Skip to content

Setting up your sending domain

Add your domain, publish the DNS records Settings shows you, and watch each record verify.

Before you can send from your own domain, you prove you own it and authorize Transactional Email to send for it. You do that by publishing a handful of DNS records. Transactional Email checks them automatically and shows the live status of each one.

Live sending stays off until DKIM, MAIL FROM, and DMARC all verify. You can set up the domain while you’re still in the sandbox — it doesn’t need a subscription.

  • The Super Admin role in HubSpot.
  • A domain picked out — ideally a subdomain such as notify.acme.com. See Choosing a sending domain.
  • Access to the domain’s DNS settings, or the email address of the person who manages them.
  1. Open Settings → Sending domain. In HubSpot, go to Marketplace apps → Transactional Email and open Settings.
  2. Enter your domain in Sending domain — for example notify.acme.com — and click Add domain. If you enter a root domain, a Use a subdomain warning explains the trade-off; you can still add it.
  3. Publish the records at your DNS provider. Settings lists each record with its Type, Name, and Value. Use Copy name and Copy value rather than typing them — the values are unique to your account.
    • If someone else manages your DNS, click Send instructions to IT, enter Their email address, and click Send instructions. They get an email with every record and what it’s for.
  4. Check the records. Transactional Email checks automatically. To check right away, click Check now. Each record shows Verified, Not found, or Wrong value — with the value it found instead.
  5. Wait for Verified. When every record checks out, the domain’s status changes from Pending verification to Verified.

Your sending domain is verified. If you’ve already accepted the Acceptable Use Policy and your subscription is active, live sending starts now; otherwise it starts as soon as both are done.

You’ll see up to six records. The names and values below show the pattern; copy the exact values from Settings.

Type Purpose Name Value
CNAME ×3 DKIM <token>._domainkey.<your domain> <token>.dkim.amazonses.com
MX MAIL FROM bounce.<your domain> 10 feedback-smtp.<region>.amazonses.com (priority 10)
TXT SPF bounce.<your domain> v=spf1 include:amazonses.com ~all
TXT DMARC _dmarc.<your domain> v=DMARC1; p=none;
  • DKIM (three CNAMEs) lets mailbox providers confirm your emails really come from your domain. Each token is different.
  • MAIL FROM (the MX and SPF records on bounce.<your domain>) handles bounces and makes SPF pass for your domain. It doesn’t touch the SPF record on your root domain.
  • DMARC appears only if your domain doesn’t already publish a DMARC policy. If you have one — on the subdomain or your root domain — keep it; Settings notes that no DMARC record is needed.

Some DNS providers add your domain to the name automatically. If yours does, enter only the part before your domain — for example abc123._domainkey.notify instead of abc123._domainkey.notify.acme.com.

  • Automatic checks. Transactional Email checks a new domain within a minute, then at growing intervals, then every 15 minutes. After 7 days it checks once a day. Until the domain is verified, Check now checks it right away.
  • A reminder after 48 hours. If the domain still isn’t verified 48 hours after you added it, your alert recipients get one email listing the records that are still missing or wrong. It’s only sent while the app is installed and your account is open.
  • Ongoing checks. After verification, the records fold into a collapsed DNS records section, and Transactional Email keeps checking them on its own. If they’re removed, the domain shows Failed and every send fails with sender_invalid until they’re restored — once you’ve been live, sends never fall back to the sandbox address.
  • Sender profiles. Adding the domain unlocks sender profiles: each one sends from an address on it, such as billing@notify.acme.com. You don’t need to wait for verification to create them. See Creating a sender profile.

Base includes one sending domain. To use a different one, click Remove domain, confirm with Yes, remove domain, and add the new domain. Until the new domain verifies, sends fail with sender_invalid (they don’t go back to the sandbox address), and warm-up starts over from day 1 once the new domain is live. Your sender profiles move to the new domain on their own: billing sends from billing@ the new domain.

A domain that’s already set up in another HubSpot account can’t be added here. If it belongs to you, email support@cambiumapps.com.