Blog · Spf

Why Brevo SPF Causes Permerror at Yahoo and How to Fix It

When you send transactional email through Brevo using your own domain, Yahoo rejects it. The error says SPF permerror. You added Brevo to your SPF record. You checked it twice. The rejection persists.

There are two separate problems here. Most articles address only the first. This article covers both.

---

What SPF Permerror Actually Means

SPF tells receiving mail servers which IP addresses are allowed to send email for your domain. When a server receives an email, it checks the envelope sender (RFC5321 MailFrom), not the From header a reader sees.

A permerror is not a simple SPF fail. It means the receiving server could not evaluate your SPF record at all, usually because of malformed syntax or exceeding the 10-DNS-lookup limit. For Brevo users, the most common cause is adding Brevo to an SPF record that already has too many includes, pushing it over the lookup ceiling.

The distinction matters: a softfail (~all) marks unauthorized email as suspicious. A permerror tells the receiver your SPF record is broken. Strict receivers like Yahoo do not retry permerror results. They reject the message.

---

The Root Cause: Brevo Sends from Its Own Infrastructure

Brevo does not relay email through your mail servers. Brevo sends from its own IP pool, using its own SMTP infrastructure. In the SMTP envelope, the MailFrom domain is set by Brevo's system, not by you.

Here is the practical consequence:

  • Your domain is yourdomain.com
  • You want Brevo to send password resets and receipts from noreply@yourdomain.com
  • Brevo sends from IPs in Brevo's infrastructure
  • The envelope sender (the address Yahoo checks SPF against) is set by Brevo, not by you

When Yahoo receives the email, it checks SPF against the envelope sender domain. If your SPF record does not include Brevo, SPF fails. If adding Brevo pushed your SPF record over 10 DNS lookups, SPF permerrors.

The From header (what the recipient sees) shows yourdomain.com. The SPF check targets a different domain. This mismatch is where most Brevo SPF problems start.

---

The Hidden Problem: DKIM Alignment

Even with correct SPF, you may still see DMARC failures. The reason is DKIM alignment, and Brevo's default configuration makes this easy to overlook.

By default, Brevo DKIM signs outgoing email using Brevo's own domain as the signing domain, typically sendinblue.com. When your From header shows yourdomain.com but the DKIM signature is from sendinblue.com, those two domains do not match.

DMARC requires at least one of SPF or DKIM to pass alignment. Alignment means the domain in the DKIM signature must match the domain in the RFC5322 From header. When they differ, DKIM alignment fails.

For DMARC p=reject domains, this means your legitimate Brevo email gets rejected even when SPF passes. Most Brevo setup guides mention SPF but skip DKIM alignment entirely, which is why this failure mode is so common and so frustrating when it happens.

---

How to Fix Brevo SPF and DKIM for Reliable Delivery

Step 1: Add Brevo to Your SPF Record

Open your DNS and find your SPF TXT record. If you do not have one yet:


v=spf1 include:sendinblue.com ~all

If you already have an SPF record, insert Brevo's include:


v=spf1 include:_spf.google.com include:sendinblue.com ~all

The ~all tag means softfail. Switch to -all only after you have confirmed everything works. Switching to -all prematurely rejects legitimate email during testing.

Before adding Brevo, count your current SPF includes. Each include counts as one DNS lookup. SPF allows a maximum of 10 per record. If you have four or five includes already, adding Brevo may push you over the limit. An SPF lookup counter tool tells you your current count in seconds.

Step 2: Configure Brevo DKIM for Your Domain

Brevo DKIM is not enabled for your custom domain by default. You must configure it in the Brevo dashboard.

Go to Settings > Sender & IP > Configure DKIM. You will see two DNS records to add to your domain. Publish both as TXT records for your sending domain.

After adding the records, send a test email and check the raw headers. Look for the DKIM-Signature header and its d= tag. It should show yourdomain.com (or your subdomain), not sendinblue.com.

This is the step most Brevo guides skip. Without it, DMARC p=reject domains reject your Brevo email even when SPF passes.

Step 3: Isolate Brevo to a Dedicated Subdomain (Recommended)

Keep Brevo separate from your primary domain by using a subdomain:


emails.yourdomain.com

Set this as your default sending domain in Brevo. Add the Brevo DKIM records to this subdomain, not your main domain. Give the subdomain its own SPF record:


v=spf1 include:sendinblue.com ~all

This approach has two advantages. First, Brevo cannot damage your main domain's sending reputation. Second, your DMARC aggregate reports show Brevo traffic as a distinct sending source, making it easier to monitor and troubleshoot.

Step 4: Verify Before Switching to p=reject

Send a test email to a Yahoo address and check the full headers. Look for Authentication-Results and confirm:

  • SPF: pass
  • DKIM: pass, with d=yourdomain.com or d=emails.yourdomain.com
  • DMARC: pass

If SPF shows permerror, your record is malformed or over the lookup limit. If DKIM shows d=sendinblue.com, your DKIM configuration is not yet signing with your domain.

Use DMARCFlow to monitor your aggregate DMARC reports during this verification phase. DMARCFlow shows DKIM alignment results per sending source. When Brevo is configured correctly, you see Brevo-sent email passing alignment. If alignment fails, you see exactly which email source is failing and why.

Set up a DMARCFlow alert for new authentication failure patterns. If Brevo adds new sending infrastructure and your SPF record does not cover it, you want to know within hours, not days. Brevo occasionally updates its IP ranges without notice, and a stale SPF record causes immediate permerrors at strict receivers.

Before changing your domain policy from p=quarantine to p=reject, confirm in your DMARC reports that Brevo DKIM alignment is passing. Rejecting before you have confirmed alignment means your own transactional email gets blocked.

---

Why Yahoo Rejects Before Gmail Does

Yahoo is among the strictest major receivers. Yahoo enforces SPF, DKIM, and DMARC in its rejection pipeline and does not route unauthenticated email to spam first.

When Yahoo sees SPF permerror for yourdomain.com, it rejects the message. It does not retry. It does not deliver to spam. The rejection goes to the envelope sender, which is Brevo's system in most cases.

Gmail and Outlook are also strict, but they sometimes route unauthenticated email to spam rather than rejecting it outright. This makes Yahoo a useful test case. If your Brevo setup passes Yahoo, it passes most other receivers.

Yahoo also maintains a feedback loop that reports permerrors specifically. A domain that accumulates permerrors may be rate-limited or blocked entirely, regardless of whether the underlying SPF record is eventually fixed.

---

FAQ

Does Brevo work with custom domains?
Yes. Brevo supports sending from your own domain. You must add Brevo to your SPF record and configure DKIM to sign with your domain. Without both, your email is unlikely to deliver to strict receivers like Yahoo and Gmail.

How do I add Brevo to my SPF record?
Add include:sendinblue.com to your existing SPF TXT record. If you do not have an SPF record, create one: v=spf1 include:sendinblue.com ~all. Save it in your DNS and wait for propagation before testing.

Why do my Brevo emails go to spam at Yahoo?
Yahoo places unauthenticated email in spam rather than rejecting it in some cases. If your SPF or DKIM is not configured, Yahoo treats Brevo-sent email as unauthenticated and filters it accordingly. Fix SPF and DKIM first, then check postmaster tools for any reputation issues.

What is DKIM alignment and why does it matter for Brevo?
DKIM alignment means the domain in the DKIM signature must match the domain in the email From header. Brevo's default DKIM setup signs with sendinblue.com, not yourdomain.com, so alignment fails. Configure Brevo DKIM to sign with your domain. Without this, DMARC p=reject policy blocks your legitimate Brevo email.

How do I verify Brevo DKIM is working?
Send a test email and inspect the raw headers. Find the DKIM-Signature header and check the d= tag. It should show yourdomain.com or your subdomain, not sendinblue.com. Use DMARCFlow to monitor aggregate DMARC reports and confirm alignment is passing for Brevo-sent email.

---

How DMARCFlow Helps You Keep Brevo Email Authenticating Correctly

Configuring Brevo SPF and DKIM correctly is the first step. Keeping it configured correctly over time is where ongoing monitoring matters.

Brevo may update its sending infrastructure, add new IP addresses, or change DKIM keys without advance notice. These changes can silently break your authentication. The first sign of a problem is usually a customer reporting missing emails, not an alert from Brevo.

DMARCFlow processes your DMARC aggregate reports and shows DKIM alignment results for each sending source. When Brevo is sending authenticated email correctly, your reports show Brevo passing alignment. When something changes on Brevo's end, your reports show the resulting alignment failures immediately.

The specific data DMARCFlow provides that matters here: DKIM alignment pass/fail per source, SPF and DKIM result breakdowns, and alerting when a previously passing source starts failing. Before you switch your domain to p=reject, DMARCFlow confirms that Brevo is passing DKIM alignment in practice, not just in theory.