beehiiv emails going to spam? Check your domain in 60 seconds.

We verify the SendGrid-powered records beehiiv provisions (s1/s2._domainkey), your DMARC — mandatory for beehiiv custom domains — and the rest of your sending foundation.

Free · no signup · unlimited checks · reads public DNS only

beehiiv sends your newsletter through SendGrid infrastructure, and a custom sending domain means publishing the CNAME records beehiiv generates: DKIM keys at s1._domainkey and s2._domainkey pointing into sendgrid.net, plus a return-path record. Since February 2024, beehiiv also requires a valid DMARC record on every custom domain — a rule that took many publications by surprise.

This checker reads your public DNS and confirms whether those records answer where they should, whether your DMARC exists and what it instructs, and whether your domain sits on any of 24+ blocklists. No signup, and nothing is sent.

How beehiiv setups actually fail

The Cloudflare orange cloud

The single most common beehiiv setup failure: adding the CNAMEs in Cloudflare with proxying on. A proxied CNAME answers with Cloudflare's own addresses, so SendGrid never sees its target and verification fails. The records must be DNS-only (grey cloud). If our check shows s1._domainkey pointing somewhere that isn't sendgrid.net, look here first.

No DMARC on a custom domain

beehiiv requires DMARC for custom domains, and Gmail/Yahoo require it for bulk senders regardless. If we show DMARC missing, publish v=DMARC1; p=none at _dmarc.yourdomain.com today — it's one TXT record.

A conflicting record at the same name

Most DNS providers refuse to serve a CNAME alongside an existing A or TXT record at the same hostname — and some fail silently, keeping the old record. If a beehiiv record won't verify, check whether something else already answers at that exact name.

Fix anything above in your beehiiv dashboard following the official beehiiv setup guide, then re-run the check — DNS changes usually show within minutes.

Record names and provider behavior on this page were last verified against beehiiv's official documentation on 12 July 2026.

Questions, answered plainly

Why is my beehiiv newsletter going to spam?

Usually one of three things: the custom-domain CNAMEs were proxied through Cloudflare (they must be DNS-only), the DMARC record beehiiv requires was never published, or the domain itself has a foundation problem — broken SPF, no MX, or a blocklisting. This checker tests all of them from your domain name alone.

What DNS records does beehiiv need?

For a custom sending domain: the CNAME records beehiiv shows you in Settings — DKIM keys at s1._domainkey and s2._domainkey pointing into sendgrid.net plus a return-path CNAME — and a DMARC TXT record at _dmarc.yourdomain.com. Copy them exactly; don't retype.

Why does beehiiv say my DKIM is not found?

Two frequent causes: the record is proxied (Cloudflare orange cloud — switch it to DNS-only), or DNS hasn't propagated yet, which can take up to 72 hours. beehiiv also evaluates DKIM against real traffic, so a freshly added record may need a few sends before it reports as found.

Do I need my own SPF record for beehiiv?

You don't add beehiiv to your SPF — the provisioned return-path CNAME handles envelope authentication. Your domain should still HAVE a valid SPF record for everything else it sends, which this checker verifies too.

The full guide

beehiiv newsletter going to spam? Look at the orange cloud first

The most common beehiiv delivery failure is a Cloudflare setting, not a missing record. The proxy trap, the DMARC rule beehiiv enforces, and how to verify both in a minute.

Read the guide →

More free checkers

A passing check is a snapshot: records that are right today drift, expire and get overwritten, and nobody gets notified. That slow rot is what we call deliverability decay, and it has its own curriculum in Decay University.

beehiiv spam checker — verify your custom sending domain — Inbox Decay