---
title: "Mandrill SPF & DKIM Configuration: A Complete Step-by-Step Guide by AutoSPF"
description: "Mandrill SPF &#38; DKIM Configuration: A Complete Step-by-Step Guide by AutoSPF explains SPF record management, sender authentication, troubleshooting steps,."
image: "https://autospf.com/og/blog/mandrill-spf-dkim-configuration-complete-step-by-step-guide-autospf.png"
canonical: "https://autospf.com/blog/mandrill-spf-dkim-configuration-complete-step-by-step-guide-autospf/"
---

Quick Answer

Email deliverability is no longer optional - it’s foundational. If you’re using Mandrill by Mailchimp to send transactional emails, properly configuring SPF and DKIM is one of the most important steps you can take to protect your domain, improve inbox placement, and prevent spoofing.

## Try Our Free DKIM Lookup

Auto-discover DKIM selectors for any domain.

[ Discover DKIM Selectors → ](/tools/dkim-lookup/) 

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fautospf.com%2Fblog%2Fmandrill-spf-dkim-configuration-complete-step-by-step-guide-autospf%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Mandrill%20SPF%20%26%20DKIM%20Configuration%3A%20A%20Complete%20Step-by-Step%20Guide%20by%20AutoSPF&url=https%3A%2F%2Fautospf.com%2Fblog%2Fmandrill-spf-dkim-configuration-complete-step-by-step-guide-autospf%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fautospf.com%2Fblog%2Fmandrill-spf-dkim-configuration-complete-step-by-step-guide-autospf%2F "Share on Facebook") [ ](https://reddit.com/submit?url=https%3A%2F%2Fautospf.com%2Fblog%2Fmandrill-spf-dkim-configuration-complete-step-by-step-guide-autospf%2F&title=Mandrill%20SPF%20%26%20DKIM%20Configuration%3A%20A%20Complete%20Step-by-Step%20Guide%20by%20AutoSPF "Share on Reddit") [ ](mailto:?subject=Mandrill%20SPF%20%26%20DKIM%20Configuration%3A%20A%20Complete%20Step-by-Step%20Guide%20by%20AutoSPF&body=Check out this article: https%3A%2F%2Fautospf.com%2Fblog%2Fmandrill-spf-dkim-configuration-complete-step-by-step-guide-autospf%2F "Share via Email") 

![SPF & DKIM Configuration](https://media.mailhop.org/autospf/images/2025/12/spf-permerror-5331.jpg) 

Email deliverability is no longer optional - it’s foundational. If you’re using Mandrill by Mailchimp to send transactional emails, properly configuring SPF and DKIM is one of the most important steps you can take to protect your domain, improve inbox placement, and prevent spoofing.

_DKIM ([RFC 6376](https://datatracker.ietf.org/doc/html/rfc6376)) signs email messages cryptographically, and unlike SPF, the signature survives email forwarding - which is why DMARC alignment via DKIM is more reliable than SPF alignment for forwarded mail and mailing lists._

_At AutoSPF, we see countless domains struggle with delivery issues simply because SPF and DKIM were misunderstood, misconfigured, or partially implemented_. This guide walks you through Mandrill SPF and DKIM setup step by step, explains _why each step matters_, and highlights common mistakes that quietly damage email performance.

Whether you’re setting up Mandrill for the first time or auditing an existing configuration, this guide will help you do it the right way.

## Why SPF and DKIM Matter for Mandrill Email Sending

Before jumping into configuration, it’s important to understand what SPF and DKIM actually do and why Mandrill depends on them.

### SPF: Proving Who Is Allowed to Send

[Sender Policy Framework (SPF)](/blog/what-is-spf-email-a-guide-to-sender-validation-technology/) tells receiving [mail servers](https://www.techtarget.com/whatis/definition/mail-server-mail-transfer-transport-agent-MTA-mail-router-Internet-mailer) which IP addresses and services are authorized to send email on behalf of your domain.

_When Mandrill sends an email using your domain in the “From” address, the receiving server checks_:

- Does this IP appear in the domain’s SPF record?
- If yes → SPF passes
- If no → SPF fails or soft-fails

Without SPF, your emails are far more likely to be:

- [Marked as spam](https://www.malwarebytes.com/blog/news/2025/11/phishing-emails-disguised-as-spam-filter-alerts-are-stealing-logins)
- Rejected outright
- Flagged as spoofed

### DKIM: Proving the Email Wasn’t Altered

_DomainKeys Identified Mail (DKIM) adds a cryptographic signature to every outgoing message_. This signature allows inbox providers to verify:

- The email was authorized by your domain
- _The message content hasn’t been modified in transit_
![Email delivery](https://media.mailhop.org/autospf/images/2025/12/spf-syntax-5214.jpg) 

Mandrill signs messages with DKIM automatically - but only if you publish the correct DKIM records in DNS.

### Why Mandrill Requires Both

_Modern inbox providers (Gmail, Outlook, Yahoo) expect SPF and DKIM alignment, especially when DMARC is in place_. Missing either one dramatically increases the risk of delivery failure.

## What You Need Before Starting

Before configuring SPF and DKIM for Mandrill, make sure you have:

- Access to your domain’s DNS provider
- An active [Mandrill account](https://docs.comify.io/channels/email/providers/mandrill)
- A verified sending domain
- Basic understanding of [DNS records](/blog/how-does-spf-flattening-simplify-dns-records/) (TXT and CNAME)

If DNS access is handled by a third party (hosting provider, IT team, or registrar), coordinate with them before proceeding.

## Step 1: Add Mandrill to Your SPF Record

### What Is Mandrill’s SPF Requirement?

_Mandrill sends email from shared IP infrastructure. To authorize Mandrill, you must include its SPF mechanism in your domain’s SPF record_.

Mandrill’s SPF include value is:

```
include:spf.mandrillapp.com
```

### Locate Your Existing SPF Record

Most domains already have an SPF record. It looks like this:

```
v=spf1 ip4:192.0.2.10 include:_spf.google.com ~all
```

Partial Important: You must never create multiple SPF records.Only one SPF record is allowed per domain.

### Update the SPF Record to Include Mandrill

Add Mandrill’s include mechanism before thealltag:

```
v=spf1 ip4:192.0.2.10 include:_spf.google.com include:spf.mandrillapp.com ~all
```

If Mandrill is the only service sending email for your domain, your SPF record may be as simple as:

```
v=spf1 include:spf.mandrillapp.com ~all
```

### Publish the Updated SPF Record

Save the updated TXT record in DNS. SPF changes typically propagate within minutes, but can take up to 48 hours depending on your DNS provider.

![Email verification](https://media.mailhop.org/autospf/images/2025/12/spf-lookup-5412.jpg) 

## Step 2: Verify SPF Is Working Correctly

After publishing the record, verify that:

- There is only one SPF record
- The record starts with v=spf1
- Mandrill is included
- The record does not exceed the 10 DNS lookup limit

At AutoSPF, we frequently see Mandrill SPF failures caused by:

- Nested includes pushing DNS lookups beyond 10
- _Duplicate SPF records created by mistake_
- Incorrect placement of the all mechanism

If your SPF record is already complex, consider [SPF flattening](/blog/what-is-spf-flattening-and-why-is-it-important/) to avoid future failures.

## Step 3: Set Up DKIM for Mandrill

SPF alone is not enough. DKIM is critical for authentication and alignment.

### Add a Sending Domain in Mandrill

1. Log in to your Mandrill dashboard
2. Navigate to Settings → Sending Domains
3. Click Add a Domain
4. Enter the domain you send email from (e.g., example.com)

Mandrill will generate DKIM DNS records for you.

## Step 4: Publish Mandrill DKIM Records in DNS

Mandrill provides two DKIM CNAME records per domain.

They look similar to this:

```
mandrill._domainkey.example.com → dkim.mandrillapp.com

mandrill2._domainkey.example.com → dkim2.mandrillapp.com
```

### How to Add the DKIM Records

At your DNS provider:

- Create [CNAME records](https://support.dnsimple.com/articles/cname-record/)
- Use the exact hostnames provided by Mandrill
- Do not modify or shorten them
- Do not use TXT records for Mandrill DKIM

Once added, save the changes.

![SPF Tool](https://media.mailhop.org/autospf/images/2025/12/how-to-create-spf-record-3041.jpg) 

## Step 5: Verify DKIM Status in Mandrill

After DNS propagation:

1. Return to Mandrill’s Sending Domains page
2. Click Test [DNS Settings](https://www.ntchosting.com/encyclopedia/dns/settings/)

If configured correctly, Mandrill will display:

- DKIM: Valid
- SPF: Valid

If DKIM fails, common causes include:

- Typo in CNAME hostnames
- Using TXT instead of CNAME
- DNS provider automatically appending the domain twice

## Step 6: Understand SPF and DKIM Alignment with DMARC

If your domain has a DMARC policy, alignment becomes critical.

### How Alignment Works

- SPF alignment checks the Return-Path domain
- DKIM alignment checks the d= domain in the [DKIM signature](https://docs.mapp.com/docs/dkim-signature)

Mandrill supports DKIM alignment automatically when configured correctly, which is why DKIM is often more reliable than SPF for transactional email.

For domains enforcing p=quarantine or p=reject, DKIM alignment is essential.

## What Are Common Mandrill SPF & DKIM Mistakes We See at AutoSPF?

### 1\. Multiple SPF Records

This is the most common and most damaging mistake. Multiple SPF records cause permanent SPF failure.

### 2\. Exceeding the 10 DNS Lookup Limit

_Mandrill + Google Workspace + marketing tools often exceed SPF limits silently_.

### 3\. Missing DKIM Records

Some senders rely on SPF alone, which is no longer sufficient for modern inbox filtering.

### 4\. Incorrect DKIM Record Type

Mandrill requires CNAME DKIM records, not TXT.

### 5\. Assuming Setup Is “One and Done”

[Email infrastructure](https://www.zoho.com/workplace/articles/email-infrastructure.html) evolves. SPF and DKIM must be reviewed whenever:

- A new email service is added
- An old service is removed
- DMARC policies are tightened
![Email infrastructure](https://media.mailhop.org/autospf/images/2025/12/sender-policy-framework-office-365-5632.jpg) 

## How AutoSPF Simplifies Mandrill SPF Management

SPF issues often don’t appear until emails start failing - and by then, reputation damage may already be done.

AutoSPF helps by:

- Automatically flattening SPF records
- Keeping DNS lookups under the 10-limit
- Monitoring changes in included services
- Preventing accidental SPF breaks
- Ensuring Mandrill stays authorized at all times

Instead of manually editing complex SPF records, [AutoSPF](/) keeps your domain stable and compliant as your email stack grows.

## How Email Authentication Affects Deliverability Over Time

Setting SPF and DKIM once isn’t enough - deliverability is dynamic.

### Changes in Your Email Stack

As you integrate:

- Marketing platforms
- [CRM systems](https://www.zoho.com/crm/what-is-crm.html)
- Support tools
- Event-based triggers

Your SPF record grows. You might unknowingly:

- Add third-party includes
- Exceed DNS lookup limits
- Break SPF syntax

AutoSPF mitigates this by flattening and optimizing SPF in real time.

### Ongoing DKIM Rotation

Mandrill [rotates keys](https://www.ibm.com/docs/en/ukofc/3.1.0?topic=understanding-key-rotation) periodically. If DNS CNAMEs are removed or changed without updating Mandrill, signatures will fail and delivery drops.

Regular monitoring ensures continuity.

## Topics

[ DKIM ](/tags/dkim/)[ DKIM record ](/tags/dkim-record/)[ DMARC ](/tags/dmarc/)[ SPF ](/tags/spf/)[ SPF record ](/tags/spf-record/) 

![Vishal Lamba](https://media.mailhop.org/autospf/images/authors/vishal-lamba.jpg) 

[ Vishal Lamba ](/authors/vishal-lamba/) 

Content Specialist

Content Specialist at AutoSPF. Writes vendor-specific SPF configuration guides and troubleshooting walkthroughs.

[LinkedIn Profile →](https://www.linkedin.com/in/vishal-lamba/) 

## Ready to get started?

Try AutoSPF free — no credit card required.

[ Book a Demo ](/book-a-demo/) 

## Related Articles

[  Foundational 8m  AWeber SPF & DKIM Setup - A Guide by AutoSPF  Nov 27, 2025 ](/blog/aweber-spf-dkim-setup-a-guide-by-autospf/)[  Foundational 8m  Email security protocols that must be a part of your security strategy  Feb 11, 2025 ](/blog/email-security-protocols-essential-for-your-security-strategy/)[  Foundational 4m  What is a DNS TXT record?  Feb 27, 2025 ](/blog/what-is-a-dns-txt-record/)[  Foundational 12m  Common SPF Record Examples and How to Implement Them Correctly  Jan 2, 2026 ](/blog/common-spf-record-examples-and-how-to-implement-them-correctly/)

```json
{"@context":"https://schema.org","@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com","logo":{"@type":"ImageObject","url":"https://autospf.com/images/autospf-logo.png"},"description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138897474","https://www.linkedin.com/company/autospf","https://x.com/autospf01","https://www.g2.com/products/autospf/reviews"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://autospf.com/contact-us/"},"knowsAbout":["SPF Record Flattening","Sender Policy Framework","Email Authentication","DNS Management","DMARC","DKIM"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"AutoSPF","url":"https://autospf.com","description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","publisher":{"@type":"Organization","name":"AutoSPF","url":"https://autospf.com","logo":{"@type":"ImageObject","url":"https://autospf.com/images/autospf-logo.png"},"description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Mandrill SPF & DKIM Configuration: A Complete Step-by-Step Guide by AutoSPF","description":"Mandrill SPF & DKIM Configuration: A Complete Step-by-Step Guide by AutoSPF explains SPF record management, sender authentication, troubleshooting steps,.","url":"https://autospf.com/blog/mandrill-spf-dkim-configuration-complete-step-by-step-guide-autospf/","datePublished":"2025-12-27T20:54:29.000Z","dateModified":"2026-04-18T02:36:41.000Z","dateCreated":"2025-12-27T20:54:29.000Z","author":{"@type":"Person","@id":"https://autospf.com/authors/vishal-lamba/#person","name":"Vishal Lamba","url":"https://autospf.com/authors/vishal-lamba/","jobTitle":"Content Specialist","description":"Vishal Lamba writes AutoSPF's how-to guides and vendor-specific configuration walkthroughs. His work focuses on step-by-step implementation guides for major email platforms (Google Workspace, Microsoft 365, SendGrid, Mimecast, Proofpoint, Brevo, and others), troubleshooting common SPF errors, and translating RFC-level specifications into practical deployment procedures for IT administrators.","image":"https://media.mailhop.org/autospf/images/authors/vishal-lamba.jpg","knowsAbout":["SPF Vendor Configuration","Email Platform Integrations","SPF Troubleshooting","Technical Documentation","Step-by-Step Guides"],"worksFor":{"@type":"Organization","name":"AutoSPF","url":"https://autospf.com"},"sameAs":["https://www.linkedin.com/in/vishal-lamba/"]},"publisher":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com","logo":{"@type":"ImageObject","url":"https://autospf.com/images/autospf-logo.png"},"description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138897474","https://www.linkedin.com/company/autospf","https://x.com/autospf01","https://www.g2.com/products/autospf/reviews"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://autospf.com/contact-us/"},"knowsAbout":["SPF Record Flattening","Sender Policy Framework","Email Authentication","DNS Management","DMARC","DKIM"]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://autospf.com/blog/mandrill-spf-dkim-configuration-complete-step-by-step-guide-autospf/"},"articleSection":"foundational","keywords":"DKIM, DKIM record, DMARC, SPF, SPF record","wordCount":1196,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/autospf/images/2025/12/spf-permerror-5331.jpg","caption":"SPF & DKIM Configuration","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://autospf.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://autospf.com/blog/"},{"@type":"ListItem","position":3,"name":"Foundational","item":"https://autospf.com/foundational/"},{"@type":"ListItem","position":4,"name":"Mandrill SPF & DKIM Configuration: A Complete Step-by-Step Guide by AutoSPF","item":"https://autospf.com/blog/mandrill-spf-dkim-configuration-complete-step-by-step-guide-autospf/"}]}
```
