Sending provider
Salesforce SPF, DKIM and DMARC setup
Salesforce signs with a DKIM key you create in Setup > DKIM Keys: two CNAME records, <selector>._domainkey and <alternate-selector>._domainkey, pointing to custdkim.salesforce.com, then Activate. For SPF, add include:_spf.salesforce.com to your domain's record, or turn on Email Security Compliance, which passes SPF on Salesforce's bounce domain. Salesforce recommends DMARC but leaves the record to you.
Salesforce
Records at a glance
- SPF include
include:_spf.salesforce.com- DKIM
Two CNAMEs to <selector>.<id>.custdkim.salesforce.com
- DMARC
Recommended by Salesforce; you choose the record
Check Salesforce on your domain
Enter the domain you send from: the check looks for the Salesforce SPF include, its DKIM key and your DMARC record, and says what to fix.
Lookups go from your browser to Cloudflare's public DNS resolver.
DNS records
The Salesforce records
Values in angle brackets are specific to your account; copy them from the provider. Hosts are relative to your domain, as most DNS panels expect them.
- Name / host
@Valuev=spf1 mx include:_spf.salesforce.com ~allSalesforce's example. Add only _spf.salesforce.com to your existing record; skip it if Email Security Compliance is on
- Name / host
<selector>._domainkeyValue<selector>.<random-id>.custdkim.salesforce.comYou choose the selector (example-sf-a in Salesforce's example); the random id comes with the key
- Name / host
<alternate-selector>._domainkeyValue<alternate-selector>.<random-id>.custdkim.salesforce.comThe Alternate CNAME Record; Salesforce rotates between the two keys
- DMARCTXTsourceName / host
_dmarcValuev=DMARC1; p=none; rua=mailto:dmarc@<yourdomain>Salesforce publishes no DMARC example; this is a monitoring start
Good to know
- With Email Security Compliance on, the envelope sender becomes *.bnc.salesforce.com and mail from Salesforce passes SPF even without your SPF recordsource (opens the vendor's page in a new tab)
- Salesforce says to use only _spf.salesforce.com in your SPF recordsource (opens the vendor's page in a new tab)
- Each domain and subdomain needs its own key, and the key's domain cannot be changed after you save itsource (opens the vendor's page in a new tab)
- RSA 2048-bit is the recommended key size; after activation Salesforce rotates the keys every 30 dayssource (opens the vendor's page in a new tab)
Step by step
Create and activate a DKIM key in Salesforce
Open DKIM Keyssource (opens the vendor's page in a new tab)
From Setup, enter DKIM Keys in Quick Find, select it and click Create New Key
Fill in the keysource (opens the vendor's page in a new tab)
Pick the 2048-bit RSA key size, enter a Selector and an Alternate Selector, the Domain and the Domain Match Pattern, then Save
Copy the CNAMEssource (opens the vendor's page in a new tab)
Wait until TXT Record Status leaves Publishing in progress (usually within 15 minutes), click the selector and copy the CNAME Record and Alternate CNAME Record
Publish bothsource (opens the vendor's page in a new tab)
Add both CNAME records at your DNS host. DNS changes can take up to 72 hours
Activatesource (opens the vendor's page in a new tab)
When DKIM Key Details shows the green check, go to Setup > DKIM Keys, click Edit, then Activate and OK
Where the records go
Field by field for the DNS panel your domain uses:
DMARC
DMARC with Salesforce
- Salesforce supports and recommends DMARC and leaves the decision to yousource (opens the vendor's page in a new tab)
- Start with v=DMARC1; p=none; rua=mailto:dmarc@<yourdomain> and move to quarantine once the reports show Salesforce and your other senders alignedsource
TXT at _dmarc
v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.comReplace the address with a mailbox you read; move to p=quarantine when the reports show every sender passing.
Troubleshooting
Common Salesforce errors and fixes
Activate is not available
Reload the DKIM Key Details page (it does not refresh itself), check that both CNAMEs match exactly and allow up to 72 hourssource (opens the vendor's page in a new tab)
Only one CNAME published
Publish both the CNAME Record and the Alternate CNAME Recordsource (opens the vendor's page in a new tab)
CNAME on the wrong domain
The record name must match the key's Domain exactly, subdomains includedsource (opens the vendor's page in a new tab)
Domain twice: example-sf-a._domainkey.example.com.example.com
Enter only the host part if your DNS host adds the root domainsource (opens the vendor's page in a new tab)
Double trailing dots
Use one trailing dot or none in the name and value, as your DNS host expectssource (opens the vendor's page in a new tab)
No CNAME values shown
TXT Record Status still says Publishing in progress; wait a few minutes, refresh and click the selector againsource (opens the vendor's page in a new tab)
For cold email
Mailboxes that come with the DNS records done
If the domain is for cold outreach, keep Salesforce on your main domain and send from separate domains. Outreach2day buys the domains, publishes SPF, DKIM and DMARC, creates the mailboxes and starts warm-up, then sends your campaigns from its own sequencer or exports the mailboxes to Instantly or Smartlead.
- SPF, DKIM and DMARC set for youOn every domain, checked after setup and kept in place
- $2.50 a mailbox a month12-mailbox minimum; warm-up and the sending engine included
- 1,000+ mailboxesA volume price per mailbox, quoted on a call
Questions
What is the Salesforce SPF record?
include:_spf.salesforce.com, added to your domain's existing SPF record (Salesforce's example is v=spf1 mx include:_spf.salesforce.com ~all). It is optional when Email Security Compliance is on, because the envelope sender is then Salesforce's own bounce domain.
How do I set up DKIM in Salesforce?
Setup > DKIM Keys > Create New Key, with a 2048-bit key, two selectors and your domain. Publish the two CNAME records Salesforce shows, wait for the green check and click Activate.
Why can I not activate my Salesforce DKIM key?
Salesforce has not seen both CNAMEs yet: one is missing, a name carries the domain twice or sits on another domain, or DNS has not updated. Reload the key page after fixing them; it does not refresh itself.
Can I send cold email from Salesforce?
Salesforce sends from your company domain. Cold outreach is usually sent from separate domains and mailboxes, so the company domain that Salesforce and your team rely on keeps its reputation.
Sources
Salesforce documentation, checked . Menus and values change; if a step differs, Salesforce's own page is the reference.
Deliverability call
Talk to our deliverability team
Book a call with the people who run our mailbox infrastructure. We look at your current setup and tell you what to change. Running 1,000+ mailboxes? We also quote a volume price below every vendor list price in our comparisons, warm-up and sending included.
- Review your domains, DNS records and current inbox placement
- Size the setup: domains, mailboxes per domain and daily volume per mailbox
- Plan warm-up and the move from your current provider or sequencer
- 1,000+ mailboxes: a volume price per mailbox for your setup
Free call
See open times in your time zone and book on this page.
Or open the booking pageLoading available times…
Open the booking page instead