Salesforce (Sales & Service Cloud) email authentication
Mail sent directly from Salesforce records and workflows.
SPF record
Add Salesforce (Sales & Service Cloud) to your domain's SPF record with this include:
include:_spf.salesforce.com
A complete record for a domain sending only through Salesforce (Sales & Service Cloud):
v=spf1 include:_spf.salesforce.com ~all
What it costs you
2 of your 10 DNS lookups. The include: itself costs one, and Salesforce (Sales & Service Cloud)'s record chains to 1 more.
Live record
This is what _spf.salesforce.com published when this page was generated:
v=spf1 exists:%{i}._spf.mta.salesforce.com -all
Domains using Salesforce (Sales & Service Cloud)
Found while resolving 293 well-known domains on 2026-08-04 — each authorises
_spf.salesforce.com in its published SPF record:
DKIM
Enable DKIM inside Salesforce (Sales & Service Cloud) and publish the selector record it generates. DKIM matters more than SPF for deliverability, because a DKIM signature survives forwarding while SPF does not — see how selectors work.
DMARC
Neither SPF nor DKIM protects the address your recipients actually see until DMARC ties them
to it. Once Salesforce (Sales & Service Cloud) is authenticating, publish a DMARC record — start at
p=none with a reporting address and
tighten from there.
Check it worked
DNS changes take minutes to hours to propagate. Once published, run the domain through the checker — it resolves the full include chain and reports the real lookup count.