DMARC (Domain-based Message Authentication, Reporting & Conformance) is an email validation protocol that allows email service providers to reject messages that do not originate from the sender's authorized mail servers. Starting in April 2014, Yahoo.com and other providers including AOL.com adopted a strict DMARC policy ("p=reject") to prevent spam and phishing scams.
This policy affects Salesforce users who have configured a FROM email address using a Yahoo, AOL, or similarly DMARC-strict domain, because Salesforce delivers those emails from Salesforce mail servers — not from Yahoo's or AOL's servers. DMARC-compliant receiving mail servers will reject these emails.
Example: If a Salesforce user record is configured with a FROM address of user@yahoo.com, and a customer's email server enforces DMARC validation, the email sent from Salesforce will be rejected because it originates from Salesforce mail infrastructure, not from Yahoo's authorized servers.
This article describes how the DMARC policy enforcement by major email providers affects Salesforce email delivery, and the options available to resolve email delivery failures caused by DMARC rejection.
If a Salesforce User record is configured to send email with a FROM address using a domain managed by a DMARC-strict provider (such as @yahoo.com or @aol.com), emails sent from Salesforce may be rejected by DMARC-compliant receiving mail servers. This is because Salesforce delivers emails using its own mail infrastructure and the DMARC policy of the FROM domain prevents third parties from sending on its behalf.
Organizations that control their own email domain can use the following options in Salesforce to comply with DMARC requirements and prevent email delivery failures:
If a user's FROM email address uses a consumer domain such as @yahoo.com or @gmail.com that the organization does not control, the recommended solution is to register a new email address using a domain your organization owns. Update the Salesforce User record to use this organization-owned address as the FROM address for all outgoing emails.
For Organizations that own their domain, options to mitigate:
Additional Resources:
000387241

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.