Validate that outgoing emails from your Salesforce instance are properly authenticated to prevent phishing and improve deliverability. This ensures receiving servers can verify your sender identity using DNS records.

Using DKIM and SPF DNS TXT records, you can configure email authentication for your Salesforce org. Debug configuration using DNS lookups or online tools.

Preparation

DKIM & SPF keys are an Email Authentication method used between servers to approve the Sender’s Identity and prevent phishing & spam.

When server1.com sends an email from server1.com to server2.com, server2 will check if server1.com keys match based on DNS records, registered as TXT entries:

  • For SPF, on server1.com
  • For DKIM, on selector._domainkey.server1.com

Walkthrough

SPF debug

$ dig server1.com txt

DKIM debug

$ dig selector._domainkey.server1.com

Validation & troubleshooting

To debug the keys configuration, use an online tool such as https://www.mail-tester.com/spf-dkim-check.

Going further