SPF and DKIM by provider

SPF record for Zendesk

Last updated 2026-08-26

Zendesk sends ticket notifications and agent replies from your support address. Here is what to publish so it can do that as your domain, and what has to line up before DMARC will pass.

What to add. include:mail.zendesk.com in your SPF record, plus the DKIM records below.

What signs your mail. DKIM under zendesk1._domainkey and zendesk2._domainkey.

Signing is off by default, so support mail flows into Zendesk and back out unsigned, and nothing looks wrong until a customer's mail provider starts enforcing.

The SPF record

Add one mechanism to the SPF record on your sending domain:

include:mail.zendesk.com

In a complete record, alongside Google Workspace, that looks like:

v=spf1 include:_spf.google.com include:mail.zendesk.com -all

Add this if Zendesk sends as an address on your domain, which is the usual reason anyone looks this up. Support addresses that stay on yourbrand.zendesk.com need nothing from you.

Then count your lookups. SPF allows ten DNS-querying mechanisms across the entire nested chain, and the eleventh turns the record into a permerror that authorises nothing. The record still reads correctly to a human while every check fails. Run the domain through the SPF checker after every change, because the number moves when your providers change their own records, not just when you change yours.

DKIM

Zendesk publishes the keys itself and you point at them with two CNAMEs:

zendesk1._domainkey.example.com CNAME zendesk1._domainkey.zendesk.com zendesk2._domainkey.example.com CNAME zendesk2._domainkey.zendesk.com

Then turn on digital signing in the Admin Center, under Channels, Talk and email, Email. Zendesk checks the records before it lets you enable it.

DMARC alignment with Zendesk

DMARC passes when SPF or DKIM passes and the domain it authenticated matches the domain in your visible From address. A provider can pass both checks for its own domain and leave you failing. These are the Zendesk specifics:

The general case is covered in alignment, explained, and the header you read to prove it is on the dmarc=fail page.

Verify it

Substitute your domain, and run these after the TTL on anything you replaced has expired:

dig +short TXT example.com dig +short TXT _dmarc.example.com dig +short TXT zendesk1._domainkey.example.com

Then send one message through Zendesk to a Gmail address you control, open Show original, and look for dkim=pass with your domain in header.i. That single check is worth more than any number of DNS lookups, because it tests the thing receivers actually do.

Our SPF checker gives you the lookup count, the DKIM checker confirms a selector resolves and the key is long enough, and the DMARC checker reads your policy back to you. All three are free and none of them ask for an account.

Values here were checked against Zendesk's own documentation, at Zendesk support site. Providers change DNS requirements without much announcement, so if their screen disagrees with this page, believe their screen and tell us.

A record can read correctly and still fail alignment once real mail moves through it. Receivers write that verdict into the reports they send. We read them for you, and paid plans email you the same day one names a new sender that failed, instead of holding it for Monday. See whether this sender passes. Your first domain is free.

Watch every sender on this domain

You published records for one sender, and the domain behind it usually carries several. One weekly summary covers them all. When a report first names a new source failing, we email you the same day. Pro holds 5 domains for $19 a month.

Get the weekly digest

No card · 12+ months of history · The free plan does not expire