Verify Your Sending Domain for Canvas Managed Email via SendGrid

Last updated: September 30, 2026

Overview

Canvas sends patient-facing email through SendGrid, an email delivery service that Canvas configures for your instance. These emails include:

  • Patient portal login and invitation links

  • Contact verification emails

  • New message notifications

  • Appointment reminders

  • Patient statements (when automated statements are enabled)

These emails are sent from your practice's own email address. For inbox providers to trust that address, your email domain must be authenticated in SendGrid. Domain authentication proves your practice owns the domain, removes the "via sendgrid.net" label that some inboxes show, and improves the chance that your emails reach the inbox instead of spam.

Domain authentication is a shared task. Canvas manages the SendGrid account and its API key. Your team owns your sending address and your domain's DNS records, and only your team can add the records that complete verification. This article covers your team's part.

Who does what

Your team

Canvas

Chooses the sending address and keeps it current in Canvas

Configures SendGrid and its API key on your instance

Identifies the DNS provider for your domain and who can make changes there

Starts domain authentication for your domain and walks you through setup

Adds the DNS records exactly as provided

Confirms verification once the records propagate

Contacts Canvas before changing the sending address or domain

Re-runs authentication for a new domain

Required role and permissions

There are two kinds of access involved, and they are often held by different people.

  • In Canvas: to view or change your sending address, you need a user in the Administrative group, which grants Staff status (to open Settings), api | organization | Can change organization, and api | organization setting | Can add organization setting and Can change organization setting.

  • At your DNS provider (for example GoDaddy, Cloudflare, Namecheap, or Amazon Route 53): someone who can add records to your domain's DNS. This is often your IT team, web host, or whoever manages your website. Identify this person before you start, because verification cannot be completed without them.

The SendGrid API key in Constance: Config (SendGrid Configuration section) is managed by Canvas.

Before you start

  • Use a domain your practice controls. Choose an address on your own root domain, for example billing@yourpractice.com. Addresses on free email providers such as gmail.com, yahoo.com, or outlook.com cannot be authenticated, because only the provider can change those domains' DNS records.

  • Use the root domain. Authenticate the domain itself (for example yourpractice.com), not a subdomain.

  • Use an address patients will recognize. Patients see this address on every email Canvas sends, and the sender name shown is your organization's full name.

Step 1: Confirm your sending address in Canvas

  1. From the triple line menu, select Settings, then Organizations, and select your organization.

  2. In the Organization settings section, find the setting named defaultEmail. Its value is the address Canvas sends from.

  3. If the address is on a domain your practice does not control, or is not the address you want patients to see, contact Canvas Support before changing it. A new domain has to be authenticated before emails from it will deliver reliably.

Step 2: Add the DNS records

  1. Contact your Canvas team (through your shared Slack channel or Canvas Support) to start domain authentication. Share the domain you are sending from and the name of your DNS provider.

  2. Your Canvas team starts authentication for your domain in SendGrid and sends you a spreadsheet, SendGrid Info to Add to Domain, listing the DNS records generated for your domain. It typically contains three CNAME records and one DMARC TXT record, each with a Type, Host, and Value.

  3. Your DNS administrator adds each record at your DNS provider exactly as provided: the same record type, host or name, and value. Do not edit or combine them.

  4. Let your Canvas team know once the records are added.

DNS changes can take up to 48 hours to propagate. Your Canvas team confirms verification once SendGrid can see the records.

Step 3: Test

After verification is confirmed, send yourself an email from Canvas, for example by resending a patient portal invitation to a test patient whose email address is your own. Confirm it arrives in your inbox, shows your practice's address as the sender, and does not show "via sendgrid.net."

Testing on a sandbox, staging, or demo instance: non-production instances only send email to addresses that are explicitly allowed. Add your test address to the emailAddressAllowList organization setting (in the same Organization settings section, as a list, for example ["you@yourpractice.com"]). Emails to any other external address are not sent from non-production instances. Canvas staff addresses are always allowed.

If you change your sending address or domain

Contact Canvas Support before changing defaultEmail to an address on a different domain. The new domain needs its own authentication and DNS records, and emails sent from an unauthenticated domain are more likely to land in spam or be rejected. Changing to another address on the same, already authenticated domain does not require new records.

Troubleshooting

  • Verification has not completed after 48 hours. Use a public DNS lookup tool to confirm each record appears on your domain with the exact host and value provided. Missing records and typos in the host or value are the most common causes.

  • Your domain has more than one DMARC record. A domain should have only one DMARC record (a TXT record at _dmarc.yourpractice.com). Work with your DNS administrator to keep the correct one before removing anything.

  • Emails are not arriving from a sandbox, staging, or demo instance. Check that the recipient is on the emailAddressAllowList setting.

  • Emails arrive but go to spam. Confirm with your Canvas team that authentication for your current defaultEmail domain is verified.

Related articles