Providers

A - E
F - L
M - S
T - Z

Salesforce Marketing Cloud (ExactTarget)

Supports SPF Supports DKIM

How to Set Up/Modify SPF for Salesforce Marketing Cloud

The following description addresses how to update a Domain Name Service (DNS) record to use SPF with your custom domain in Salesforce Marketing Cloud (formerly ExactTarget).

To utilize a custom domain, the Salesforce provider requires an SPF TXT record be added to the DNS record. This TXT record is then used by DNS to recognize email servers allowed to send messages on behalf of your custom/third-party domain. To determine whether a correspondence from the specified domain comes from an authorized messaging server, the recipient system relies on the implemented SPF TXT record. At that point, the message is either accepted, quarantined, or rejected by the email receiving system.

To implement SPF authentication for your domain, you will need access to your DNS records in the domain hosting account. Important: If you already have an SPF record, then you should modify that existing record. You must not have more than one SPF record.

For convenience, be sure to log in to your Salesforce account to verify your domain and copy your TXT records. Salesforce Marketing Cloud utilizes an include mechanism during the set-up process. For example, if you do not have an SPF record on your domain, the following scenario is the most common and would pass SPF:

v=spf1 include:cust-spf.exacttarget.com ~all

If you do already have an SPF record on your domain, simply add the following to it:

include:cust-spf.exacttarget.com

To create an SPF record for your domain name, follow these steps:

1. Log in to control panel for your domain DNS host

2. Create a TXT record with the following specifications:

If you do not have an SPF record insert the below into the value field:

v=spf1 include:cust-spf.exacttarget.com ~all

If you already have an SPF record, then you simply need to add the below to your existing record:

include:cust-spf.exacttarget.com

4. Save changes

 

How to Set Up/Modify DKIM for Salesforce

If your domain publishes a DMARC (Domain-based Message Authentication, Reporting, and Conformance) policy, recipients can use the applied DKIM signature to verify that the mail conforms to DMARC. Follow the below steps:

1. In Setup, enter DKIM Keys in Quick Find box, then select DKIM Keys

2. Click Create New Key

3. For Selector, enter unique name

4. Enter your domain name

5. Select preferred type of domain match

6. Save changes

7. Publish your public domain key to DNS using TXT file name format: selector._domainkey.domain.com; For TXT file value, use: v=DKIM1; k=rsa; p=[yourPublicKey]

As a user of this outbound email provider, Salesforce customers are afforded DKIM signing because it supports that mechanism. By utilizing Salesforce’s self-service portal, you can manually set up DKIM at your convenience via TXT records mentioned above. Overall, this Salesforce product provides beneficial components (e.g., DKIM signing, custom DKIM records, self-service set up with TXT records) that result in a streamlined process.

DKIM/SPF Setup Highlights

The below sections highlight notable characteristics of setting up DKIM and SPF for this provider as well as highlighting advanced settings if offered by this Outbound Email Source.

SPF

SPF Include Tag Required

This outbound email provider uses an include mechanism to add this provider's IP space to your SPF. To get fully set up with SPF for this provider, you will need to take the provided “include” domain and add it to your SPF record. An example of an SPF record without an include tag is compared to one with the tag added below (the include tags added are denoted in bold).

 

Initial SPF Record:

HOST TEXT
yourdomain.com v=spf1 ~all

 

SPF record include added:

HOST TEXT
yourdomain.com v=spf1 include:sender.net include:new3rdparty.com ~all

 

This outbound email provider does not allow a custom Return-Path address to be set. 

DKIM

Supports DKIM Signing

Yes, this outbound email provider supports DKIM signing.

DKIM Setup via TXT record

This outbound email provider uses a TXT record to initiate DKIM set up. You will need to take the TXT record(s) provided to you by the provider and add them to your DNS via your DNS hosting provider.

An example of a DKIM TXT record is shown below.

HOST TEXT
s1.domainkey.yourdomain.com. k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPtW5iwpXVPiH5FzJ7Nrl8USzuY9zqqzjE0D1r04xDN6qwziDnmgcFNNfMewVKN2D1O+2J9N14hRprzByFwfQW76yojh54Xu3uSbQ3JP0A7k8o8GutRF8zbFUA8n0ZH2y0cIEjMliXY4W4LwPA7m4q0ObmvSjhd63O9d8z1XkUBwIDAQAB

This outbound email provider allows custom DKIM records to be setup.

DKIM Setup Process: Self-Service Dashboard

This email provider offers a self-service dashboard where DKIM records will be setup for the account. To get DKIM setup for this provider you will login to your account at this provider and proceed to the DKIM setup area.

burritos@banana-pancakes.com braunstrowman@banana-pancakes.com finnbalor@banana-pancakes.com ricflair@banana-pancakes.com randysavage@banana-pancakes.com