Set up SPF, DKIM and DMARC for Salesforce
The exact SPF, DKIM and DMARC records Salesforce needs, where to add them and how to check they pass and align, so Salesforce mail reaches the inbox.
Updated September 30, 2026
For email sent from Salesforce (Sales Cloud, Service Cloud and the rest of the core platform), create a DKIM key in Setup > DKIM Keys, publish the two CNAME records Salesforce shows, and activate the key. Add include:_spf.salesforce.com to your SPF record. DKIM is what makes Salesforce mail pass DMARC, because SPF only aligns if you turn off bounce management and email security compliance. Marketing Cloud Engagement and Account Engagement (Pardot) are set up separately.
Records at a glance
| Host | Type | Value |
|---|---|---|
<selector>._domainkey | CNAME | <CNAME value from Salesforce>Shown on the DKIM Key Details page after you save the key. The selector is a name you choose, like example-sf-a. |
<alternate selector>._domainkey | CNAME | <Alternate CNAME value from Salesforce>Salesforce uses the alternate for key rotation. Publish both. |
@ | TXT | v=spf1 include:_spf.salesforce.com -allMerge into your existing SPF record rather than adding a second one. |
_dmarc | TXT | v=DMARC1; p=none; rua=mailto:<your report address> |
Set up SPF for Salesforce
Salesforce’s documented SPF entry for mail sent from the application is _spf.salesforce.com. Add it to the SPF record of the domain in your users’ From addresses, alongside your other senders:
v=spf1 include:spf.protection.outlook.com include:_spf.salesforce.com -allThe include only helps DMARC when Salesforce uses your domain as the envelope sender, which by default it doesn’t (see alignment below). It still matters for receivers that check SPF on the From domain, and it’s required if you turn those settings off. Watch the 10-lookup limit: as of September 2026, Salesforce’s include costs two (the include itself plus an exists: check inside it). With DMARC Dojo’s hosted SPF, you add Salesforce in the dashboard instead of editing DNS, and it refuses changes that would break the limit.
If you use Email Relay to send Salesforce mail through Google Workspace or Microsoft 365, that provider’s SPF and DKIM apply to those messages instead.
Set up DKIM in Salesforce
- In Setup, type DKIM Keys in the Quick Find box and select it. Click Create New Key.
- Choose the key size (2048-bit is recommended unless something you use requires a smaller key).
- Enter a Selector and an Alternate Selector: unique names of up to 62 letters, digits and hyphens, such as
example-sf-aandexample-sf-b. - Enter the Domain you send from (it can’t be changed later) and a Domain Match Pattern: a comma-separated list of domains the From address must match before Salesforce signs with this key.
- Save. Salesforce publishes the TXT key records on its side and shows a CNAME and Alternate CNAME. Add both as CNAME records at your DNS host.
- When Salesforce detects the CNAMEs (propagation can take up to 72 hours), an Activate button appears on the DKIM Key Details page. Salesforce won’t let you activate the key before that.
To confirm, send an email from Salesforce to an outside mailbox and check for DKIM-Signature with d= your domain and s= your selector, and dkim=pass in Authentication-Results. An active DKIM key also counts as verifying that you own the sending domain, which Salesforce now requires for domains you send from; Authorized Email Domains with a TXT record is the other way.
Make it pass DMARC (alignment)
With Activate bounce management or Enable compliance with standard email security mechanisms turned on in Deliverability settings, Salesforce rewrites the envelope sender to a bounce address on bnc.salesforce.com. SPF then passes for Salesforce’s domain, not yours, so it doesn’t align.
| Setup | DKIM | SPF | DMARC |
|---|---|---|---|
| Active DKIM key for your domain | Aligned | Not aligned (bounce address) | Passes |
| No DKIM key, both settings off, SPF include added | None | Aligned | Passes, but fragile |
| No DKIM key, default settings | None | Not aligned | Fails |
Salesforce’s own recommendation is the first row: a DKIM key whose domain matches your From addresses, which lets you keep bounce management. Turning the two settings off (Setup > Deliverability) makes SPF align but loses bounce tracking, and SPF alone breaks when mail is forwarded. See DMARC alignment for the rules.
Marketing Cloud Engagement and Account Engagement
These products send from different infrastructure, and the DKIM keys above don’t cover them.
- Marketing Cloud Engagement authenticates mail through a Sender Authentication Package (SAP) or a Private Domain. Both give you an authenticated sending domain signed with DKIM as your domain; SAP also brands link and image URLs and includes a dedicated IP. Salesforce makes the DNS changes for SAP, so you don’t add an SPF include yourself.
- Account Engagement (Pardot) has its own Domain Management page (Admin > Domain Management) that lists the DKIM and SPF entries it expects for each domain, then checks them for you.
Add DMARC
v=DMARC1; p=none; rua=mailto:<your report address>Salesforce orgs often send from several places at once: users, workflows, Marketing Cloud, Account Engagement. DMARC Dojo recognizes Salesforce in DMARC reports, so you can check each stream passes before you move toward p=reject (here’s the safe path).
Check your Salesforce DKIM
Enter your domain to check your DKIM selectors, SPF lookup count and DMARC policy, with the fixes to make.
Troubleshooting
- No Activate button. Salesforce can’t see the CNAMEs yet. Check both records resolve and that the names aren’t doubled (
example-sf-a._domainkey.example.com.example.com). - DKIM active but mail isn’t signed. The From address doesn’t match the key’s Domain Match Pattern, for example mail from a subdomain that isn’t in the list.
- SPF fails alignment in reports. Expected while bounce management or email security compliance is on. Rely on DKIM rather than switching them off.
- SPF permerror after adding Salesforce. The record now exceeds 10 DNS lookups. Remove unused includes or use a hosted SPF service.
- Marketing emails fail DMARC. They come from Marketing Cloud or Account Engagement, which need their own authentication; the core DKIM key doesn’t apply to them.
Frequently asked questions
Is include:_spf.salesforce.com enough for DMARC?
Usually not. With Salesforce’s default deliverability settings the envelope sender is a Salesforce bounce address, so SPF doesn’t align with your domain. An active DKIM key is what makes Salesforce mail pass DMARC.
What should I name my Salesforce DKIM selectors?
Anything unique, up to 62 letters, digits and hyphens. A pair like example-sf-a and example-sf-b makes it obvious in DNS and in reports that the keys belong to Salesforce.
Do I need a DKIM key for every domain my users send from?
Yes, one key per sending domain. The Domain Match Pattern controls which From domains a key signs, so check it covers any subdomains you use.
Does Salesforce DKIM cover emails sent through Gmail or Outlook integration?
No. Mail sent through Gmail or Outlook integration, or relayed through your mail server, is signed by that provider. Set up DKIM there too.