Guide

Email deliverability for ActiveCampaign: keep your campaigns out of spam

ActiveCampaign sends both marketing campaigns and transactional emails (cart abandonment, welcome series, automated follow-ups). If these land in the spam folder, you lose engagement and revenue. The fix is usually a DNS record, not an email app.

Why ActiveCampaign email goes to spam

ActiveCampaign sends email on your behalf using your domain (or a subdomain you set up). But the receiving mail server does not trust your domain by default. It checks your DNS records to verify the email is legitimate.

When a subscriber receives an email from yourdomain.com sent by ActiveCampaign, Gmail and Outlook check your domain's DNS records. If the records are missing or misconfigured, the email gets flagged as suspicious and filtered to spam.

The frustrating part: ActiveCampaign's dashboard shows "delivered." The email reached the mail server. It just did not reach the inbox. You have zero opens and no idea why.

The 6 records that decide delivery

Here is what the receiving mail server checks, in order:

  1. MX record: tells the mail server where to deliver mail for your domain. If this is missing, email bounces immediately.
  2. SPF record: lists the IP addresses and services allowed to send email as your domain. If ActiveCampaign is not listed, the email fails SPF.
  3. DKIM record: a cryptographic signature that proves the email was not tampered with in transit. If the signature is broken or missing, the email fails DKIM.
  4. DMARC record: tells the receiving server what to do when SPF or DKIM fails. Without a DMARC record, Gmail and Outlook apply their own (stricter) policy.
  5. TLS/STARTTLS: encrypts the email in transit. If your mail server does not support TLS, some providers downgrade or reject the email.
  6. PTR / reverse DNS: maps the sending IP back to a hostname. If the PTR does not match the sending server, the email gets flagged.

Any one of these can break your deliverability. Most ActiveCampaign users have at least one missing or misconfigured.

How to check your ActiveCampaign domain in 30 seconds

You do not need to run dig commands by hand. Inboxproof checks all 6 records in about 30 seconds. You type in your domain, it queries your live DNS, and gives you a score plus the exact records to fix. No account, no setup, nothing to install.

The report is public and shareable, which is handy when you need to send the findings to whoever manages your DNS (your developer, your agency, your ActiveCampaign setup).

The ActiveCampaign-specific gotchas

1. You are using a different domain for email

Many ActiveCampaign users use a custom domain for their website but send email from a different domain (e.g., yourdomain.com for the site, yourdomain-mail.com for email). The receiving server checks the domain in the From: header, not the domain in the URL. If your From: header says yourdomain.com but your SPF record is on yourdomain-mail.com, the email fails SPF.

Fix: make sure the domain in your From: header matches the domain with the SPF, DKIM, and DMARC records.

2. Your SPF record does not include ActiveCampaign

ActiveCampaign uses a specific domain include for SPF. If your SPF record does not include include:activecampaign.com (or the specific ActiveCampaign sending domain you are using), the email fails SPF. Check your ActiveCampaign sending settings to find the exact include you need.

Fix: add the ActiveCampaign include to your SPF record. If you have multiple includes, make sure the total SPF lookup count stays under 10.

3. Your DKIM record is missing or the selector is wrong

ActiveCampaign uses a specific DKIM selector. If your DKIM record is missing or the selector does not match what ActiveCampaign expects, the email fails DKIM. Check your ActiveCampaign sending settings for the current DKIM selector and make sure it is in your DNS.

Fix: add the DKIM record with the correct selector to your DNS. The record type is TXT, and the name is the selector followed by a dot and your domain.

4. Your DMARC record is missing or set to p=none

Gmail has been enforcing DMARC more strictly since early 2024. A domain with no DMARC record, or one set to p=none, is treated as unauthenticated. Gmail filters these emails more aggressively. Set your DMARC record to at least p=quarantine, and ideally p=reject once you are confident your SPF and DKIM are correct.

Fix: add a DMARC record with p=quarantine or p=reject to your DNS. Start with p=quarantine, monitor your DMARC reports, and move to p=reject once you are confident.

5. You have multiple sending domains

If you use ActiveCampaign for marketing email and a different provider for transactional email (e.g., Postmark for order confirmations), both need to be in your SPF record. Missing one means emails from that provider fail SPF. Check every service that sends email on your behalf.

Fix: make sure all sending services are included in your SPF record. If you have more than 10 includes, consider using a separate domain for one of the services.

How to monitor so a broken record never costs you a sale

Fixing the records is the first step. But records break. Your email provider changes something. Your DNS provider expires a record. A new include gets added. You do not get an email when this happens. You find out when a subscriber says "I never got the welcome email."

Inboxproof Pro monitors all 6 records daily and emails you the moment one breaks, expires, or changes. $29/month for up to 5 domains. For an agency managing multiple clients, the Agency plan covers up to 25 domains for $99/month.

Quick checklist

If any of these are missing, run a free audit and get the exact record values to add. Takes 30 seconds. No account needed.

Related guides

Check your ActiveCampaign domain now

Run a free 30 second audit on your domain. No account, no setup, reads your live DNS only.

Run my free audit

Audited by Inboxproof · live DNS checks · privacy