Zendesk email authentication
Customer support suite that sends ticket mail as your domain.
SPF record
Add Zendesk to your domain's SPF record with this include:
include:mail.zendesk.com
A complete record for a domain sending only through Zendesk:
v=spf1 include:mail.zendesk.com ~all
What it costs you
1 of your 10 DNS lookups. That is the cheapest an include can be — the record it points at contains only IP ranges, with no further includes to follow. Behind it are 5 IP ranges.
Live record
This is what mail.zendesk.com published when this page was generated:
v=spf1 ip4:103.151.192.0/23 ip4:185.12.80.0/22 ip4:188.172.128.0/20 ip4:192.161.144.0/20 ip4:216.198.0.0/18 ~all
Domains using Zendesk
Found while resolving 293 well-known domains on 2026-08-04 — each authorises
mail.zendesk.com in its published SPF record:
DKIM
Enable DKIM inside Zendesk and publish the selector record it generates. DKIM matters more than SPF for deliverability, because a DKIM signature survives forwarding while SPF does not — see how selectors work.
DMARC
Neither SPF nor DKIM protects the address your recipients actually see until DMARC ties them
to it. Once Zendesk is authenticating, publish a DMARC record — start at
p=none with a reporting address and
tighten from there.
Check it worked
DNS changes take minutes to hours to propagate. Once published, run the domain through the checker — it resolves the full include chain and reports the real lookup count.