1. Why Salesforce authentication is non-negotiable in 2026
Salesforce sends a lot of mail on your behalf - sales outreach, workflow alerts, case notifications, and full campaigns from Marketing Cloud and Pardot. Each product can handle authentication differently, which is exactly why Salesforce deliverability is harder to get right than most platforms.
And the stakes just rose. With the Spring '26 release, Salesforce is making domain verification mandatory for outbound email. Production orgs must comply by April 27, 2026; new orgs immediately. Miss it and you get undelivered mail and 550-class errors. So this isn't just a deliverability nicety anymore - it's a hard platform requirement.
Publishing the DKIM DNS records is not enough. Salesforce will not sign your mail until you go back into Setup and explicitly Activate the key. Publish → wait for propagation → activate. Skip that last step and every email fails DKIM while your DNS looks perfect.
2. Before you start: permissions & access
DKIM setup in Salesforce is admin-gated. Confirm you have the Customize Application and Manage DKIM Keys permissions, access to Setup → DKIM Keys, and the ability to edit your domain's DNS. Without both the Salesforce permissions and DNS control, activation will fail and your mail stays unauthenticated.
3. Generate and publish the DKIM key
In Salesforce Setup, use Quick Find to search DKIM Keys, then click Create New Key. Salesforce generates a key pair and shows you a selector name and the public key value to publish in DNS. Add the records Salesforce provides exactly as shown at your DNS provider.
selector1._domainkey TXT "v=DKIM1; k=rsa; p=MIGfMA0GCSq..."
Then - the step people miss - return to the DKIM Keys page after propagation and click Activate. Until you do, Salesforce signs nothing.
4. Add SPF (and mind the multi-product trap)
For Salesforce CRM, merge the Salesforce include into your single existing SPF record:
v=spf1 include:_spf.salesforce.com include:_spf.google.com ~all
Adding include:_spf.salesforce.com covers core CRM sending only. Marketing Cloud and Pardot send from different infrastructure and need their own authentication (a Sender Authentication Package for Marketing Cloud). If your Marketing Cloud mail fails DMARC, an incomplete SAP setup is the usual cause - not your CRM SPF.
Remember: only one SPF record per domain, and stay under ten DNS lookups. Don't add Salesforce includes you don't use.
5. The SPF-alignment gotcha (why DKIM is the real fix)
Here's the Salesforce-specific trap that confuses even experienced admins. Salesforce CRM sends using its own return-path domain. So when a receiver runs SPF, it passes - against Salesforce's record - but the authenticated domain doesn't match your From: domain. That's an alignment failure, and DMARC needs alignment, not just a pass.
The fix isn't more SPF tinkering. It's DKIM: once your Salesforce DKIM key signs with your own domain and is activated, DKIM aligns to your From: domain and carries DMARC to a pass - even while SPF alignment fails. This is why "enable and activate DKIM" is the heart of Salesforce authentication.
6. Publish your DMARC policy
Add a DMARC TXT record at _dmarc, starting in monitor mode:
v=DMARC1; p=none; rua=mailto:[email protected]
Run p=none for a couple of weeks, confirm your DKIM is aligning in the reports, then move up to p=quarantine and finally p=reject. Don't jump straight to reject - you'll risk blocking legitimate Salesforce mail before you've confirmed alignment.
With the Spring '26 deadline looming, don't guess. Run your domain through our CRM DNS Verifier - it checks your published records against Salesforce's spec, confirms DKIM alignment, and flags the activate-the-key and multi-product mistakes that quietly break Salesforce mail.
Verify my Salesforce DNS →7. Authenticated but still landing in spam?
If everything's verified and mail still hits spam, look beyond authentication: (1) reputation - is your domain or IP blacklisted? Run a blacklist sweep. (2) content - run a spam score check. (3) list quality - clean stale and invalid addresses with our List Cleaner. Authentication opens the door; reputation and hygiene keep you inside.
8. Frequently asked questions
Do I need to activate the DKIM key in Salesforce after publishing DNS?
What SPF record does Salesforce need?
include:_spf.salesforce.com to your existing SPF record, merged into one record: v=spf1 include:_spf.salesforce.com ~all. Important: this include only covers core CRM sending. Marketing Cloud and Pardot use different infrastructure and may need their own includes or IP authorization - one Salesforce include does not cover all Salesforce products.