Drip SPF and DKIM setup
The three CNAME records behind a Drip Custom Sending Domain, why Drip never hands you an SPF include, and the s1/s2 selector clash that stops the records verifying.
What you are setting up
Drip sends your ecommerce marketing email. Out of the box it sends from its own infrastructure and your mail arrives marked “via Drip.com”, which is a DMARC failure waiting to happen: Drip’s own docs say that with DMARC in place, every message sent without a Custom Sending Domain will fail your policy. The fix is to verify that Custom Sending Domain, which is three CNAME records. Drip generates them for your account, and they do not change for as long as you send with Drip.
Publish SPF and DKIM
In Drip, go to Settings > Email Setup, click Sending Domain, then Change Sending Domain. Choose the domain you want to send from and click Next. Drip shows you three CNAME records; add them at your DNS host exactly as shown:
Type: CNAME Host: drip Value: (the target Drip shows you) Type: CNAME Host: s1._domainkey Value: (the target Drip shows you) Type: CNAME Host: s2._domainkey Value: (the target Drip shows you)
There is no SPF TXT record in this setup, and Drip does not give you an include: to paste. The two _domainkey CNAMEs delegate the DKIM selectors s1 and s2 to Drip, so Drip hosts and rotates the keys and signs as your domain. That DKIM signature is what aligns your Drip mail under DMARC. Once the records are in, click I’ve added these records and Drip checks for them. Allow up to 24 to 48 hours for the CNAMEs to propagate.
Two DNS-host quirks Drip calls out: some hosts want a trailing period on the name (drip. instead of drip), and some want the full name (drip.yoursite.com, s1._domainkey.yoursite.com, s2._domainkey.yoursite.com). On Cloudflare, set all three records to DNS-only (gray cloud); they carry no web traffic and a proxied CNAME will not verify.
Add DMARC
Standard _dmarc TXT record, nothing Drip-specific. Start in monitor-only mode and ramp up:
Type: TXT Host: _dmarc Value: v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com
Build it with our DMARC builder and progress past p=none once your reports are clean. Do not publish DMARC before the Custom Sending Domain verifies; until then, every Drip send fails the check.
The Drip gotcha
The s1 and s2 selectors may already be taken. Drip uses s1._domainkey and s2._domainkey, the same names Twilio SendGrid and several other senders use. If those CNAMEs already exist on your domain, you cannot add a second one at the same name, and Drip’s verification will never go green. Drip’s answer is to contact support@drip.com and ask for custom CNAME records for your account. The same route covers hosts that reject underscores in CNAME names or lock built-in CNAMEs: support can issue an MX plus two TXT alternative instead (set the MX priority to 0 or 1). Two smaller ones: only one Drip account can verify a given domain unless support links the accounts on their end, and accounts created after July 31, 2023 must also verify each from address, which needs to sit on the verified domain.
Confirm it worked
- Check the byline. Send a campaign to yourself as the only recipient. The from address should show plainly with no “via” tag; if you still see “via dripemail2.com”, one of the three records is not resolving.
- Read the headers. Open the test message and confirm the DKIM signature shows
d=yourdomain.comwith selectors1ors2, anddmarc=pass. Our header analyzer reads it back plainly. - Watch the reports. Drip should appear as an aligned, passing source in your DMARC aggregate reports, labeled as a known sender in trustyourinbox.
Connect your DNS once and we publish the Drip records above in a single click, with a five-minute window to undo. Then we keep watching this sender in your DMARC reports and tell you the moment Drip mail starts failing, so a typo in a record never quietly costs you the inbox.
Keep reading
Run a free DMARC audit
Paste your domain and see your published SPF, DKIM, and DMARC in plain English.
DMARC alignment, in plain English
Why the s1 and s2 DKIM signatures are what align your Drip mail to your domain.
DKIM record checker
Confirm s1._domainkey and s2._domainkey resolve through the CNAME to a live key.
Twilio SendGrid SPF and DKIM setup
The same s1/s2 CNAME pattern, and the vendor most likely to already own those names.
Last verified 2026-08-30 against the official Drip documentation.
Was this page helpful?
Free for one domain. Set up in five minutes. We parse the reports; you read plain-English summaries.