Email deliverability

The following information is for administrators who configure sending infrastructure to support marketers and email content creators. It describes deliverability features and how to configure subdomains, authentication, and IP pools.

Email deliverability in Adobe Marketo Optimizer is the set of infrastructure and authentication configurations that help email messages reach the recipient’s inbox, not the spam folder, and not blocked by ISPs (Internet Service Providers).

It uses the following building blocks, configured by an administrator, typically in the following order:

  1. Delegate one or more subdomains to Adobe.
  2. Configure DMARC, SPF, and DKIM records on each subdomain.
  3. Confirm the IP pool used to send email for your subdomain.
  4. Create one or more email channel configurations that bind a subdomain, IP pool, and sender identity.

Email deliverability setup for Marketo Optimizer {width="550" modal="regular"}

TIP
Treat deliverability and channel setup as a one-time administrator activity. When configured, marketers and email authors do not need to revisit it.
See the following topics for additional information about email channels:

Current limitations limitations

  • Custom Delegation method for subdomain delegation is not yet available. Use Fully Delegated or CNAME. Custom Delegation is targeted for the GA release.
  • Dedicated IP pools are not available at Beta. The shared IP pool is the only option. Dedicated IPs ship at GA, including IP warmup planning and PTR record management.

Key concepts key-concepts

Before configuring email, review these concepts that apply to email channel deliverability features:

Concept
What it means in Marketo Optimizer
Subdomain
A delegated portion of your sending domain (for example, mail.contoso.com) used to send email through Marketo Optimizer. Subdomains isolate your B2B marketing reputation from corporate or transactional mail.
IP pool
A group of IP addresses associated with one or more subdomains. Marketo Optimizer supports a shared IP pool managed by Adobe in this release; dedicated IP pools are on the GA roadmap.
Channel configuration
A reusable set of email-sending settings (sender identity, reply-to address, subdomain, IP pool, email type, and tracking) that you attach to email actions in journeys. You can have multiple named channel configurations for different brands, business units, or send types.

Subdomain delegation subdomain-delegation

Subdomain delegation tells the internet that Adobe is authorized to send email on behalf of a specific subdomain (for example, mail.contoso.com) of your domain. Delegating a dedicated subdomain — rather than your root domain — protects your corporate mail and provides the following benefits:

  • Reputation isolation. Marketing sends are kept separate from corporate mail. If marketing reputation dips, your transactional and corporate mail are not affected.
  • Faster IP warmup. Dedicated subdomains help establish positive sender reputation more quickly with ISPs.
  • Modern authentication. SPF, DKIM, and DMARC can be set up cleanly per subdomain without affecting other mail flows.
  • Compliance. Helps meet bulk-sender requirements from Gmail, Yahoo, and other major ISPs.
NOTE
Each subdomain in Marketo Optimizer can only be used by one Adobe product. You cannot share the same sending subdomain between Marketo Optimizer and another product such as Adobe Marketo Engage or Adobe Campaign — you must use distinct subdomains.

Supported methods supported-methods

Marketo Optimizer supports two of the three subdomain delegation methods in this Beta release. The third method (Custom Delegation) is on the roadmap.

Method
When to use
What it involves
Fully Delegated
Recommended
Delegate full DNS authority for the subdomain to Adobe. Adobe creates and maintains MX, SPF, DKIM, DMARC, A, and CNAME records. Lowest operational overhead. Adobe handles DNS changes for you.
CNAME
For restricted policies
Keep DNS authority on your side and create CNAME records pointing to Adobe-managed records. Use this when the DNS policy of your organization does not allow full delegation. You are responsible for maintaining DNS records.
Custom Delegation
Roadmap (GA)
Maintain full ownership of DNS and SSL certificates. Provides maximum control, including the ability to use your own certificates. This is targeted for the GA release.

Delegate a subdomain (Fully Delegated method) delegate-fully-delegated

PREREQUISITES
  • Decide on a subdomain naming convention (for example, mail.contoso.com for marketing, alerts.contoso.com for transactional).
  • Confirm with your IT/DNS team that they can delegate the subdomain (NS records) to Adobe.
  • Create the new subdomain in your DNS provider, then wait 24–48 hours for DNS propagation before delegating to Adobe.
  • Confirm you have the Administrator role in Marketo Optimizer.
  1. In the Marketo Optimizer left navigation, expand Administration and select Channels.

  2. In the panel, expand Email settings and select Subdomains.

  3. Click Set up subdomain.

  4. Enter the full subdomain name (for example, mail.contoso.com).

  5. Choose Fully Delegated as the delegation method.

  6. Configure DMARC for the subdomain (see DMARC, SPF, and DKIM).

    At minimum, set up a DMARC record with a starting policy of none so you can monitor reports without affecting delivery.

  7. Review the list of DNS records for Adobe to manage.

    These typically include MX, SPF, DKIM, DMARC, A, and CNAME records (for tracking and mirror-page URLs).

  8. Download the DNS records as a CSV file using the Download records button. Share this file with your DNS team.

  9. Your DNS team adds the NS records in your domain hosting solution that delegate the subdomain to Adobe.

  10. After your DNS team confirms the records are in place, return to Marketo Optimizer and check the box confirming that you have created the required records on the hosting site.

  11. Click Submit to initiate a series of validation checks (pre-validation, MX, SPF, DKIM, DMARC, FBL registration).

  12. Wait for the subdomain status to change to Success.

    This typically takes a few minutes after DNS propagation is complete.

NOTE
If validation fails, the status changes to Failed and Marketo Optimizer displays the reason (for example, NS record not found, MX record missing, or DMARC misconfigured). Fix the underlying DNS issue, then retry submission.

Delegate a subdomain (CNAME method) delegate-cname

Use this method only if the DNS policy of your organization prohibits full delegation. With CNAME, you maintain DNS records on your side.

  1. In the Marketo Optimizer left navigation, expand Administration and select Channels.
  2. In the panel, expand Email settings and select Subdomains.
  3. Click Set up subdomain.
  4. Enter the full subdomain name.
  5. Choose CNAME as the delegation method.
  6. Configure DMARC for the subdomain (DMARC, SPF, and DKIM).
  7. Review the list of CNAME records to generate. These point the components of your subdomain to Adobe-managed records.
  8. Download the records as CSV and share with your DNS team.
  9. Your DNS team adds each CNAME record to your DNS hosting solution.
  10. When records are in place and propagated, return to Marketo Optimizer and confirm.
  11. Click Submit.
  12. Wait for status to reach Success.
IMPORTANT
With CNAME, Adobe cannot help you change, maintain, or troubleshoot DNS for the subdomain. Any future changes, such as adding a new CNAME for a feature update, must be made by your DNS team.

For step-by-step instructions for common DNS providers, review the following sections:

Add CNAME records by DNS provider add-cname-records-dns-provider

Marketo Optimizer generates the exact CNAME and TXT records for your subdomain and lets you download them as a CSV file. Use the following provider-specific steps to help your DNS team locate the correct settings screen and add each record.

NOTE
The host, type, and target values in the downloaded CSV are specific to your subdomain and organization. Copy them exactly rather than reusing values from another subdomain.

AWS Route 53 aws-route-53

  1. Sign in to the AWS Management Console and open Route 53.

  2. Select Hosted zones, then choose the hosted zone for your domain.

  3. Click Create record and keep the routing policy set to Simple routing.

  4. For each row in the CSV:

    • Record name — Enter only the portion before your zone name. For example, for data.mail.contoso.com in the contoso.com zone, enter data.mail.
    • Record type — Choose CNAME or TXT to match the CSV.
    • Value — Paste the target from the CSV. For TXT records, wrap the value in double quotation marks.
    • TTL — 300 seconds is sufficient.
  5. Click Add another record to batch entries, then Create records after all rows are entered.

NOTE
TXT values must be double-quoted, or the record fails validation. A CNAME record cannot sit at the zone apex, but this does not affect a delegated subdomain.

Cloudflare cloudflare

  1. Log in to the Cloudflare dashboard and select your domain.

  2. Go to DNS Records and click Add record.

  3. For each row in the CSV:

    • Type — Choose CNAME or TXT.
    • Name — Enter the host portion, for example data.mail. Cloudflare appends your domain automatically.
    • Target (for CNAME) or Content (for TXT) — Paste the value from the CSV.
    • Proxy status — Set to DNS only (grey cloud icon).
    • TTL — Leave as Auto.
  4. Click Save for each row.

IMPORTANT
Every record you add for Marketo Optimizer must show a grey cloud (DNS only), not an orange cloud (Proxied). A proxied record routes traffic through the servers of Cloudflare instead of Adobe, which breaks DKIM signing, click tracking, and bounce handling. If a record shows orange, click the cloud icon to toggle it to grey.

Azure DNS azure-dns

  1. Sign in to the Azure portal and open DNS zones.

  2. Select the DNS zone for your domain.

  3. Click + Record set.

  4. For each row in the CSV:

    • Name — Enter the host portion, for example data.mail. Azure appends the zone name.
    • Type — Choose CNAME or TXT.
    • For a CNAME record, enter the target from the CSV in the Alias field.
    • For a TXT record, paste the value into the Value field. Azure handles quoting for you.
    • TTL — Enter a number and unit, for example 300 seconds.
  5. Click OK to save the record set for each row.

NOTE
Use a standard CNAME record set, not the Alias record set option, which points only to Azure resources rather than external hostnames. Each CNAME record set holds exactly one target, matching how Marketo Optimizer issues records — one CNAME per host.

Google Cloud DNS google-cloud-dns

  1. Open the Google Cloud console and go to Network Services > Cloud DNS.

  2. Select the zone for your domain.

  3. Click Add standard to add a record set.

  4. For each row in the CSV:

    • DNS name — Enter the host portion, for example data.mail. Cloud DNS shows the zone suffix, and you prepend the host.
    • Resource record type — Choose CNAME or TXT.
    • TTL — 300 seconds is sufficient.
    • For a CNAME record, enter the target in Canonical name and end it with a trailing period.
    • For a TXT record, paste the value into the data field.
  5. Click Create for each row.

NOTE
The canonical name must be fully qualified and end with a trailing period, or resolution fails. Your DNS team can also add each record with the gcloud dns record-sets create command.

Subdomain guardrails subdomain-guardrails

  • Default limit: 10 subdomains per organization. Contact your Adobe representative if you need more (up to 100 depending on contract).
  • DNS propagation: Allow 24–48 hours for changes to propagate globally. Validation can fail simply because DNS has not yet propagated.
  • Subdomain reuse: A subdomain that is already used by another Adobe product (Marketo Engage, Adobe Campaign) cannot be reused in Marketo Optimizer.

DMARC, SPF, and DKIM dmarc-spf-dkim

DMARC, SPF, and DKIM are email authentication standards. Together they prove to receiving mail servers that your message is genuinely sent on behalf of your domain and has not been spoofed. Modern ISPs — Gmail, Yahoo, Microsoft — require these standards for bulk senders.

Record
Stands for
Purpose
SPF
Sender Policy Framework
Lists the mail-server IPs allowed to send mail from your domain. Receiving servers reject mail from IPs not on this list. Adobe creates and maintains the SPF record automatically when you delegate a subdomain (Fully Delegated).
DKIM
DomainKeys Identified Mail
A cryptographic signature added to every outbound email. The receiving server verifies the signature against a public key published in DNS. Adobe automatically generates DKIM keys and DNS records during subdomain delegation.
DMARC
Domain-based Message Authentication, Reporting & Conformance
Tells receiving servers what to do if SPF or DKIM fails — and gives you reports about authentication results. DMARC has three policy modes: none, quarantine, and reject.

DMARC policy modes dmarc-policy-modes

Policy
Action
When to use
none
Monitor
The receiving server does nothing if DMARC fails — but still sends a report. Use this when first delegating a subdomain to confirm authentication is working without risking message loss.
quarantine
Quarantine
The receiving server places failing messages in the spam/junk folder.
reject
Reject
The receiving server rejects (bounces) messages that fail authentication. Strictest mode. Recommended when you are confident in your authentication setup.

Configure DMARC configure-dmarc

DMARC is configured at the time of subdomain delegation, but you can also add or update DMARC for an already-delegated subdomain.

  1. In the Marketo Optimizer left navigation, expand Administration and select Channels.

  2. In the panel, expand Email settings and select Subdomains.

  3. In the Subdomains list, locate your subdomain and check the DMARC Record column.

    If a record is missing, an alert is displayed.

  4. Open the subdomain and scroll to the DMARC record section.

    • If a DMARC record already exists on the parent domain, Marketo Optimizer fetches the values automatically. You can keep them or override.
    • If no record exists, choose Manage with Adobe and Adobe creates and hosts the DMARC record.
  5. Set the policy: none, quarantine, or reject. Start with none unless you already have a mature DMARC posture on your parent domain.

  6. (Optional) Configure additional DMARC tags (sp for subdomain policy, pct for percentage, rua and ruf for report addresses).

  7. If using Fully Delegated, click Save.

    Adobe applies the record automatically. If using CNAME, copy the DNS record and have your DNS team add it, then confirm it in Marketo Optimizer.

  8. Allow up to 48 hours for DNS propagation, then verify that the DMARC status indicator on the subdomain page is green/healthy.

TIP
Begin with policy=none to monitor authentication reports, then progress to quarantine, and finally to reject after your reports show healthy SPF and DKIM alignment. Moving straight to reject without monitoring can cause legitimate mail to be rejected.

IP pools ip-pools

An IP pool is a named group of IP addresses used to send your email. IP pools are critical for sender reputation: each pool has its own reputation with ISPs, so a problem with one pool (for example, a marketing burst that triggers spam complaints) does not contaminate another (for example, transactional confirmations).

Pool types pool-types

Pool type
Availability
Description
Shared IP pool
Available at Beta
A pool of IP addresses managed by Adobe and shared across many customers. Reputation is maintained by Adobe across the pool. Best for low-to-mid email volume and customers who do not want to manage IP warmup.
Dedicated IP pool
Roadmap (GA)
One or more IP addresses allocated exclusively to your organization. You own the reputation. Recommended for high-volume senders. Includes IP warmup planning and PTR record management.

Review and assign an IP pool review-ip-pool

In this release, IP pools are pre-provisioned for your organization. You assign an IP pool when creating an email channel configuration.

  1. In the Marketo Optimizer left navigation, expand Administration and select Channels.
  2. In the panel, expand Email settings and select IP pools.
  3. Confirm that an IP pool with status Active is available for your organization.
  4. Hover over the pool to view the IP addresses and their PTR records (reverse DNS).
  5. If your organization has multiple business units or brands, plan how you will use IP pools (for example, marketing-pool versus webinar-pool) before creating channel configurations.
IMPORTANT
Do not mix marketing and transactional traffic on the same IP pool, even when the shared pool is available. The Email type setting on the channel configuration (Marketing versus Transactional) governs suppression behavior, but your channel configurations should still use distinct pools where possible.
recommendation-more-help
marketo-optimizer-help-user-guide