Connect SendGrid to SiteOps

Billions of messages a day move through SendGrid, Twilio's email arm — a battle-tested pipe that does not blink when your list grows. You prove you own a domain once, create a key, and email goes out at whatever volume you need.

Plugged into SiteOps, that pipe becomes your email channel's exit: approve a scheduled email and SendGrid carries it out from your own domain, then the sent, opened and clicked counts flow back next to your other channels.

Two things make this guide worth reading rather than skimming. First, the key: SendGrid lets you create keys with Restricted Access, and the one you make here gets exactly one permission — Mail Send. It cannot read your contacts, change your account or see anything else. Second, sender identity: SendGrid offers a quick single-sender verification and a proper domain authentication. The quick one gets you started; the DNS one is what keeps you out of spam — and there is an agent prompt below to paste the records for you.

The CNAME set SendGrid asks for — DKIM and return path, delegated

Set it up, step by step

0 of 9 done

    1. Settings
    2. Sender Authentication
    3. Authenticate Your Domain
    1. Settings
    2. API Keys
    3. Create API Key
  1. A key that can send mail — and do nothing else
    1. Settings
    2. SendGrid
    3. Save

Let an agent do it

An agent with access to your DNS can add SendGrid's domain authentication CNAME records for you.

Prompt for your agent
Add the SendGrid domain authentication records to my DNS.

1. I started Authenticate Your Domain for <my sending domain> under Settings, Sender Authentication in SendGrid, and it lists a set of CNAME records (hosts like em1234, s1._domainkey and s2._domainkey). Here they are exactly as displayed: <each record: type, host, value>.
2. Open the DNS zone for the domain at <my DNS host, e.g. Cloudflare or the registrar> and add each record with the exact type, host and value. Watch for the host trap: if the DNS host auto-appends the domain, enter only the prefix (for example s1._domainkey), so the host does not end up doubled. If the DNS host is Cloudflare, set these records to DNS only — proxying breaks CNAME verification.
3. Check each record resolves: dig CNAME <host> +short for every entry.
4. Tell me when they resolve so I can press Verify in SendGrid.

Creating the SendGrid account, creating the restricted API key and pasting it into SiteOps stay with you.

If something does not work

Links in my emails are broken or point at a strange domain
That is SendGrid's click tracking: it rewrites every link through its tracking domain to count clicks, and on a fresh account the rewritten links can trip strict inboxes or scare readers. Two fixes: set up link branding under Settings, Sender Authentication (a couple more CNAMEs, so rewritten links use your own domain), or switch click tracking off under Settings, Tracking — you lose click counts but links stay untouched.
The domain is stuck on not verified
Compare each CNAME in your DNS against what SendGrid shows — type, host and value must match exactly, and some registrars append your domain to the host on their own. On Cloudflare, make sure the records are DNS only, not proxied — the orange cloud breaks CNAME checks. Fixed records can still take a few hours; press Verify again after a break.
The key saved but my emails still sit as drafts
The from address is the missing half. Open the Email section in SiteOps settings and set the sender name and address — on the domain you authenticated. The draft's note says exactly which half the gate is waiting on.
SendGrid rejected my send with a sender identity error
The from address is not covered by a verified identity. Either finish domain authentication for the domain the address is on, or — as a stopgap — add that exact address under Single Sender Verification and confirm the email SendGrid sends it.
I chose Full Access for the key — is that a problem?
It works, but it grants far more than SiteOps needs — a full-access key can read contacts and change account settings if it ever leaks. Better: delete it on the API Keys page and make a Restricted Access key with only Mail Send, then paste the new one into SiteOps.
I connected SendGrid and another email provider — which one sends?
The one named in the 'Sends go through' picker in SiteOps Settings — an explicit choice, not a guess. Several providers can stay connected at once; only the picked one sends, and you can switch it in the Email section any time.

Set up once, see everything every morning

Get started