Admins may see an entry in the Setup Audit logs showing domainAuthWarningOffOn which to all intents is attributed to a user that didn’t make any changes in Salesforce and may have not been logged in at the time.
Salesforce admins may unexpectedly see an entry for domainAuthWarningOffOn in the Setup Audit logs, attributed to a user who made no changes and might not have been logged in. This occurs because a permission to display in-app reminders for verifying all email sending domains is automatically activated in your Salesforce org. The permission is activated, and the log entry created, only after an email is sent from an unverified domain. This email could be a direct send by a user or an automated send (such as from a flow, batch job, or report subscription). The Audit Trail then incorrectly attributes the domainAuthWarningOffOn permission change to the user who sent the related email. Although this is the current expected behavior, Salesforce admins may find this confusing when reviewing the Audit Trail.
005321780

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.