Verify Your Sending Domain for Canvas Managed Email via SendGrid
Last updated: September 30, 2026
Overview
Canvas sends patient-facing email through SendGrid, an email delivery service that Canvas configures for your instance. These emails include:
Patient portal login and invitation links
Contact verification emails
New message notifications
Appointment reminders
Patient statements (when automated statements are enabled)
These emails are sent from your practice's own email address. For inbox providers to trust that address, your email domain must be authenticated in SendGrid. Domain authentication proves your practice owns the domain, removes the "via sendgrid.net" label that some inboxes show, and improves the chance that your emails reach the inbox instead of spam.
Domain authentication is a shared task. Canvas manages the SendGrid account and its API key. Your team owns your sending address and your domain's DNS records, and only your team can add the records that complete verification. This article covers your team's part.
Who does what
Your team | Canvas |
|---|---|
Chooses the sending address and keeps it current in Canvas | Configures SendGrid and its API key on your instance |
Identifies the DNS provider for your domain and who can make changes there | Starts domain authentication for your domain and walks you through setup |
Adds the DNS records exactly as provided | Confirms verification once the records propagate |
Contacts Canvas before changing the sending address or domain | Re-runs authentication for a new domain |
Required role and permissions
There are two kinds of access involved, and they are often held by different people.
In Canvas: to view or change your sending address, you need a user in the Administrative group, which grants Staff status (to open Settings), api | organization | Can change organization, and api | organization setting | Can add organization setting and Can change organization setting.
At your DNS provider (for example GoDaddy, Cloudflare, Namecheap, or Amazon Route 53): someone who can add records to your domain's DNS. This is often your IT team, web host, or whoever manages your website. Identify this person before you start, because verification cannot be completed without them.
The SendGrid API key in Constance: Config (SendGrid Configuration section) is managed by Canvas.
Before you start
Use a domain your practice controls. Choose an address on your own root domain, for example
billing@yourpractice.com. Addresses on free email providers such as gmail.com, yahoo.com, or outlook.com cannot be authenticated, because only the provider can change those domains' DNS records.Use the root domain. Authenticate the domain itself (for example
yourpractice.com), not a subdomain.Use an address patients will recognize. Patients see this address on every email Canvas sends, and the sender name shown is your organization's full name.
Step 1: Confirm your sending address in Canvas
From the triple line menu, select Settings, then Organizations, and select your organization.
In the Organization settings section, find the setting named
defaultEmail. Its value is the address Canvas sends from.If the address is on a domain your practice does not control, or is not the address you want patients to see, contact Canvas Support before changing it. A new domain has to be authenticated before emails from it will deliver reliably.
Step 2: Add the DNS records
Contact your Canvas team (through your shared Slack channel or Canvas Support) to start domain authentication. Share the domain you are sending from and the name of your DNS provider.
Your Canvas team starts authentication for your domain in SendGrid and sends you a spreadsheet, SendGrid Info to Add to Domain, listing the DNS records generated for your domain. It typically contains three CNAME records and one DMARC TXT record, each with a Type, Host, and Value.
Your DNS administrator adds each record at your DNS provider exactly as provided: the same record type, host or name, and value. Do not edit or combine them.
Let your Canvas team know once the records are added.
DNS changes can take up to 48 hours to propagate. Your Canvas team confirms verification once SendGrid can see the records.
Step 3: Test
After verification is confirmed, send yourself an email from Canvas, for example by resending a patient portal invitation to a test patient whose email address is your own. Confirm it arrives in your inbox, shows your practice's address as the sender, and does not show "via sendgrid.net."
Testing on a sandbox, staging, or demo instance: non-production instances only send email to addresses that are explicitly allowed. Add your test address to the emailAddressAllowList organization setting (in the same Organization settings section, as a list, for example ["you@yourpractice.com"]). Emails to any other external address are not sent from non-production instances. Canvas staff addresses are always allowed.
If you change your sending address or domain
Contact Canvas Support before changing defaultEmail to an address on a different domain. The new domain needs its own authentication and DNS records, and emails sent from an unauthenticated domain are more likely to land in spam or be rejected. Changing to another address on the same, already authenticated domain does not require new records.
Troubleshooting
Verification has not completed after 48 hours. Use a public DNS lookup tool to confirm each record appears on your domain with the exact host and value provided. Missing records and typos in the host or value are the most common causes.
Your domain has more than one DMARC record. A domain should have only one DMARC record (a TXT record at
_dmarc.yourpractice.com). Work with your DNS administrator to keep the correct one before removing anything.Emails are not arriving from a sandbox, staging, or demo instance. Check that the recipient is on the
emailAddressAllowListsetting.Emails arrive but go to spam. Confirm with your Canvas team that authentication for your current
defaultEmaildomain is verified.