Official DNS Guide • Customer Service & Helpdesk Platform

Zendesk Support & Ticketing SPF Record Setup & Validator

Step-by-step Zendesk SPF setup (include:mail.zendesk.com), dual CNAME DKIM keys (zendesk1/zendesk2), and anti-spoofing guide.

Quick Answer • Exact Zendesk Support SPF Syntax

To authorize Zendesk Support & Ticketing to send emails on behalf of your domain, add include:mail.zendesk.com to your domain's single DNS TXT SPF record before the terminating ~all mechanism. The standard record is v=spf1 include:mail.zendesk.com ~all.

Live Zendesk Support DNS Validator

Test your domain's published SPF, DKIM, and DMARC records via global DoH edge nodes in real time.

Zero-Log Client Evaluation

Understanding Zendesk Support & Ticketing Email Authentication

Zendesk Support sends automated ticket responses on behalf of your custom support address (e.g. support@yourcompany.com). Adding Zendesk SPF and DKIM prevents ticket replies from landing in customer spam folders.

When Zendesk Support & Ticketing delivers outbound emails on your behalf, recipient mail transfer agents (MTAs) at Google, Yahoo, Microsoft, and corporate mail gateways inspect the sender identity. Without a published SPF record explicitly permitting Zendesk Support & Ticketing's IP ranges, these emails trigger SPF Softfail (~all) or Hardfail (-all), severely degrading domain reputation and inbox placement.

Required DNS Records for Zendesk Support

Publish the following DNS records in your domain registrar or DNS management console (Cloudflare, AWS Route 53, GoDaddy, Namecheap):

TypeHost / NameValue / TargetTTLPurpose
TXT@v=spf1 include:mail.zendesk.com ~all3600Authorizes Zendesk ticket dispatch.
CNAMEzendesk1._domainkeyzendesk1.domainkey.zendesk.com3600Primary Zendesk DKIM.
CNAMEzendesk2._domainkeyzendesk2.domainkey.zendesk.com3600Secondary Zendesk DKIM.

Step-by-Step Setup Instructions

1

In Zendesk Admin Center > Channels > Talk and email > Email > Custom address.

2

Add "include:mail.zendesk.com" to your existing root SPF TXT record.

3

Add the 2 DKIM CNAME records (zendesk1._domainkey and zendesk2._domainkey) pointing to zendesk.com.

4

Click "Verify DNS records" in Zendesk Admin Center.

Common Zendesk Support SPF Configuration Mistakes

× DMARC Alignment Fail on Support Replies

Cause: Only setting up email forwarding without SPF/DKIM DNS authorization.

Fix: Add SPF include and both DKIM CNAME records in DNS.

Frequently Asked Questions

What is the SPF include for Zendesk?

The SPF mechanism is "include:mail.zendesk.com".

Does Zendesk require DKIM?

Yes, DKIM is required to ensure replies pass DMARC alignment.

Why does Zendesk use dual CNAME DKIM selectors (zendesk1 and zendesk2)?

Zendesk uses two CNAME DKIM records (zendesk1._domainkey and zendesk2._domainkey) to support automatic DKIM key rotation. When Zendesk rotates keys, the CNAME destination updates without requiring any DNS record changes on your end.

What is the most common DMARC failure mode for Zendesk support replies?

The most common failure is using email forwarding (e.g. support@yourcompany.com forwarding to Zendesk) without publishing SPF and DKIM authentication records. Forwarded mail changes the Return-Path, breaking SPF alignment. Adding include:mail.zendesk.com to SPF and both DKIM CNAMEs resolves this.

How do I set up Zendesk with a custom support email address?

In Zendesk Admin Center > Channels > Talk and Email > Email > Custom Email Address, add your support address (e.g. support@yourcompany.com). Zendesk will then display the required SPF and DKIM DNS records to add. After publishing, click Verify DNS Records in Zendesk.

Can Zendesk emails fail SPF even after adding include:mail.zendesk.com?

Yes, if your total SPF record exceeds 10 DNS lookups (RFC 7208 PermError). Zendesk's include counts as 1 lookup. Use IncogSay's SPF Checker to audit your total lookup count. If you exceed the limit, consider flattening some includes to static ip4: ranges using an SPF flattening tool.