Skip to content

Troubleshooting DNS verification

Fix the usual reasons a DNS record shows Not found or Wrong value, and get your domain verified.

Each record in Settings → Sending domain shows its own status, so you can see exactly what’s left. Not checked yet means the first check hasn’t run. Not found means DNS has no record with that name. Wrong value means a record exists but its value doesn’t match — the status shows what was found instead. Most problems come down to a typo in the name, a provider that adds the domain twice, or DNS that hasn’t updated yet.

  1. Copy, don’t type. Use Copy name and Copy value in Settings and paste into your DNS provider. Every DKIM token is unique.
  2. Give it time. Most DNS providers update within minutes; some take up to 48 hours.
  3. Click Check now after you change a record, instead of waiting for the next automatic check.

A record shows Not found, but I added it. Your DNS provider may have added your domain to the name a second time, so the record lives at abc123._domainkey.notify.acme.com.acme.com. Many providers append the domain automatically: enter only the part before your root domain (for notify.acme.com at a provider managing acme.com, that’s abc123._domainkey.notify). Also check that you added it in the right DNS zone — the one for the domain you’re verifying.

The DKIM records show Wrong value. Check that the value ends in .dkim.amazonses.com and has no extra characters or spaces. If your DNS provider can proxy traffic (Cloudflare’s proxy, for example), set these CNAME records to DNS only: a proxied CNAME returns the provider’s address instead of the value.

The MX record shows Wrong value. The MX record belongs on bounce.<your domain>, not on your domain itself, with the value shown in Settings, 10 feedback-smtp.<region>.amazonses.com. If your provider has a separate priority field, enter 10 there and only the feedback-smtp… part as the value. Don’t change the MX records of your main domain.

The SPF record shows Wrong value. The SPF TXT record also belongs on bounce.<your domain>. Paste the value exactly, including v=spf1 and ~all. You don’t need to change the SPF record on your root domain.

There’s no DMARC record in the list. That’s expected when your domain already publishes a DMARC policy. Settings says so under the records table. Keep your existing policy.

The DMARC record shows Wrong value. Check that the record is a TXT record at _dmarc.<your domain> and its value starts with v=DMARC1. A name can hold only one DMARC record, so remove any duplicate you added by mistake.

Every record shows Verified, but the domain is still Pending. Your records are in place. Amazon SES, which sends your email, runs its own check of the DKIM and MAIL FROM records on its own schedule, usually within minutes of ours and occasionally a few hours later. Settings says All records are in place while it waits. Nothing needs fixing: the domain changes to Verified on its own, and you can set up your sender profiles meanwhile.

Everything verified, then the domain changed to Failed. Transactional Email keeps checking your records after verification. If a record is removed — often during a DNS migration — the domain shows Failed and sends fail with sender_invalid until it verifies again; they don’t fall back to the sandbox address. Put the records back and click Check now.

I’m getting a “still waiting on DNS records” email. You’ll get one, once, if the domain isn’t verified 48 hours after you added it. It lists the records that still need attention.

Settings says the domain is already set up in another account. Each domain can belong to only one HubSpot account. If it’s yours, email support@cambiumapps.com with the domain and both HubSpot account IDs.

Click Send instructions to IT to email the exact records to whoever manages your DNS. If the records look right to you and still don’t verify, email support@cambiumapps.com with your sending domain.