SPF problems with Sales Force


May 15, 2019
Hey guys,

I recently upgraded our PMG to the latest version and also added some DNSBLs the product over all performs very well. However I recently discovered in the tracking center that some legitimate mails get rejected because of spf failures.

When I check the spf records manually they seem fine though. Usually mails from salesforce are affected:

reject: RCPT from smtp07-ia5-sp4.mta.salesforce.com[]: 554 5.7.1 <xy@xy.com>: Recipient address rejected: Rejected by SPF: is not a designated mailserver for support%40veeam.com

Several SPF check sites list this combination as valid. Sometimes mails from the same IP go through, sometimes they fail. As the fails happen frequently and affect different companies (all using salesforce apparently) I first thought that salesforce might have issues with their SPF-records. But everytime I check them they seem fine...

any ideas? are there more detailed logs why the spf check failed?

  • Like
Reactions: Dark-Sider

thanks, yes you are spot on - I'm using opnSense which is a pfSense fork. I just recently discovered that most of the DNSBLs were not working because of unbound DNS. I then whitelisted those DNSBLs to allow private IPs.

If SPF is also affected by this problem, this escalates to a different level though, as I don't know every possible SPF query in advance.

I looked at your link, and I'm a bit puzzled why the spf lookup returns as - is this by design or did salesforce just choose to do so? Also it seems a bit strange that it sometimes works and sometimes doesn't although only unbound is configured within PMG
  • Like
Reactions: Dark-Sider
Reliable email delivery requires addressing SPF concerns in Sales Force. Errors in setup may result in spam flags or bounces. Fast resolution requires close examination and frequent revisions to SPF records, which requires cooperation between IT and Sales Force managers.