To avoid email spoofing, we encourage our customers to include the Sender Policy Framework (SPF) record of Salesforce in their domain's SPF record. In addition to an SPF record, we also encourage customers to implement the DomainKeys Identified Mail (DKIM) feature. This allows Salesforce to sign outbound emails sent on your company’s behalf.
However, if the email domain has a Domain-based Message Authentication Reporting & Conformance (DMARC) policy, then either SPF or DKIM must not only pass, but also be in alignment, as defined by DMARC.
Root Cause of SPF Alignment failures: Bounce Management and Email Security Compliance or either setting enabled. As long as DKIM signing passes in alignment, DMARC does not require SPF to also be aligned. So for customers who want to continue using Bounce Processing, we recommend setting up DKIM.
If any of these two settings are enabled in your organization, the envelope sender address changes to a Variable Envelope Return Path (VERP) address such as "sampleemail=salesforce.com__abc123@abc123.bnc.salesforce.com". This does not meet DMARC's alignment requirement because the Envelope Sender does not match the domain in the From header.
NOTE: Leaving Bounce Management active in Salesforce does not ensure a successful email delivery because of the mismatch between the Envelope Sender and the From header. Emails can be rejected or sent to spam folders depending upon the recipient's email server policies.
Root Cause of DKIM Alignment failures: The Domain field in the DKIM Key does not match the domain in the From header.
Note: To confirm if there’s an alignment issue, use various web-based header analyzers such as Message Head Analyzer tool.
The preferred resolution is to set up a DKIM Key. The contents of the Domain field must match the Domain Match Pattern field.
Salesforce recommends the following as an alternate solution if you cannot set up a DKIM key:
To disable Bounce Management and Email Security Compliance:
In Lightning Experience
Best practices to setup DKIM
Find email headers for emails
Best email setup for your organization
Guidelines for Configuring Deliverability Settings for Emails Sent from Salesforce
Sender Policy Framework and Salesforce SPF Records
Considerations for Creating DKIM Keys
SPF and DKIM FAQ
Vote and comment on the Idea - We require a way to not have to disable Bounce Management for SPF & DKIM Keys
000381292

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.