Understanding Salesforce Marketing Cloud & Pardot Email Authentication
Salesforce Marketing Cloud (formerly ExactTarget) utilizes Sender Authentication Package (SAP) with custom dedicated IP addresses and SPF inclusion.
When Salesforce Marketing Cloud & Pardot delivers outbound emails on your behalf, recipient mail transfer agents (MTAs) at Google, Yahoo, Microsoft, and corporate mail gateways inspect the sender identity. Without a published SPF record explicitly permitting Salesforce Marketing Cloud & Pardot's IP ranges, these emails trigger SPF Softfail (~all) or Hardfail (-all), severely degrading domain reputation and inbox placement.
Required DNS Records for Salesforce
Publish the following DNS records in your domain registrar or DNS management console (Cloudflare, AWS Route 53, GoDaddy, Namecheap):
| Type | Host / Name | Value / Target | TTL | Purpose |
|---|---|---|---|---|
| TXT | @ | v=spf1 include:cust-spf.exacttarget.com ~all | 3600 | Salesforce Marketing Cloud SPF. |
Step-by-Step Setup Instructions
In Salesforce Marketing Cloud > Admin > Send Management > Sender Authentication Package.
Add "include:cust-spf.exacttarget.com" to your domain SPF record.
Publish DKIM and MX records provided by Salesforce support.
Verify status.
Common Salesforce SPF Configuration Mistakes
× Pardot Alignment Mismatch
Cause: Missing Pardot sending domain verification.
Fix: Verify domain in Account Engagement.
Frequently Asked Questions
What is Salesforce Marketing Cloud SPF string?
Use "include:cust-spf.exacttarget.com" or "include:_spf.salesforce.com".
What is the Salesforce Sender Authentication Package (SAP)?
The Sender Authentication Package is a Salesforce add-on that provisions a dedicated sending IP, custom From domain, custom Return-Path, and dedicated DKIM keys for Marketing Cloud. Without SAP, outbound mail uses Salesforce's shared IP pools under the exacttarget.com domain.
What is the difference between Salesforce Marketing Cloud and Pardot (Account Engagement)?
Marketing Cloud handles high-volume broadcast email for customer engagement campaigns. Pardot (now Account Engagement) handles B2B marketing automation and CRM lead nurturing. Both require separate sending domain authentication, with Pardot using Account Engagement > Admin > Domain Management.
What SPF record does Salesforce Pardot/Account Engagement use?
Pardot uses include:_spf.salesforce.com. Ensure your sending domain is verified in Account Engagement > Admin > Domain Management before expecting SPF to pass for Pardot-sent emails.
How does dedicated IP assignment affect Salesforce SPF configuration?
If Salesforce provisions a dedicated sending IP via the SAP package, that specific IP must be whitelisted in your SPF record using the ip4: mechanism (e.g. ip4:198.51.100.0/24). The generic include:cust-spf.exacttarget.com may not cover dedicated IPs.
How do I verify Salesforce DKIM is active?
Use IncogSay's DKIM Checker with your domain and the selector provided by Salesforce support. The DKIM TXT record must resolve to a valid public key, and the key size should be at least 2048-bit per RFC 8301 recommendations.