Email authentication helps email providers verify that messages sent from your domain are legitimate. Proper authentication helps protect your domain from unauthorized use and supports email deliverability.
Authentication applies to the domain used in your send-from email address, not to an individual email address.
For example:
If you send from info@yourbrand.com, you need to authenticate yourbrand.com.
If you also send from team@yourcourses.co, you need to authenticate yourcourses.co.
The authentication you need depends on the email delivery service you use.
If you use KartraMail
When you send email through KartraMail, each domain you use in a send-from address needs to be authenticated with DKIM.
KartraMail handles SPF for its own sending infrastructure, so you don't need to add an SPF record specifically for KartraMail.
You can also add a DMARC record for additional protection and reporting. DMARC is optional but strongly recommended.
To authenticate a domain for KartraMail:
Set up DKIM. Kartra can configure DKIM automatically for supported domain providers. If automatic configuration isn't available, you can add the required DKIM records manually.
Add DMARC if desired. Once your domain is authenticated for sending, you can add a DMARC policy for additional protection and reporting.
If you don't already own a domain to use for your business email address, you can Buy a domain for email authentication.
If you use a third-party email delivery service
If you send email through a third-party email delivery service, you need to authenticate your sending domain for that service.
Third-party email delivery services require SPF, which identifies the services authorized to send email on behalf of your domain. You will also need to meet any other authentication requirements specified by your provider.
Authentication for a third-party delivery service is configured according to that provider's requirements rather than through KartraMail's DKIM setup.
You can also add a DMARC record for additional protection and reporting.
DKIM, SPF, and DMARC explained
DKIM, SPF, and DMARC have different roles in email authentication.
DKIM
DKIM (DomainKeys Identified Mail) helps email providers verify that a message was authorized by the domain it claims to come from.
DKIM is required when you use your own sending domain with KartraMail.
Kartra can configure DKIM automatically when your domain provider is supported. If automatic configuration isn't available, you can add the DKIM records manually through your domain provider.
See Set up DKIM for KartraMail for both setup methods.
SPF
SPF (Sender Policy Framework) identifies which email delivery services are authorized to send email on behalf of your domain.
If you use KartraMail, you don't need to add an SPF record specifically for KartraMail. SPF is handled by KartraMail's sending infrastructure as soon as you configure DKIM.
If you use a third-party email delivery service, you need to configure SPF for that service. The required SPF configuration depends on the provider you use.
If your domain already has an SPF record, don't create a second one. Instead, the authorization required by your email delivery service needs to be included in your existing SPF record.
For the correct SPF value and instructions for configuring it, contact your email delivery provider or refer to their documentation.
DMARC
DMARC (Domain-based Message Authentication, Reporting, and Conformance) works with DKIM and SPF to help protect your domain from unauthorized use.
DMARC lets you define how receiving email providers should handle messages that fail authentication. It can also provide reports showing which services are sending email using your domain, whether your legitimate email is passing authentication, and whether someone may be trying to spoof your domain.
DMARC is optional but strongly recommended for additional protection and reporting.
A DMARC policy can tell receiving email providers to:
Monitor (p=none): Monitor messages that fail authentication without taking action. This is the recommended starting point if you're new to DMARC.
Quarantine (p=quarantine): Treat messages that fail authentication as suspicious.
Reject (p=reject): Reject messages that fail authentication.
DMARC is added to your domain as a DNS TXT record. You can create and manage the record through your domain provider and use a DMARC monitoring service. A monitoring service can also help you understand the reports generated by DMARC.
If you're unsure which DMARC policy or record values are appropriate for your domain, contact your domain provider.
Why am I seeing an authentication warning?
Kartra may display a warning when you use a sender address whose domain has not been authenticated for the selected email gateway.
If you're using KartraMail, set up DKIM for the sending domain(s) before sending your email.
If you're using a third-party email delivery service, make sure the domain meets the authentication requirements for that service.
Kartra may allow you to continue without completing authentication. However, sending from an unauthenticated domain can significantly affect email delivery and may harm your sender reputation. Completing authentication before sending is strongly recommended.
