SendGrid sender authentication: domain auth for production, single sender for tests
Pick the right sender identity: domain authentication (DNS records, all addresses on the domain) versus single sender verification (one address via an emailed link). Most deliverability pain comes from shipping on single-sender. Not the full reference manual.
TL;DR: Pick the right sender identity: domain authentication (DNS records, all addresses on the domain) versus single sender verification (one address via an emailed link). Most deliverability pain comes from shipping on single-sender. Add the DNS records SendGrid generates. Validate in the console and wait for DNS to propagate.
The fix
- Settings > Sender Authentication > Authenticate Your Domain, enter the domain.
- Add the DNS records SendGrid generates. With automated security on, SendGrid creates the records for you to copy: DKIM CNAMEs plus the return-path record, covering SPF, DKIM, and DMARC assertions (you own the domain, you authorized the server, the message was not tampered with).
- Validate in the console and wait for DNS to propagate. Until validation passes, treat the domain as unverified.
- Once a domain is authenticated, any sender address on that domain is verified automatically. Single sender verification (testing only):
- Settings > Sender Authentication > Verify a Single Sender; fill in from name, from address, reply-to, and company address.
- Click the link in the verification email. No link click, no sending from that address.
- Do not use gmail.com / yahoo.com style addresses: SendGrid warns that they can fail DMARC checks. Rule of thumb: if more than one address or any production traffic sends from the domain, do domain auth. Single sender is for trying things out.
When to use this
- This covers exactly what the title says: SendGrid sender authentication.
- You are setting this up for the first time, or auditing an existing setup.
- You want the key gotchas in one place before you start.
When not to use this
- You are doing a different workflow with SendGrid; these steps are specific to the title above.
- You need the full reference docs; this is the short path, not the manual.
Compatibility
- Not pinned to a specific version; follows current SendGrid behavior.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.