Validate that outgoing emails from your Salesforce instance are properly authenticated to prevent phishing and improve deliverability. This ensures receiving servers can verify your sender identity using DNS records.
Using DKIM and SPF DNS TXT records, you can configure email authentication for your Salesforce org. Debug configuration using DNS lookups or online tools.
Preparation
DKIM & SPF keys are an Email Authentication method used between servers to approve the Senderβs Identity and prevent phishing & spam.
When server1.com sends an email from server1.com to server2.com, server2 will check if server1.com keys match based on DNS records, registered as TXT entries:
- For SPF, on server1.com
- For DKIM, on selector._domainkey.server1.com
Walkthrough
SPF debug
$ dig server1.com txtDKIM debug
$ dig selector._domainkey.server1.comValidation & troubleshooting
To debug the keys configuration, use an online tool such as https://www.mail-tester.com/spf-dkim-check.
Going further
- Marketing Cloud REST API: send transactional emails from an external call
- Acquisition page: send a welcome email from an Apex controller