Set up DKIM for SendGrid

Settings → Sender Authentication

  1. Open Settings → Sender Authentication → Authenticate Your Domain in the SendGrid dashboard.
  2. Enter your sending domain and choose whether to use automated security (CNAME-based key management).
  3. Publish the s1._domainkey and s2._domainkey CNAME records SendGrid provides.
  4. Publish the return-path CNAME as well — SPF alignment depends on it.
  5. Click Verify. SendGrid checks the records and marks the domain authenticated.

Confirm it worked

DNS changes take time to propagate. Check the record once you have published it.

Leave the selector blank and we will probe the selectors that common providers use.

SendGrid official documentation