Skip to main content

Hi All, I know with the Winter 27 Release, the Adopt Authorized Email Domains is one of the main features they are rolling out. I have been digging into this further and wondering if I need to add each of my clients domains to our Salesforce, even though we don't own the domains. They are mainly client portal users accessing the Community Portal site. Instead of adding each of our client domains, I was wondering if enabling the "Substitute email address for unverified domain" would be an alternative solution. thank you for any guidance!    

1 个回答
  1. 8月13日 16:08

    Hey Midori, 

     

    Your instinct is right, "Substitute email address for unverified domains" is exactly the intended solution for this scenario. Salesforce's own docs specifically call out Experience Cloud site users, consultants, and users with domains you can't verify as the use case for this setting. 

     

    You don't need to add each client's domain to Authorized Email Domains, that's meant for domains you actually own and control (your own org-wide addresses, your company's sending domains). For client portal users on domains you have no ownership over, adding them individually isn't realistic or even the correct approach. 

     

    With the substitute setting enabled, Salesforce sends on their behalf using a fallback address like

    email@UniqueId.sfcustomeremail.com

    instead of failing the send outright. This keeps portal notifications, password resets, case updates, etc. flowing without needing DKIM or domain verification for every client. 

     

    One thing to check: if your org does any inbound email filtering or client-side rules based on sender domain, this substitute address is different from the user's real domain, so loop in IT/networking if that could cause filtering issues on the client side. 

     

    Reference:

    https://help.salesforce.com/s/articleView?id=xcloud.security_user_email_verification.htm&language=en_US&type=5

0/9000