You are here:
Authenticate and Configure Domains in Unified Messaging
To send authenticated emails, you must set up and verify your sending domains in Unified Messaging. Authenticating your sending domains helps Internet Service Providers (ISPs) and enterprise mail servers recognize emails sent through Salesforce originate from your organization, not Salesforce itself. This authentication builds trust with Email Service Providers (ESPs), improves email deliverability, and strengthens your sender reputation.
Set up your domain and DNS records in Unified Messaging to verify sender identity and ensure compliance with DKIM, SPF, and DMARC.
| Available in: Lightning Experience |
| Available in: Salesforce Enterprise and Unlimited Editions for Service Cloud AND Enterprise and Unlimited Editions with Marketing Cloud Next Growth and Advanced Editions |
| Not supported in Government Cloud Plus |
Understand Root Domains and Subdomains
A domain can include a root domain and subdomains that serve different purposes.
The root domain represents your organization’s main domain, while a sending subdomain is specifically for sending or tracking emails. Using subdomains helps you build a sending reputation separate from your corporate or transactional mail streams.
For example, if your From address
is noreply@marketing.yourcompany.com,
-
Root domain:
yourcompany.com -
Sending subdomain:
marketing.yourcompany.com
The subdomain appears in the From address of your emails and helps ESPs or mailbox providers associate your messages with your brand.
- Set Up and Authenticate a Sending Domain
Set up and verify your sending domains in Unified Messaging to authenticate that emails originate from your organization and not from Salesforce itself. - Functional Subdomains in Unified Messaging
After you send an email, Email Service Providers (ESPs) and subscribers communicate back to the sender for scenarios, such as bounces, replies, or unsubscribes. To manage these inbound communications, Unified Messaging uses functional subdomains. - CNAME Records for Functional Subdomains
To route inbound email responses correctly, each functional subdomain must have a corresponding CNAME record in your DNS provider. - Configure CNAME Records with Your DNS Provider
To simplify setup, Unified Messaging provides the complete CNAME record names and values. You can copy the values directly into your DNS provider’s interface. - DNS Provider Behavior
DNS providers differ in how they handle domain naming conventions. Understanding these differences helps prevent configuration errors. - Verify and Activate Your Domain
After you add all DNS records, verify your configuration in Unified Messaging to confirm that Salesforce recognizes and authenticates your domain. Salesforce checks the correctness of all records before activating the domain for authenticated sending in Unified Messaging.

