Domain authentication (production):
1. Settings > Sender Authentication > Authenticate Your Domain, enter the domain.
2. Add the DNS records SendGrid generates. With automated security on, SendGrid creates the records for you to copy: DKIM CNAMEs plus the return-path record, covering SPF, DKIM, and DMARC assertions (you own the domain, you authorized the server, the message was not tampered with).
3. Validate in the console and wait for DNS to propagate. Until validation passes, treat the domain as unverified.
4. Once a domain is authenticated, any sender address on that domain is verified automatically.
Single sender verification (testing only):
1. Settings > Sender Authentication > Verify a Single Sender; fill in from name, from address, reply-to, and company address.
2. Click the link in the verification email. No link click, no sending from that address.
3. Do not use gmail.com / yahoo.com style addresses: SendGrid warns that they can fail DMARC checks.
Rule of thumb: if more than one address or any production traffic sends from the domain, do domain auth. Single sender is for trying things out.