メールのなりすましを回避するために、Salesforce の Sender Policy Framework (SPF) レコードをドメインの SPF レコードに含めることをお勧めします。SPF レコードに加えて、DomainKeys Identified Mail (DKIM) 機能も実装することをお勧めします。これにより、貴社に代わって送信された送信メールに Salesforce が署名できるようになります。
ただし、メールドメインが DMARC ポリシーを持っている場合、SPF または DKIM のどちらかがパスするだけでなく、DMARC で定義されているようにアライメントしていなければなりません。
SPF のアライメントが失敗する根本原因: 不達管理およびメールセキュリティコンプライアンス、またはどちらかの設定が有効になっています。DKIM 署名が一致してパスする限り、DMARC はSPF も一致させる必要はありません。そのため、不達処理を継続したいお客様には DKIM の設定をお勧めします。
この 2 つの設定のいずれかが組織で有効になっている場合、envelope-from は、
sampleemail=salesforce.com__abc123@abc123.bnc.salesforce.com などの可変エンベロープリターンパス (VERP) アドレスに変更されます。この場合、envelope-from が From ヘッダーのドメインと一致しないため、DMARC のアライメント要件を満たしません。
注: 不達管理を有効にしたままにしても、Envelope SenderとFromヘッダーの不一致があるため、メール配信が成功する保証にはなりません。受信側のメールサーバーのポリシーによっては、メールが拒否されたりスパムフォルダに振り分けられたりする可能性があります。
DKIM のアライメントが失敗する根本原因: DKIM 鍵のドメイン項目が From ヘッダーのドメインと一致しません。
注: アライメントに問題があるかどうかを確認するには、Message Head Analyzer などの様々な Web ベースのヘッダー分析を使用してください。
参考idea exchange - We require a way to not have to disabling Bounce Management for SPF & DKIM Keys
000381292

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.