Skip to main content
CRM Setup · 14 min read

SPF, DKIM and DMARC for Salesforce in 2026.

The exact DNS records Salesforce needs, why publishing DKIM is not enough (you have to activate it), and the Spring 26 deadline that makes domain verification mandatory. Plus the multi-product trap that breaks Marketing Cloud mail.

Updated May 2026·By EmailSheriff

1. Why Salesforce authentication is non-negotiable in 2026

Salesforce sends a lot of mail on your behalf - sales outreach, workflow alerts, case notifications, and full campaigns from Marketing Cloud and Pardot. Each product can handle authentication differently, which is exactly why Salesforce deliverability is harder to get right than most platforms.

And the stakes just rose. With the Spring '26 release, Salesforce is making domain verification mandatory for outbound email. Production orgs must comply by April 27, 2026; new orgs immediately. Miss it and you get undelivered mail and 550-class errors. So this isn't just a deliverability nicety anymore - it's a hard platform requirement.

The one thing everyone gets wrong

Publishing the DKIM DNS records is not enough. Salesforce will not sign your mail until you go back into Setup and explicitly Activate the key. Publish → wait for propagation → activate. Skip that last step and every email fails DKIM while your DNS looks perfect.

Apr 27
2026 production deadline for mandatory domain verification
DKIM
The protocol that carries Salesforce DMARC alignment
10
Maximum DNS lookups allowed in a single SPF record
48 hr
Worst-case DNS propagation after you publish a record

2. Before you start: permissions & access

DKIM setup in Salesforce is admin-gated. Confirm you have the Customize Application and Manage DKIM Keys permissions, access to Setup → DKIM Keys, and the ability to edit your domain's DNS. Without both the Salesforce permissions and DNS control, activation will fail and your mail stays unauthenticated.

3. Generate and publish the DKIM key

In Salesforce Setup, use Quick Find to search DKIM Keys, then click Create New Key. Salesforce generates a key pair and shows you a selector name and the public key value to publish in DNS. Add the records Salesforce provides exactly as shown at your DNS provider.

DNS · Salesforce DKIM (example - use your own selector & key)
selector1._domainkey TXT "v=DKIM1; k=rsa; p=MIGfMA0GCSq..."

Then - the step people miss - return to the DKIM Keys page after propagation and click Activate. Until you do, Salesforce signs nothing.

4. Add SPF (and mind the multi-product trap)

For Salesforce CRM, merge the Salesforce include into your single existing SPF record:

DNS · merged SPF TXT record at root
v=spf1 include:_spf.salesforce.com include:_spf.google.com ~all
One include ≠ all of Salesforce

Adding include:_spf.salesforce.com covers core CRM sending only. Marketing Cloud and Pardot send from different infrastructure and need their own authentication (a Sender Authentication Package for Marketing Cloud). If your Marketing Cloud mail fails DMARC, an incomplete SAP setup is the usual cause - not your CRM SPF.

Remember: only one SPF record per domain, and stay under ten DNS lookups. Don't add Salesforce includes you don't use.

5. The SPF-alignment gotcha (why DKIM is the real fix)

Here's the Salesforce-specific trap that confuses even experienced admins. Salesforce CRM sends using its own return-path domain. So when a receiver runs SPF, it passes - against Salesforce's record - but the authenticated domain doesn't match your From: domain. That's an alignment failure, and DMARC needs alignment, not just a pass.

The fix isn't more SPF tinkering. It's DKIM: once your Salesforce DKIM key signs with your own domain and is activated, DKIM aligns to your From: domain and carries DMARC to a pass - even while SPF alignment fails. This is why "enable and activate DKIM" is the heart of Salesforce authentication.

6. Publish your DMARC policy

Add a DMARC TXT record at _dmarc, starting in monitor mode:

DNS · TXT record at _dmarc.yourdomain.com
v=DMARC1; p=none; rua=mailto:[email protected]

Run p=none for a couple of weeks, confirm your DKIM is aligning in the reports, then move up to p=quarantine and finally p=reject. Don't jump straight to reject - you'll risk blocking legitimate Salesforce mail before you've confirmed alignment.

Verify before the deadline

With the Spring '26 deadline looming, don't guess. Run your domain through our CRM DNS Verifier - it checks your published records against Salesforce's spec, confirms DKIM alignment, and flags the activate-the-key and multi-product mistakes that quietly break Salesforce mail.

7. Authenticated but still landing in spam?

If everything's verified and mail still hits spam, look beyond authentication: (1) reputation - is your domain or IP blacklisted? Run a blacklist sweep. (2) content - run a spam score check. (3) list quality - clean stale and invalid addresses with our List Cleaner. Authentication opens the door; reputation and hygiene keep you inside.

8. Frequently asked questions

Do I need to activate the DKIM key in Salesforce after publishing DNS?
Yes - and this is the single most common Salesforce mistake. Publishing the DKIM DNS records alone does nothing. After the records propagate, you must return to Setup → DKIM Keys and explicitly click Activate. Any mail signed before activation will fail DKIM. Publish, wait for propagation, then activate.
What SPF record does Salesforce need?
For Salesforce CRM (Sales Cloud), add include:_spf.salesforce.com to your existing SPF record, merged into one record: v=spf1 include:_spf.salesforce.com ~all. Important: this include only covers core CRM sending. Marketing Cloud and Pardot use different infrastructure and may need their own includes or IP authorization - one Salesforce include does not cover all Salesforce products.
Why does Salesforce SPF pass but DMARC still fails?
Because of SPF alignment. Salesforce CRM sends using its own return-path (envelope-from) domain, so SPF passes against Salesforce's record but does not align with your From: domain. DMARC needs alignment, not just a pass. The fix is DKIM: enable and activate a Salesforce DKIM key so it signs with your domain - DKIM alignment then carries DMARC to a pass even when SPF alignment fails.
Is Salesforce domain verification really mandatory now?
Yes. Salesforce's Spring '26 release makes domain verification mandatory for outbound email, with DKIM signing or the Authorized Email Domain feature required. Production deadline is April 27, 2026; new orgs immediately. Unverified domains face undelivered mail and 550-type errors, so this is no longer optional.

Keep your sending healthy

CRM DNS Verifier
Forensic verification for Salesforce, Zoho, HubSpot, Mailchimp - finds the exact misconfigurations that break authentication.
Full Audit
All 6 deliverability checks on a domain in 30 seconds, graded A-F. Catches SPF lookup overflow and DKIM alignment issues.
DNS Checker
SPF · DKIM · DMARC · MX with plain-English explanations. Includes a 10-lookup counter for SPF.