{"id":22745,"date":"2024-05-30T12:00:00","date_gmt":"2024-05-30T10:00:00","guid":{"rendered":"https:\/\/www.marketinet.com\/blog\/salesforce-email-authentication\/"},"modified":"2025-04-04T11:33:52","modified_gmt":"2025-04-04T09:33:52","slug":"salesforce-email-authentication","status":"publish","type":"post","link":"https:\/\/www.marketinet.com\/en\/blog\/salesforce-email-authentication\/","title":{"rendered":"Salesforce Email Authentication"},"content":{"rendered":"<p>In simple terms, email authentication is a process that\u00a0enables businesses to send messages securely.\u00a0It also works with recipients&#8217; email servers to determine if a message comes from a real account and if the sender is legitimate.<\/p>\n<p><!--more--><\/p>\n<p>If\u00a0you use Salesforce to send emails, it&#8217;s essential to consider your SPF, DKIM, and DMARC settings\u00a0to ensure they are delivered correctly.<\/p>\n<p>In this guide, we&#8217;ll review each authentication method and provide guidelines for implementing\u00a0SPF and DKIM policies in Salesforce.<\/p>\n<h2>Email authentication definitions<\/h2>\n<ul>\n<li><strong>DMARC (Domain-based Message Authentication, Reporting, and Conformance):\u00a0<\/strong>It\u00a0has\u00a0been created to\u00a0empower owners to control their email domain and prevent unauthorized use\u00a0(email spoofing). This protocol tells the receiving email servers how to handle emails coming from the company&#8217;s domain.<\/li>\n<li><strong>DKIM (Domain Keys Identified Mail):<\/strong>\u00a0It\u00a0is a protocol that\u00a0<strong>allows a company to assume responsibility for the transmission of a message by signing it<\/strong>\u00a0, allowing mailbox providers to verify it. Therefore, DKIM requires a public key in the DNS, and the recipient&#8217;s email server uses this information to accept emails with the corresponding private key.<\/li>\n<li><strong>SPF (Sender Policy Framework):<\/strong>\u00a0is an email authentication technique used to<strong>\u00a0prevent spammers from sending messages on behalf of your domain.\u00a0<\/strong>Similar to the DKIM configuration, SPF will ask you to add its records to your DNS to authorize Pardot or Salesforce to send emails from the company&#8217;s own domain.<\/li>\n<\/ul>\n<p>These protocols initially originated as a\u00a0measure to strengthen the security of the Simple Mail Transfer Protocol\u00a0(SMTP) and address the rise of spam, since SMTP itself lacks authentication mechanisms. Each of these protocols has its own configuration and must be implemented and verified before sending emails from each platform.<\/p>\n<h2>How does email authentication work?<\/h2>\n<p>SPF\u00a0is responsible for confirming that the email is sent from an\u00a0authorized sender\u00a0, while\u00a0DKIM\u00a0performs\u00a0email authentication\u00a0by comparing and validating public and private keys.<\/p>\n<p>\u00a0<img decoding=\"async\" data-src=\"https:\/\/www.marketinet.com\/wp-content\/uploads\/2024\/06\/blog\/Autenticaci%C3%B3n%20de%20email%20de%20Salesforce\/El%20email%20se%20env%C3%ADa.png\" alt=\"Autenticaci\u00f3n email Salesforce\" width=\"647\" height=\"364\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" class=\"lazyload\" style=\"--smush-placeholder-width: 647px; --smush-placeholder-aspect-ratio: 647\/364;\" \/><\/p>\n<h2>Why is it advisable to implement authentication protocols?<\/h2>\n<p>There are multiple reasons why we should implement these protocols:<\/p>\n<ul>\n<li>The proper implementation of SPF, DKIM and DMARC can\u00a0<strong>save the reputation of your brand, as well as the trust of your clients and leads.<\/strong><\/li>\n<li><strong>They\u00a0<\/strong><strong>affect the delivery capacity of the email<\/strong>\u00a0. If email authentication protocols are not configured properly, there is a high probability that customers will not receive emails, and they\u00a0<strong>will end up in the spam folder<\/strong>.<\/li>\n<li>These email authentication methods\u00a0<strong>prevent phishing attempts<\/strong>\u00a0by allowing email servers to reject messages that were not actually generated by your company.<\/li>\n<\/ul>\n<h2>Preparing to configure SPF\/DKIM<\/h2>\n<p>Before starting the SPF and DKIM adjustment process, it is crucial to establish contact with the IT department.\u00a0This will allow you\u00a0to obtain a list of available domains and understand in detail the procedure necessary to make changes to the DNS. The time required for this process may vary, estimated between 2 and 4 weeks, depending on internal IT policy.<\/p>\n<h2>How to configure SPF and DKIM in Salesforce<\/h2>\n<ol>\n<li>Settings &gt; search for \u201cDKIM\u201d &gt; navigate to DKIM Keys in Email &gt; click Generate New Key.<\/li>\n<\/ol>\n<p><img decoding=\"async\" data-src=\"https:\/\/www.marketinet.com\/wp-content\/uploads\/2024\/06\/blog\/Autenticaci%C3%B3n%20de%20email%20de%20Salesforce\/Salesforce-Email-Authentication-for-Pardot-Salesforce-and-Marketing-Cloud-Salesforce-Ben.png\" alt=\"Generar clave DKIM Salesforce\" width=\"596\" height=\"228\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" class=\"lazyload\" style=\"--smush-placeholder-width: 596px; --smush-placeholder-aspect-ratio: 596\/228;\" \/><\/p>\n<p>2. Selector &gt; Alternative Selector and Domain for the required field &gt; select the preferred Domain Matching policy.<\/p>\n<p>3. Once published, you should see the following message &#8220;Salesforce has published the TXT records for this DKIM key to DNS. Before activating this key, add the CNAME and Alternate CNAME records to DNS for your domain.&#8221; Copy the values \u200b\u200bfrom the CNAME and Alternate CNAME records &gt; send to IT in step 4.<\/p>\n<p><img decoding=\"async\" data-src=\"https:\/\/www.marketinet.com\/wp-content\/uploads\/2024\/06\/image-png-Jan-09-2024-08-39-27-0885-AM.png\" alt=\"DKIM Key Details Salesforce\" width=\"655\" height=\"339\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" class=\"lazyload\" style=\"--smush-placeholder-width: 655px; --smush-placeholder-aspect-ratio: 655\/339;\" \/><\/p>\n<p>4.\u00a0Update the text below with the appropriate information for your organization and send it to the IT team.<\/p>\n<p><em>Hello [name],<\/em><\/p>\n<p><em>I&#8217;m working with the Salesforce team to allow Salesforce to send emails from @yourdomain.com. To ensure high email deliverability, we need to make the following changes.<\/em><\/p>\n<p><em>We need to configure SPF and DKIM so that Salesforce is authorized to send emails on our behalf.<\/em><\/p>\n<ul>\n<li>\n<ul>\n<li><em>To configure SPF, you must add the following to your DNS entries:<\/em>\n<ul>\n<li><em>Type: TXT<\/em><em><br \/><\/em><\/li>\n<li><em>Entry: v=spf1 mx include:_spf.salesforce.com ~all<\/em>\n<ul>\n<li><em>If an SPF record already exists in the DNS entry, just add the following: _spf.salesforce.com<\/em><\/li>\n<\/ul>\n<\/li>\n<li><em>To configure DKIM, you must create two CNAME entries<\/em>\n<ul>\n<li><em>CNAME record<\/em>\n<ul>\n<li><em>Domain: [insert host record here]._domainkey.yourdomain.com<\/em><\/li>\n<li><em>Type: CNAME<\/em><\/li>\n<li><em>Input: [enter host value here].<\/em><\/li>\n<\/ul>\n<\/li>\n<li><em>Alternative CNAME record<\/em>\n<ul>\n<li><em>Domain: [insert alternate host record here]._domainkey.yourdomain.com<\/em><\/li>\n<li><em>Type: CNAME<\/em><\/li>\n<li><em>Input: [insert host value here].<\/em><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><em>Please let me know when these steps are complete so we can complete the setup process within Pardot. If you have any questions, please feel free to contact me.<\/em><\/p>\n<p><em>Greetings,<\/em><\/p>\n<p><em>Marketing operations<\/em><\/p>\n<p>When the IT team adds the CNAME entries, return to the DKIM Keys page.\u00a0DNS changes can take up to 72 hours\u00a0. If Salesforce finds relevant CNAME entries in DNS, you can click the Activate button and you can start sending emails from Salesforce.<\/p>\n<p><img decoding=\"async\" data-src=\"https:\/\/www.marketinet.com\/wp-content\/uploads\/2024\/06\/image-png-Jan-09-2024-08-43-04-3612-AM.png\" alt=\"Activaci\u00f3n inicio lanzamiento emails Salesforce\" width=\"518\" height=\"277\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" class=\"lazyload\" style=\"--smush-placeholder-width: 518px; --smush-placeholder-aspect-ratio: 518\/277;\" \/><\/p>\n<p>If the Activate button is still gray after the IT team confirms the configuration and 72 hours have passed,\u00a0you can use the DKIM Record Lookup tool to validate these records.<\/p>\n<p>You can also review the published DNS record through a DNS interface, but this view will only be accessible to the IT team, so you can ask them for a screenshot.<\/p>\n<p>Email authentication\u00a0is an essential part of secure communication\u00a0with recipients. <strong>If you&#8217;re still having trouble validating your SPF or DKIM records in Salesforce,\u00a0<a href=\"https:\/\/www.marketinet.com\/salesforce-cloud\/consultoria-gestion-pardot-account-engagement\" rel=\"noopener\">please contact us<\/a>\u00a0and we&#8217;ll be happy to help.<\/strong><\/p>\n<hr \/>\n<p><span id=\"hs_cos_wrapper_post_body\" data-hs-cos-general-type=\"meta_field\" data-hs-cos-type=\"rich_text\">If you liked this article, you might also be interested in:<\/span><\/p>\n<ul>\n<li><a href=\"\/en\/blog\/google-ads-connector-for-pardot\" target=\"_blank\" rel=\"noopener\"><span id=\"hs_cos_wrapper_name\">Google Ads Connector for Pardot: setup, reports, and considerations<\/span><\/a><\/li>\n<li><span id=\"hs_cos_wrapper_name\"><\/span><a href=\"\/en\/blog\/pardot-forms-when-to-use-same-when-to-duplicate\" target=\"_blank\" rel=\"noopener\"><span id=\"hs_cos_wrapper_name\">Account Engagement\/Pardot forms<\/span><\/a><\/li>\n<li><a href=\"\/en\/blog\/configuring-google-analytics-events-goals-pardot\" target=\"_blank\" rel=\"noopener\"><span id=\"hs_cos_wrapper_name\" data-hs-cos-general-type=\"meta_field\" data-hs-cos-type=\"text\">Configuring Google Analytics Events and Goals in Pardot<\/span><\/a><\/li>\n<\/ul>\n<p>\u00a0<\/p>\n<p>\u00a0<\/p>\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.marketinet.com\/ebooks\/segmentar-y-plantear-estrategia-email-marketing-pardot-account-engagement?utm_source=blog&amp;utm_medium=inbound&amp;utm_campaign=cta_recurso_blog_ebook_segmentaci\u00f3n_y_email_marketing_pardot\"><img decoding=\"async\" width=\"802\" height=\"189\" data-src=\"https:\/\/www.marketinet.com\/wp-content\/uploads\/2024\/05\/cap4.png\" alt=\"\" class=\"wp-image-26715 lazyload\" data-srcset=\"https:\/\/www.marketinet.com\/wp-content\/uploads\/2024\/05\/cap4.png 802w, https:\/\/www.marketinet.com\/wp-content\/uploads\/2024\/05\/cap4-480x113.png 480w\" data-sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 802px, 100vw\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 802px; --smush-placeholder-aspect-ratio: 802\/189;\" \/><\/a><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>In simple terms, email authentication is a process that\u00a0enables businesses to send messages securely.\u00a0It also works with recipients&#8217; email servers to determine if a message comes from a real account and if the sender is legitimate.<\/p>\n","protected":false},"author":31,"featured_media":22799,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[1],"tags":[232],"class_list":["post-22745","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sin-categorizar","tag-salesforce-email-authentication"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.marketinet.com\/en\/wp-json\/wp\/v2\/posts\/22745","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.marketinet.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.marketinet.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.marketinet.com\/en\/wp-json\/wp\/v2\/users\/31"}],"replies":[{"embeddable":true,"href":"https:\/\/www.marketinet.com\/en\/wp-json\/wp\/v2\/comments?post=22745"}],"version-history":[{"count":0,"href":"https:\/\/www.marketinet.com\/en\/wp-json\/wp\/v2\/posts\/22745\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.marketinet.com\/en\/wp-json\/wp\/v2\/media\/22799"}],"wp:attachment":[{"href":"https:\/\/www.marketinet.com\/en\/wp-json\/wp\/v2\/media?parent=22745"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.marketinet.com\/en\/wp-json\/wp\/v2\/categories?post=22745"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.marketinet.com\/en\/wp-json\/wp\/v2\/tags?post=22745"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}