Email authentication has become a critical part of the email landscape and is essential for reducing the risk of emails being blocked or sent to spam. Authentication allows servers and people to verify that the email is genuinely from the organization that it claims to be from, and that the servers sending the mail are permitted to send on behalf of that organization. The components involved in authentication – DKIM, SPF, DMARC, and more – are important tools for overcoming spam and fraud.
Given the importance of authentication both for trust and deliverability, Campaign Monitor has a policy of only sending mail from authenticated domains.
Why you can’t send from a free email address
Email addresses from webmail providers like Gmail, Yahoo, and Outlook.com are convenient for personal communication, but cannot be authenticated for sending in Campaign Monitor or any other email service provider (ESP). Why is that? As an example, Google owns gmail.com and is the only organization who can authenticate sending from @gmail.com addresses. Because you can’t authenticate those domains, sending from them risks the emails being blocked or classed as spam.
Most of these big free email providers use a policy framework called DMARC, and this is where the issue lies.
DMARC allows the domain owner to tell mail servers what to do if they receive an email claiming to be from their domain but not properly authenticated. In many cases, these free providers choose a DMARC policy to either REJECT (block the send) or QUARANTINE (send to the spam folder) any unauthenticated emails sent from their domain.
Allowing users to send unauthenticated mail from free domains with a REJECT or QUARANTINE policy would be a bad experience for everyone. Instead we encourage users to authenticate their own sending domain.
Why you need to authenticate your domain
Sending emails with proper domain authentication has long been a best practice to improve deliverability and allows your organization to establish an independent sending reputation. It also limits spoofing: only people with ownership of the domain can set up authentication, and it is important to prevent bad actors from impersonating domains they don’t have access to.
Furthermore Gmail and Yahoo have set robust authentication as one of a suite of sender requirements from 2024 onwards, and it is likely that other providers will follow. Without authentication, there is an increased likelihood that your emails will be blocked or sent to the spam folder.
Finally, many businesses and organizations with established emailing practices already have DMARC or other similar policies in place which require mail sent from their domains to be authenticated. Employees trying to send unauthenticated emails through an ESP will run into deliverability problems and not know why.
For these reasons Campaign Monitor requires that before you can use a particular domain in the From address of your emails, you need to first authenticate it as a sending domain.
For more tips and hints on choosing effective sender details, see Why “From” names and email addresses are important.
How we’ll help if you don’t authenticate
Your emails are important. We want to give them the best chance of being delivered to your recipients’ inbox and meet industry requirements.
We provide all clients with a default sending domain to be used as a replacement for unauthenticated domains. So if you send from a free email address or any other domain that you haven’t or cannot authenticate, we won’t stop you from entering it, but we will make a couple of changes:
- We’ll authenticate the email with a domain belonging to our systems (eg
cmail7.com,createsend7.com, or similar) - We’ll adjust the From email address to use a sub-domain specific to your client (eg
abcxyz.createsend7.com) - Replies from recipients will go to your original From address (unless you customize the Reply-to)
An example transformation of an unauthenticated From address:
- Original:
newsletter@example.com - Becomes:
newsletter@abcxyz.createsend7.com
You’ll be notified of these changes at various points in the campaign creation process, so it’s clear what’s happening.
These changes will help with delivery, but it’s no guarantee. If at all possible, our recommendation is to authenticate your own domain and send from that.
Deactivating the default sending domain
If you are unable to authenticate your own domain, the default we provide is designed to help meet deliverability requirements and give your email the best chance of landing in the inbox.
If your organization is aware of the risks to the delivery of your emails, you can deactivate the default sending domain for your clients by following these steps.
- Click Clients in the top navigation, then find the client you want to work with.
- Click Settings for the relevant client.
- Click Email setup in the lefthand sidebar and locate the Sending domains section.
- Find the table heading “Default sending domain” and then click on the toggle in the status column.
- Confirm your choice by clicking “Yes, deactivate” in the pop-up box.
Once deactivated the default sending domain can be reactivated at any time.