Sending provider

Salesforce SPF, DKIM and DMARC setup

Salesforce signs with a DKIM key you create in Setup > DKIM Keys: two CNAME records, <selector>._domainkey and <alternate-selector>._domainkey, pointing to custdkim.salesforce.com, then Activate. For SPF, add include:_spf.salesforce.com to your domain's record, or turn on Email Security Compliance, which passes SPF on Salesforce's bounce domain. Salesforce recommends DMARC but leaves the record to you.

Salesforce

Records at a glance

SPF include
include:_spf.salesforce.com
DKIM

Two CNAMEs to <selector>.<id>.custdkim.salesforce.com

DMARC

Recommended by Salesforce; you choose the record

Check Salesforce on your domain

Enter the domain you send from: the check looks for the Salesforce SPF include, its DKIM key and your DMARC record, and says what to fix.

Lookups go from your browser to Cloudflare's public DNS resolver.

DNS records

The Salesforce records

Values in angle brackets are specific to your account; copy them from the provider. Hosts are relative to your domain, as most DNS panels expect them.

  • Name / host
    @
    Value
    v=spf1 mx include:_spf.salesforce.com ~all

    Salesforce's example. Add only _spf.salesforce.com to your existing record; skip it if Email Security Compliance is on

  • Name / host
    <selector>._domainkey
    Value
    <selector>.<random-id>.custdkim.salesforce.com

    You choose the selector (example-sf-a in Salesforce's example); the random id comes with the key

  • Name / host
    <alternate-selector>._domainkey
    Value
    <alternate-selector>.<random-id>.custdkim.salesforce.com

    The Alternate CNAME Record; Salesforce rotates between the two keys

  • DMARCTXT
    source
    Name / host
    _dmarc
    Value
    v=DMARC1; p=none; rua=mailto:dmarc@<yourdomain>

    Salesforce publishes no DMARC example; this is a monitoring start

Good to know

Step by step

Create and activate a DKIM key in Salesforce

  1. Open DKIM Keyssource (opens the vendor's page in a new tab)

    From Setup, enter DKIM Keys in Quick Find, select it and click Create New Key

  2. Fill in the keysource (opens the vendor's page in a new tab)

    Pick the 2048-bit RSA key size, enter a Selector and an Alternate Selector, the Domain and the Domain Match Pattern, then Save

  3. Copy the CNAMEssource (opens the vendor's page in a new tab)

    Wait until TXT Record Status leaves Publishing in progress (usually within 15 minutes), click the selector and copy the CNAME Record and Alternate CNAME Record

  4. Publish bothsource (opens the vendor's page in a new tab)

    Add both CNAME records at your DNS host. DNS changes can take up to 72 hours

  5. Activatesource (opens the vendor's page in a new tab)

    When DKIM Key Details shows the green check, go to Setup > DKIM Keys, click Edit, then Activate and OK

DMARC

DMARC with Salesforce

  • Salesforce supports and recommends DMARC and leaves the decision to yousource (opens the vendor's page in a new tab)
  • Start with v=DMARC1; p=none; rua=mailto:dmarc@<yourdomain> and move to quarantine once the reports show Salesforce and your other senders alignedsource
DMARCA safe first record

TXT at _dmarc

v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com

Replace the address with a mailbox you read; move to p=quarantine when the reports show every sender passing.

Troubleshooting

Common Salesforce errors and fixes

For cold email

Mailboxes that come with the DNS records done

If the domain is for cold outreach, keep Salesforce on your main domain and send from separate domains. Outreach2day buys the domains, publishes SPF, DKIM and DMARC, creates the mailboxes and starts warm-up, then sends your campaigns from its own sequencer or exports the mailboxes to Instantly or Smartlead.

  • SPF, DKIM and DMARC set for youOn every domain, checked after setup and kept in place
  • $2.50 a mailbox a month12-mailbox minimum; warm-up and the sending engine included
  • 1,000+ mailboxesA volume price per mailbox, quoted on a call

Questions

What is the Salesforce SPF record?

include:_spf.salesforce.com, added to your domain's existing SPF record (Salesforce's example is v=spf1 mx include:_spf.salesforce.com ~all). It is optional when Email Security Compliance is on, because the envelope sender is then Salesforce's own bounce domain.

How do I set up DKIM in Salesforce?

Setup > DKIM Keys > Create New Key, with a 2048-bit key, two selectors and your domain. Publish the two CNAME records Salesforce shows, wait for the green check and click Activate.

Why can I not activate my Salesforce DKIM key?

Salesforce has not seen both CNAMEs yet: one is missing, a name carries the domain twice or sits on another domain, or DNS has not updated. Reload the key page after fixing them; it does not refresh itself.

Can I send cold email from Salesforce?

Salesforce sends from your company domain. Cold outreach is usually sent from separate domains and mailboxes, so the company domain that Salesforce and your team rely on keeps its reputation.

Deliverability call

Talk to our deliverability team

Book a call with the people who run our mailbox infrastructure. We look at your current setup and tell you what to change. Running 1,000+ mailboxes? We also quote a volume price below every vendor list price in our comparisons, warm-up and sending included.

  • Review your domains, DNS records and current inbox placement
  • Size the setup: domains, mailboxes per domain and daily volume per mailbox
  • Plan warm-up and the move from your current provider or sequencer
  • 1,000+ mailboxes: a volume price per mailbox for your setup

Free call

See open times in your time zone and book on this page.

Or open the booking page