SUPPORT.TWILIO.COM END OF LIFE NOTICE: This site, support.twilio.com, is scheduled to go End of Life on February 27, 2024. All Twilio Support content has been migrated to help.twilio.com, where you can continue to find helpful Support articles, API docs, and Twilio blog content, and escalate your issues to our Support team. We encourage you to update your bookmarks and begin using the new site today for all your Twilio Support needs.

Troubleshooting SPF and DKIM Failures for Authenticated Domains

Issue

 

You may notice that your authenticated domain appears as verified, but SPF and DKIM authentication fail when sending emails.

 

Product

 

Twilio SendGrid (Email)

 

Cause

 

There are two common scenarios that can result in this behavior:


Scenario 1: EU-Pinned Domain


If the domain was authenticated using the EU-Pinned option, it can only be used with an EU subuser. To confirm whether the domain is EU-pinned, open the authenticated domain in your SendGrid account and check the DNS records. If the records include eu, the domain is EU-pinned.


Scenario 2: Missing CNAME Records


If the required CNAME records have been removed from your DNS provider, SPF and DKIM authentication will fail even if the domain previously appeared to be authenticated.

 

Resolution

 

For Scenario 1: EU-Pinned Domain


EU-pinned domains are supported only with EU subusers. If the domain was authenticated under the parent account, assign the authenticated domain to the appropriate EU subuser before sending email. Once assigned, retry sending the email and verify that SPF and DKIM authentication pass.


For Scenario 2: Missing CNAME Records

  • In your SendGrid account, navigate to the authenticated domain and click Verify.
  • If the verification fails, compare the required DNS records with those currently configured in your DNS provider.
  • Re-add any missing or incorrect CNAME records.
  • After the DNS changes have propagated, click Verify again to confirm that the domain is successfully authenticated.
  • Once verification succeeds, send a test email to confirm that SPF and DKIM authentication pass.

 

Related links:

 

How to set up Domain Authentication

 

 

 

Have more questions? Submit a request
Powered by Zendesk