All platforms
CRM-matched DNS
Salesforce Marketing Cloud · 6 CNAME + 2 TXT · DKIM · BOUNCE · FBL · REPLY · UNSUB · SPF · DMARC
Salesforce Marketing Cloud DNS Checker
Salesforce Marketing Cloud sends from your domain using its own required records
, 6 CNAME + 2 TXT covering DKIM, BOUNCE, FBL, REPLY, UNSUB, SPF, DMARC. A generic SPF test
cannot see whether they match. We check your live DNS against
Salesforce Marketing Cloud’s spec, host by host, character by character.
Free, no account.
Using Salesforce Sales Cloud? Marketing Cloud and Sales Cloud publish different DKIM and SPF records. check against Salesforce Sales Cloud instead.
domain only, we strip email and protocol automatically
What Salesforce Marketing Cloud requires
SAP: 6 CNAME (DKIM × 2, anonymous, bounce, fbl, reply, leave) + 2 TXT (SPF, DMARC). Values are unique per account. This is the exact table our verifier checks
your DNS against, not a generic template.
| Type | Host | Required value | Purpose |
| CNAME | 200608._domainkey | 200608._domainkey.exct.net | DKIM |
| CNAME | anonymous.YOUR_SUBDOMAIN | cname.exct.net | BOUNCE |
| CNAME | bounce.YOUR_SUBDOMAIN | cname.exct.net | BOUNCE |
| CNAME | fbl.YOUR_SUBDOMAIN | cname.exct.net | FBL |
| CNAME | reply.YOUR_SUBDOMAIN | cname.exct.net | REPLY |
| CNAME | leave.YOUR_SUBDOMAIN | cname.exct.net | UNSUB |
| TXT | @ | v=spf1 include:_spf.salesforce.com ~all | SPF |
| TXT | _dmarc | v=DMARC1; p=none; rua=mailto:[email protected] | DMARC |
How Salesforce Marketing Cloud authenticates
Salesforce Marketing Cloud handles DKIM by delegation: you publish 1 CNAME record (selector 200608) pointing into 200608._domainkey.exct.net, and Salesforce Marketing Cloud hosts and rotates the actual signing keys on its side. You never see the public key, which also means a checker that only looks for TXT keys at _domainkey will wrongly report DKIM as missing here.
For SPF, Salesforce Marketing Cloud needs its include (_spf.salesforce.com) present in the ONE SPF record your domain is allowed to publish. If you already have an SPF record, this include is merged into it, never added as a second record; two SPF records is an automatic PermError everywhere.
The non-DKIM CNAMEs handle tracking or bounce domains. They carry no authentication themselves, but Salesforce Marketing Cloud's setup screen will not verify the domain until they resolve.
DMARC is yours, not the platform's: one record at _dmarc governs every sender on the domain. If another tool already publishes it, do not add a second; the spec row above shows the minimum this platform expects to find.
Mistakes we see on Salesforce Marketing Cloud domains
Publishing the CNAME target as a TXT record. The record type matters: a TXT with the right value still is not a delegation, and the key lookup dies at your zone.
Proxying the _domainkey CNAMEs through a CDN. They must resolve as plain DNS; an orange-clouded record answers with the CDN's addresses and the key disappears.
Adding Salesforce Marketing Cloud's SPF as a second TXT record next to an existing v=spf1. Receivers see two records and hard-fail both.
Why a generic checker misses this
A standard DNS tool tells you your SPF parses and your DMARC exists. It has no
idea Salesforce Marketing Cloud is in the picture. It cannot tell you a required CNAME points at
the wrong target, a selector is missing, or the include chain never reaches
Salesforce Marketing Cloud’s servers, which are precisely the failures that put
Salesforce Marketing Cloud mail in spam while every generic check shows green.
Read the full Salesforce Marketing Cloud setup guide →
Common questions
What DNS records does Salesforce Marketing Cloud require?
Salesforce Marketing Cloud requires 8 DNS records: 6 CNAME + 2 TXT, covering DKIM, BOUNCE, FBL, REPLY, UNSUB, SPF, DMARC. The exact hosts and values are in the table above, they come from the same spec table our verifier checks against.
Why does a normal SPF checker pass my domain but Salesforce Marketing Cloud mail still fails?
A generic checker only tests whether your SPF record parses. It does not know which include Salesforce Marketing Cloud needs, which CNAME targets its DKIM keys live behind, or which selector names it signs with. We compare your live DNS against Salesforce Marketing Cloud’s required records character by character, so a missing include or a typo in a CNAME target is called out by name.
Will adding these records break my existing email?
The DKIM CNAMEs and the DMARC record are additive. SPF is the one to be careful with: a domain must publish exactly one SPF record, so if you already have one, merge the new include into it rather than adding a second record, two SPF records is an automatic PermError.
Keep going