Email authentication troubleshooting

Email authentication  is a technical process that requires working with Domain Name Servers (DNS). For those who aren't used to working with DNS, it can be a confusing process, as each DNS host uses different configuration software, and it can sometimes take up to 48 hours for your changes to be seen around the internet.

Below we've listed the most common issues people have when trying to set up email authentication.

If you haven’t or cannot authenticate, we won’t stop your client from sending, but we will make a couple of changes to their sending domain.

Errors you may see in Campaign Monitor

When you try to authenticate your client's sending domain with Campaign Monitor, you may see the errors below. We've detailed the most common reasons for receiving the errors, and how you can resolve them.

Incomplete

You have not completed the domain authentication.

This status is shown when a freshly added sending domain has not been through any verification checks yet. Click the Authenticate button and follow the on-screen instructions to finish setting up.

Missing record

The TXT record could not be found. Please create the appropriate TXT record. It can take some time for our systems to see a new record once added or changed.

This error can appear for DKIM or DMARC records. For SPF records, the icon will be colored orange instead of red, and the tooltip will also include A valid SPF record includes “_spf.createsend.com” domain.

Setting up an SPF record for your client's sending domain is recommended but not currently required, as we automatically handle SPF. To improve your client's email setup and future proof the delivery of their emails, we recommend adding include _spf.createsend.com to your client's SPF record in case it becomes necessary in future.

There are a couple of reasons you might see this error:

  • There's a typo in the domain name you provided
  • You've entered an incorrect record name in the DNS host

There's a typo in the domain name you provided

Make sure the domain you entered in Campaign Monitor matches the one you set up authentication for in the DNS host, then try again.

You've entered an incorrect record name in the DNS host

Many DNS hosts only require you to enter cm._domainkey, _dmarc, or @ as the TXT record name instead of the full domain, as they automatically add your client's domain to the end. If this is the case, and you've entered the full domain, the TXT record name will actually be cm._domainkey.example.com.example.com, _dmarc.example.com.example.com, or example.com.example.com, and Campaign Monitor will be looking in the wrong place to verify the authentication.

You only need to have a DMARC record on your client's top level domain. You do not need to add an additional DMARC record for their subdomain(s). If they already have a DMARC record in place, you do not need to make any changes to the p value.

Invalid record

Record found but is invalid. Please re-create the TXT record. It can take some time for our systems to see a new record once added or changed.

This error can appear for DKIM and DMARC. Make sure the records match exactly by copying the record we show on screen, and pasting it into the DNS host.

You might see this error if your change hasn't propagated yet. This can occur when our servers are still seeing the original DNS settings, and haven't picked up your changes yet.

DNS changes also aren't instantaneous. Depending on the DNS host settings, it can take up to 48 hours for the entire internet, including our servers, to see any updates as they propagate across the world. The timing can vary, involves multiple systems controlled by various organizations, and it isn't something Campaign Monitor can speed up.

If you're reading this after you updated the record, and everything is set up correctly, the only option is to wait until the changes propagate. You can still send emails during this time, but we will make a couple of changes to the sending domain you nominate. For future DNS changes, read about lowering your Time To Live (TTL) setting.

You can use a validator like EmailStuff to check published DKIM or DMARC records and help you to verify that servers outside the DNS host can see your changes, and that the TXT records are present and valid. When you verify the record, the domain name is the one your client is sending from, and in the case of DKIM, the selector is often cm.

You can also check if different servers around the world are seeing the same DNS record values with Whatsmydns. For DKIM, enter cm._domainkey.mail.example.com in the search box. For DMARC, enter _dmarc.mail.example.com. Replace mail.example.com with the domain you're trying to authenticate in both examples. Set the dropdown menu next to it to TXT, then click Search. The record value for each server should match the TXT record value you entered in the DNS host if they have seen the update. Note that this is just an indicator, and doesn't represent the whole internet.

If you continue to have problems, contact the DNS host for assistance.

Possibly invalid

Record found but is invalid. Please re-create the TXT record. It can take some time for our systems to see a new record once added or changed. A valid SPF record includes “_spf.createsend.com” domain.

Updating an existing SPF record for your client's sending domain is recommended but not currently required, as we automatically handle SPF. To improve your client's email setup and future proof the delivery of their emails, we recommend adding include _spf.createsend.com to your client's SPF record in case it becomes necessary in future.

This error is unique to SPF only. It can appear for the same reasons as for DKIM and DMARC above, but also if you have an existing SPF record that does not include _spf.createsend.com. Please add include:_spf.createsend.com immediately after the v=spf1in the existing record. Make sure you include the space after v=spf1.

Once updated, your client's SPF record should look something like v=spf1 include:_spf.createsend.com include:_spf.google.com ~all, where include:_spf.google.com is an example of another domain that is also included. The SPF record may have more domains included.

You can use a validator like EmailStuff to check the published SPF record. The domain name is the one you are sending from.

You can also check if different servers around the world are seeing the same DNS record values with Whatsmydns. Enter the domain you're trying to authenticate, set the dropdown menu next to it to TXT, then click Search. The record value for each server should match the TXT record value you entered in the DNS host if they have seen the update. Note that this is just an indicator, and doesn't represent the whole internet.

If you continue to have problems, contact the DNS host for assistance.

If you are using an SPF record flattening service you will likely continue to see the Possibly invalid error because our checker looks for include:_spf.createsend.com only.

Multiple records found

Please make sure there is only one record. It can take some time for our systems to see a new record once added or changed.

This error can occur if you have more than one DKIM record with the same name. Email servers will often reject multiple records as invalid. Make sure there is only one record of that name in your client's DNS.

Mismatches can also occur if someone else authenticated the same domain in the past. This means the matching record name can have a different value in the DNS host, compared to what you need. We recommend removing any previous DKIM record generated by Campaign Monitor from the DNS.

Key length at risk

Key is shorter than the minimum of 1024 bits.

This error will appear if you have an older, 768 bit DKIM key. This key length is not considered secure enough and your client's emails will fail authentication as a result. You will need to remove this entry and add the sending domain again to regenerate a stronger, 1024 bit DKIM. Remember to delete the old record from your client's DNS too.

Note that if a sending domain is used across multiple clients you will need to remove it from them all before you can regenerate a 1024 bit DKIM key.


Other issues

Due to its complex nature, or needs your client's business may have, you may run into other issues with authentication. Other common issues are listed below.

The domain has authenticated, but my client's email isn't being signed with DKIM

It can take up to 30 minutes after a domain has been verified for our system to start signing emails with DKIM.

In addition to this, your client's emails will only be signed with DKIM when sent from Campaign Monitor. If your client uses the same domain to send email through other email service providers, that email won't be DKIM signed by our process. However, you can set up DKIM for your client's domain with other service providers using DKIM keys generated by that system. We recommend setting up authentication for all your client's mail streams as best practice.

My client's web host doesn't support DKIM

DNS records are usually hosted by the same company that hosts your client's site, but it doesn't have to be that way. It's possible to keep your client's webhost and use a separate DNS host. Switch DNS providers, then ask for assistance from the new DNS host to set things up.

My client's host doesn't allow me to modify the domain's DNS

Some web and DNS hosts won't let you modify the DNS records yourself, however many will add authentication records for you. Contact the host to find out if they offer this service.

My client's DNS host doesn't support semicolons, underscores, fourth level domains, or record values longer than 255 characters

Some DNS hosts have limitations that make authenticating with DKIM difficult:

  • Lack of semicolon or underscore support — In some cases, substituting ; for \; will let you bypass the lack of support for semicolons in a DNS host. Underscores are a requirement for DKIM and DMARC records, and if the host doesn't support them, you'll need to change DNS hosts.
  • Fourth level domains — Some DNS hosts may not accept a fourth level domain like cm._domainkey.example.com. In this case, try adding the subdomain _domainkey to your  client's sending domain first, then adding the cm subdomain to that.
  • 255 character limit in DNS record values — Campaign Monitor generates 1024-bit DKIM keys, which are 225 characters long, and therefore don't exceed the 255 character limit imposed by some DNS hosts on record values. You might exceed this limit if your client has generated their own keys outside of Campaign Monitor with a higher bit value. Campaign Monitor currently supports up to 2048-bit DKIM keys from 3rd parties.

In all other cases, the best option is to switch DNS hosts to one that properly supports DKIM.

How can I check my client's domain has been authenticated?

The way email clients display FROM details changes when you authenticate. You can set up a free test account with Gmail to see the difference.

I authenticated with DKIM, but my client's email still ended up in spam

Spam filters look at many different things when determining whether or not an email should reach the inbox. While authentication can help your sending reputation, it isn't a cure-all or magic bullet — it is only one part of the solution. Among other things, you still need to make sure your client's email doesn't contain spammy content, that they're a good sender, and that everyone on your client's list gave them permission to send.

If you see consistently high spam complaints or your client's emails landing in the spam folder, here are three things you can do to improve your results:

  1. Audit all signup sources and list collection methods, and change them if they don't require explicit, direct action by the subscriber to opt in. 
  2. Focus on sending to your client's most active and engaged audience and exclude inactive contacts for the next few campaigns.
  3. Remove dormant contacts, people who have shown no activity or engagement within the last 12 months.

We've seen significant improvement when lists are carefully and routinely managed based on recipient engagement. 

Read more on deliverability best practices that help you successfully land in your subscribers’ inbox: