reports the real lookup count.

Official documentation

ActiveCampaign setup docs →