Loading
Prepare for Email to Become the Default Login ExperienceRead More
Secure Your Salesforce Org
Requirements to Send Email from Salesforce

Requirements to Send Email from Salesforce

To protect your org and brand, Salesforce requires domain-level and user-level email verification. To send email from Salesforce with your email domain, verify ownership of your email-sending domains.

Important
Important If you disable the substitute email address for unverified domains, users can't send messages from Salesforce if their email domain is unverified. In some cases, users get no message and can believe that the email was sent when it was dropped.

Domain-Level Verification

To enable Salesforce to send email from email addresses that contain a domain that you own, verify the sending email domain. For example, if your users’ email addresses are in the format <name>@example.com, those users can’t send email from Salesforce until you verify that you own example.com. We refer to that domain as a “email-sending domain.” If you send email via subdomains, each domain and subdomain requires separate verification.

This requirement applies to emails sent from Salesforce and related automations with an email-sending domain that Salesforce doesn't own, including system-generated emails. For example, Salesforce can't send emails from an organization-wide email address with an unverified email-sending domain, even if the individual email address is verified.

Each domain and subdomain requires separate verification via either an active DKIM key or a verified entry in the Authorized Email Domains list in Setup. See Determine How to Verify Your Email-Sending Domains.

Note
Note To verify your ownership, both options require an update to your domain’s DNS (Domain Name System) record. Prepare to work with your IT team or DNS provider for this step.

Exceptions to the Domain-Level Verification Requirement

For these specific situations, domain-level verification isn’t required.

  • Emails sent through Gmail™ and Office 365® (Outlook) integrations.
  • Emails sent via the Salesforce Einstein Activity Capture (EAC) tool (“Inbox”).
  • Emails sent with Salesforce Free Suite or in trial orgs with the salesforce-free-mailsend.com domain.
  • Emails that end in @gmail.com, @hotmail.com, or @outlook.com don’t require domain-level verification. Those domains belong to the most common public email providers used to send email from Salesforce.
  • Marketing Cloud or Marketing Cloud Advanced emails.
  • System emails sent from a Salesforce-owned domain. For example, email sent by Salesforce from noreply@salesforce.com.

If you want Salesforce to send email for users with an unverified email domain, enable a deliverability setting. See Send Email for Users with Unverified Domains.

Email Address Verification

To send email from Salesforce, every user, including single sign-on (SSO) provisioned users, is required to verify their Salesforce email address. If a user sets a different return email address, they must verify that address separately. Salesforce also requires address verification for shared email addresses, such as organization-wide email addresses, Email-to-Case routing addresses, and Experience Cloud site sender email addresses.

Users, see Verify Your Email Address and Return Email Address in Salesforce.

Admins, to learn how to identify users with unverified email addresses or return email addresses and help them with verification, see Manage User Email Address Verification.

If a trusted integration or admin manages your users’ email addresses in Salesforce, admins can bypass the requirement for user-level email verification via an authorized email domain. This feature affects users’ ability to send email from Salesforce. It has no impact on user account verification or the user’s ability to log in to Salesforce. See Use a Verified Domain for User-Level Email Verification.

 
Loading
Salesforce Help | Article