{"id":63674,"date":"2026-09-29T20:19:08","date_gmt":"2026-09-29T20:19:08","guid":{"rendered":"https:\/\/easydmarc.com\/blog\/?p=63674"},"modified":"2026-09-29T20:21:51","modified_gmt":"2026-09-29T20:21:51","slug":"zendesk-sender-authentication-spf-dkim","status":"publish","type":"post","link":"https:\/\/easydmarc.com\/blog\/zendesk-sender-authentication-spf-dkim\/","title":{"rendered":"Broken SPF or DKIM? Your Emails to Zendesk Support Desks May Never Arrive"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">In February 2024, Google and Yahoo changed their requirements for bulk email. A little over a year later, in May 2025, Microsoft introduced similar requirements. These changes were aimed at consumer inboxes and the high-volume senders trying to reach them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Now, that same idea is making its way into another part of the email ecosystem: support inboxes. Zendesk is enabling sender authentication by default for inbound email sent to its customers. So, if your domain has a broken SPF or DKIM setup, an email your organization sends to a company\u2019s Zendesk-powered support desk might never turn into a support ticket.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this article, we\u2019ll look at what has changed in Zendesk, how these requirements compare with those introduced by Google, Yahoo, and Microsoft, and which senders could be affected.<\/p>\n\n\n\n<h2 id=\"h-what-zendesk-announced\" class=\"wp-block-heading\"><strong>What Zendesk Announced<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">On June 18 2026, Zendesk published the announcement and described it as raising the security floor for all accounts by making &#8220;Minimal&#8221; the default sender authentication profile. <a href=\"https:\/\/support.zendesk.com\/hc\/en-us\/articles\/10806145522074-Announcing-a-new-security-standard-for-sender-authentication\">The rollout has two phases<\/a>:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Phase 1<\/strong>: New accounts will have sender authentication enabled and set to Minimal from the start. Admins can still change the profile or turn sender authentication off if needed.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Phase 2<\/strong>: Starting September 23, 2026, Zendesk will gradually move eligible accounts that currently have sender authentication turned off to the Minimal profile. There are two different end dates listed on Zendesk\u2019s page, October 22 and December 16, 2026. For that reason, it\u2019s safest to assume that an account could be moved over at any point during this period.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Zendesk says there are two main reasons for this change. First, it wants security to be turned on by default. Second, it wants to reduce problems with suspended emails. There is also a deliverability benefit for senders with proper authentication. With the Minimal profile, Zendesk uses different spam limits for emails that pass authentication, which can help prevent legitimate forwarded emails from being wrongly suspended.<\/p>\n\n\n\n<h2 id=\"h-what-zendesk-actually-checks\" class=\"wp-block-heading\"><strong>What Zendesk Actually Checks<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">To put it simply, Zendesk checks inbound emails against SPF, DKIM, DMARC, and ARC, and then applies one of three authentication profiles.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Minimal (the new default):<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>An email is suspended when SPF fails and DKIM is either missing or fails.<\/li>\n\n\n\n<li>If the sender&#8217;s domain has no SPF and DKIM fails, the email is delivered but flagged as potential spoofing.<\/li>\n\n\n\n<li>Everything else passes.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Native traffic<\/strong>: This adds another layer of checks for emails that claim to come from one of your organization\u2019s verified domains. If the email fails DMARC and the policy is set to quarantine or reject, it is suspended. Emails where neither SPF nor DKIM is configured are also flagged. These stricter rules only apply to emails sent directly to the native Zendesk address. Forwarded emails are still checked under the Minimal profile.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Native and forwarded traffic<\/strong>: This extends the same checks to auto-forwarded emails. Zendesk validates the ARC seals and the authentication results recorded by each forwarder.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here are a&nbsp; few details worth highlighting:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">1. A broken SPF record can be worse than having no SPF record under Minimal. A domain with no SPF and no DKIM can pass the Minimal checks. But if the domain has an SPF record that fails and there is no working DKIM, the email gets suspended. So, publishing an SPF record and then leaving it outdated can now create a real problem.<\/p>\n\n\n\n<ol class=\"wp-block-list\"><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">2. Agents are always checked. Inbound emails from agent addresses are authenticated regardless of the account setting is, and this cannot be switched off. If your agents reply to tickets from their own mailboxes, your domain&#8217;s authentication need to be configured correctly.<\/p>\n\n\n\n<ol start=\"2\" class=\"wp-block-list\"><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">3. Some senders face stricter checks. Zendesk maintains a blocklist of providers that have historically had weaker authentication. Emails from these providers are suspended if the sender&#8217;s domain has neither SPF nor DKIM configured.<\/p>\n\n\n\n<ol start=\"3\" class=\"wp-block-list\"><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">4. The sender does not get a bounce. Zendesk accepts the email and moves it to the Suspended tickets view instead. The customer thinks their message has reached support, but the support team will not see it unless someone checks that view.<\/p>\n\n\n\n<ol start=\"4\" class=\"wp-block-list\"><\/ol>\n\n\n\n<h2 id=\"h-how-this-compares-to-google-yahoo-and-microsoft\" class=\"wp-block-heading\"><strong>How This Compares to Google, Yahoo, and Microsoft<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The background:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Google and Yahoo (2024 onward)<\/strong>: Google and Yahoo announced their new requirements in October 2023, with the changes taking effect in February 2024. Google started rejecting some non-compliant traffic in April 2024, and one-click unsubscribe became mandatory in June 2024. Bulk senders needed SPF, DKIM, and a DMARC record set to at least p=none, along with proper alignment. Enforcement was fairly soft at first, but that changed in November 2025 when Gmail began ramping up enforcement. Non-compliant messages could then face temporary or permanent rejections.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Microsoft (2025)<\/strong>: Starting May 5, 2025, domains sending 5,000 or more messages a day to Outlook.com, Live.com, and Hotmail.com addresses needed to have SPF, DKIM, and DMARC in place. Those messages also had to pass DMARC alignment. Microsoft initially said that non-compliant high-volume emails would go to Junk before rejection was introduced later. It then changed its approach, with failing messages being rejected with the error: \u201c550; 5.7.515 Access denied, sending domain does not meet the required authentication level.\u201d<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Zendesk (2026)<\/strong>: The situation is a little different, but the direction is the same: email authentication is becoming a basic requirement for getting messages where they need to go.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><\/td><td><strong>Google \/ Yahoo<\/strong><\/td><td><strong>Microsoft<\/strong><\/td><td><strong>Zendesk (Minimal default)<\/strong><\/td><\/tr><tr><td><strong>Who it applies to<\/strong><\/td><td>Bulk senders to consumer Gmail\/Yahoo<\/td><td>Senders of 5,000+\/day to Outlook.com consumer addresses<\/td><td>Anyone emailing a Zendesk support address<\/td><\/tr><tr><td><strong>Volume threshold<\/strong><\/td><td>~5,000\/day (Google)<\/td><td>5,000+\/day<\/td><td>None<\/td><\/tr><tr><td><strong>Authentication bar<\/strong><\/td><td>SPF + DKIM + DMARC (p=none min), aligned<\/td><td>SPF + DKIM + DMARC (p=none min), aligned<\/td><td>SPF or DKIM must pass<\/td><\/tr><tr><td><strong>Failure outcome<\/strong><\/td><td>Deferral, spam folder, or rejection<\/td><td>Rejection (550 5.7.515)<\/td><td>Ticket suspended, with no bounce<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Zendesk&#8217;s authentication bar is lower. Under the Minimal profile, you don&#8217;t need DMARC for an email to become a ticket. But the scope is much broader. Google and Microsoft&#8217;s requirements didn&#8217;t affect, for example, an account manager at a 40-person company who sends one email a week. Zendesk&#8217;s rules can affect that person too.<\/p>\n\n\n\n<h2 id=\"h-why-the-scale-matters\" class=\"wp-block-heading\"><strong>Why the Scale Matters<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Zendesk is far from a niche tool. It powers billions of conversations with hundreds of millions of customers across more than 100,000 companies, with customers in 160 countries and territories. If you deal with SaaS vendors, e-commerce businesses, fintech companies, travel services, or gaming companies, there\u2019s a good chance some of the support desks you contact run on Zendesk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At the same time, domain authentication is still far from being a solved problem. <a href=\"https:\/\/easydmarc.com\/blog\/easydmarc-releases-2026-dmarc-adoption-report\/\">EasyDMARC\u2019s 2026 DMARC Adoption Report<\/a> found that 52.1% of the top 1.8 million domains have a valid DMARC record, up from 47.7% in 2025 and 27.2% in 2023. Of the 937,931 domains with valid DMARC, 525,996 (56.1%) are still at p=none, which means more than half have not moved to enforcement yet. A domain with p=none, broken SPF, and no DKIM signing on some of its mail streams is exactly the kind of authentication gap that Zendesk&#8217;s Minimal profile can expose.<\/p>\n\n\n\n<h2 id=\"h-who-is-at-risk\" class=\"wp-block-heading\"><strong>Who is At Risk?<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">1. <strong>Organizations emailing Zendesk-powered support desks<\/strong>: If your SPF record fails, with the 10-lookup limit being a common reason, and one or more of your sending sources doesn&#8217;t use DKIM, your emails to vendor support desks could end up suspended. You won&#8217;t receive a bounce or other obvious warning. You may simply get a slower response, or no response at all.<\/p>\n\n\n\n<ol class=\"wp-block-list\"><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">2. <strong>Zendesk customers who forward mail into Zendesk<\/strong>: A common setup is support@yourcompany.com forwarding messages to yourcompany.zendesk.com. Forwarding can break SPF because Zendesk sees the forwarder&#8217;s IP address rather than the original sender&#8217;s. DKIM, however, can survive the forwarding process when the signature remains intact. So, if the original sender doesn&#8217;t sign the message with DKIM, a forwarded email could end up in Suspended. This is where ARC becomes important, which is also why Zendesk checks ARC in its strictest profile.<\/p>\n\n\n\n<ol start=\"2\" class=\"wp-block-list\"><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">3. <strong>Internal systems that email Zendesk<\/strong>: There are plenty of email streams that people don&#8217;t think about until they suddenly stop showing up. These can include monitoring alerts, web forms, CRM notifications, billing systems, and older on-premises applications that send mail &#8220;as&#8221; your domain through an unauthenticated relay.<\/p>\n\n\n\n<ol start=\"3\" class=\"wp-block-list\"><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">4. <strong>Your agents<\/strong>: As mentioned earlier, agent mail is always authenticated. If an agent replies from a mailbox on a domain with broken authentication, that reply can also be suspended.<\/p>\n\n\n\n<ol start=\"4\" class=\"wp-block-list\"><\/ol>\n\n\n\n<h2 id=\"h-what-to-do\" class=\"wp-block-heading\"><strong>What To Do<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you send email (everyone):<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Make DKIM a priority<\/strong>: Sign every mail stream with a DKIM key on your own domain. DKIM can survive forwarding, and under the Minimal profile, a valid DKIM signature can keep a message from being suspended when SPF fails. On Microsoft 365, don&#8217;t rely on the default onmicrosoft.com signature. Make sure DKIM is enabled for your custom domain.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Fix SPF instead of simply publishing it<\/strong>: Stay below the 10 DNS lookup limit, remove services you no longer use, and check that the record actually passes authentication. With Zendesk&#8217;s Minimal logic, a broken SPF record can work against you.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Set up DMARC reporting<\/strong>: Aggregate reports give you visibility into the different sources sending email on behalf of your domain, including sources you may have forgotten about. Once you have that visibility, you can start working toward enforcement.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>If you run Zendesk:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Keep an eye on the Suspended tickets view<\/strong>: Zendesk recommends this and suggests sorting the view by suspension reason to identify patterns. In particular, look for messages marked &#8220;Email authentication failed.&#8221; Check this regularly during the rollout, especially if you notice certain customers suddenly taking longer to get a response. Repeated authentication failures can also help you identify which senders or forwarding paths need attention.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Check your forwarding path<\/strong>: Make sure the forwarder preserves DKIM and, where possible, adds ARC headers. Test the full forwarding path instead of checking only the original message, since authentication results can change as an email passes through different systems. This is especially important if you use multiple forwarding services or gateways.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Don&#8217;t simply switch the feature off:<\/strong> Zendesk recommends fixing the forwarding setup instead of disabling sender authentication. It also warns that spam issues need to be addressed at the source, since changing the filters won&#8217;t improve the sender&#8217;s reputation.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Consider moving to &#8220;Native traffic&#8221;<\/strong>: Once your own domain has reached DMARC enforcement. This profile provides stronger protection against spoofed messages claiming to come from your domain.<\/li>\n<\/ul>\n\n\n\n<h2 id=\"h-the-bigger-picture\" class=\"wp-block-heading\"><strong>The Bigger Picture<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Two years ago, email authentication was mainly something you worried about when trying to reach Gmail and other major inboxes. Now, it can also determine whether a support team ever sees your message. Mailbox providers started pushing the industry in this direction, and platforms that handle email are now following. We may see more helpdesks, CRMs, and ticketing platforms introduce similar checks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The basic fix hasn&#8217;t really changed since 2024: use aligned DKIM across your mail streams, keep SPF working, enable DMARC reporting, and work toward enforcement. If you&#8217;re not sure where your domain stands, start with your DMARC reports. They can show you what&#8217;s going wrong before a support desk makes you find out the hard way.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In February 2024, Google and Yahoo changed their requirements for bulk email. A little over a year later, in May 2025, Microsoft introduced similar requirements. These changes were aimed at consumer inboxes and the high-volume senders trying to reach them. Now, that same idea is making its way into another part of the email ecosystem: [&hellip;]<\/p>\n","protected":false},"author":25,"featured_media":63675,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[204,291],"tags":[563],"class_list":["post-63674","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","category-email-authentication","tag-authentication"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.5 (Yoast SEO v28.5) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Zendesk Sender Authentication: SPF &amp; DKIM Changes | EasyDMARC<\/title>\n<meta name=\"description\" content=\"Zendesk is making sender authentication the default. Learn how broken SPF or DKIM can suspend emails and what senders should do to avoid issues. Pasted markdown\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/easydmarc.com\/blog\/zendesk-sender-authentication-spf-dkim\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Broken SPF or DKIM? Your Emails to Zendesk Support Desks May Never Arrive\" \/>\n<meta property=\"og:description\" content=\"Zendesk is making sender authentication the default. Learn how broken SPF or DKIM can suspend emails and what senders should do to avoid issues. Pasted markdown\" \/>\n<meta property=\"og:url\" content=\"https:\/\/easydmarc.com\/blog\/zendesk-sender-authentication-spf-dkim\/\" \/>\n<meta property=\"og:site_name\" content=\"EasyDMARC\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/EasyDMARC\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-29T20:19:08+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-29T20:21:51+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/easydmarc.com\/blog\/wp-content\/uploads\/2026\/09\/Zendesk-SPF-DKIM-Hero.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1440\" \/>\n\t<meta property=\"og:image:height\" content=\"910\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Hagop K.\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@easydmarc\" \/>\n<meta name=\"twitter:site\" content=\"@easydmarc\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Hagop K.\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/zendesk-sender-authentication-spf-dkim\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/zendesk-sender-authentication-spf-dkim\\\/\"},\"author\":{\"name\":\"Hagop K.\",\"@id\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/#\\\/schema\\\/person\\\/740e38b8d7f98e6c4141ae2931ca5a2a\"},\"headline\":\"Broken SPF or DKIM? Your Emails to Zendesk Support Desks May Never Arrive\",\"datePublished\":\"2026-09-29T20:19:08+00:00\",\"dateModified\":\"2026-09-29T20:21:51+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/zendesk-sender-authentication-spf-dkim\\\/\"},\"wordCount\":1839,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/zendesk-sender-authentication-spf-dkim\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Zendesk-SPF-DKIM-Hero.png\",\"keywords\":[\"Authentication\"],\"articleSection\":[\"Blog\",\"Email Authentication\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/easydmarc.com\\\/blog\\\/zendesk-sender-authentication-spf-dkim\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/zendesk-sender-authentication-spf-dkim\\\/\",\"url\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/zendesk-sender-authentication-spf-dkim\\\/\",\"name\":\"Zendesk Sender Authentication: SPF & DKIM Changes | EasyDMARC\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/zendesk-sender-authentication-spf-dkim\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/zendesk-sender-authentication-spf-dkim\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Zendesk-SPF-DKIM-Hero.png\",\"datePublished\":\"2026-09-29T20:19:08+00:00\",\"dateModified\":\"2026-09-29T20:21:51+00:00\",\"description\":\"Zendesk is making sender authentication the default. Learn how broken SPF or DKIM can suspend emails and what senders should do to avoid issues. Pasted markdown\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/zendesk-sender-authentication-spf-dkim\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/easydmarc.com\\\/blog\\\/zendesk-sender-authentication-spf-dkim\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/zendesk-sender-authentication-spf-dkim\\\/#primaryimage\",\"url\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Zendesk-SPF-DKIM-Hero.png\",\"contentUrl\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Zendesk-SPF-DKIM-Hero.png\",\"width\":1440,\"height\":910},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/zendesk-sender-authentication-spf-dkim\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Startseite\",\"item\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Blog\",\"item\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/category\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Email Security\",\"item\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/category\\\/blog\\\/email-security\\\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"Email Authentication\",\"item\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/category\\\/blog\\\/email-security\\\/email-authentication\\\/\"},{\"@type\":\"ListItem\",\"position\":5,\"name\":\"Broken SPF or DKIM? Your Emails to Zendesk Support Desks May Never Arrive\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/\",\"name\":\"EasyDMARC\",\"description\":\"Blog\",\"publisher\":{\"@id\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/#organization\",\"name\":\"EasyDMARC\",\"url\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/09\\\/cropped-android-chrome-512x512-1.png\",\"contentUrl\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/09\\\/cropped-android-chrome-512x512-1.png\",\"width\":512,\"height\":512,\"caption\":\"EasyDMARC\"},\"image\":{\"@id\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/EasyDMARC\\\/\",\"https:\\\/\\\/x.com\\\/easydmarc\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/easydmarc\\\/mycompany\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/#\\\/schema\\\/person\\\/740e38b8d7f98e6c4141ae2931ca5a2a\",\"name\":\"Hagop K.\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/bb6e65e2ae3c6e57f798515a978995b899d1d972034c909397efad978249be85?s=96&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/bb6e65e2ae3c6e57f798515a978995b899d1d972034c909397efad978249be85?s=96&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/bb6e65e2ae3c6e57f798515a978995b899d1d972034c909397efad978249be85?s=96&r=g\",\"caption\":\"Hagop K.\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/hagopkhatchoian\\\/\"],\"url\":\"https:\\\/\\\/easydmarc.com\\\/blog\\\/author\\\/hagop-khatchoian\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Zendesk Sender Authentication: SPF & DKIM Changes | EasyDMARC","description":"Zendesk is making sender authentication the default. Learn how broken SPF or DKIM can suspend emails and what senders should do to avoid issues. Pasted markdown","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/easydmarc.com\/blog\/zendesk-sender-authentication-spf-dkim\/","og_locale":"en_US","og_type":"article","og_title":"Broken SPF or DKIM? Your Emails to Zendesk Support Desks May Never Arrive","og_description":"Zendesk is making sender authentication the default. Learn how broken SPF or DKIM can suspend emails and what senders should do to avoid issues. Pasted markdown","og_url":"https:\/\/easydmarc.com\/blog\/zendesk-sender-authentication-spf-dkim\/","og_site_name":"EasyDMARC","article_publisher":"https:\/\/www.facebook.com\/EasyDMARC\/","article_published_time":"2026-09-29T20:19:08+00:00","article_modified_time":"2026-09-29T20:21:51+00:00","og_image":[{"width":1440,"height":910,"url":"https:\/\/easydmarc.com\/blog\/wp-content\/uploads\/2026\/09\/Zendesk-SPF-DKIM-Hero.png","type":"image\/png"}],"author":"Hagop K.","twitter_card":"summary_large_image","twitter_creator":"@easydmarc","twitter_site":"@easydmarc","twitter_misc":{"Written by":"Hagop K.","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/easydmarc.com\/blog\/zendesk-sender-authentication-spf-dkim\/#article","isPartOf":{"@id":"https:\/\/easydmarc.com\/blog\/zendesk-sender-authentication-spf-dkim\/"},"author":{"name":"Hagop K.","@id":"https:\/\/easydmarc.com\/blog\/#\/schema\/person\/740e38b8d7f98e6c4141ae2931ca5a2a"},"headline":"Broken SPF or DKIM? Your Emails to Zendesk Support Desks May Never Arrive","datePublished":"2026-09-29T20:19:08+00:00","dateModified":"2026-09-29T20:21:51+00:00","mainEntityOfPage":{"@id":"https:\/\/easydmarc.com\/blog\/zendesk-sender-authentication-spf-dkim\/"},"wordCount":1839,"commentCount":0,"publisher":{"@id":"https:\/\/easydmarc.com\/blog\/#organization"},"image":{"@id":"https:\/\/easydmarc.com\/blog\/zendesk-sender-authentication-spf-dkim\/#primaryimage"},"thumbnailUrl":"https:\/\/easydmarc.com\/blog\/wp-content\/uploads\/2026\/09\/Zendesk-SPF-DKIM-Hero.png","keywords":["Authentication"],"articleSection":["Blog","Email Authentication"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/easydmarc.com\/blog\/zendesk-sender-authentication-spf-dkim\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/easydmarc.com\/blog\/zendesk-sender-authentication-spf-dkim\/","url":"https:\/\/easydmarc.com\/blog\/zendesk-sender-authentication-spf-dkim\/","name":"Zendesk Sender Authentication: SPF & DKIM Changes | EasyDMARC","isPartOf":{"@id":"https:\/\/easydmarc.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/easydmarc.com\/blog\/zendesk-sender-authentication-spf-dkim\/#primaryimage"},"image":{"@id":"https:\/\/easydmarc.com\/blog\/zendesk-sender-authentication-spf-dkim\/#primaryimage"},"thumbnailUrl":"https:\/\/easydmarc.com\/blog\/wp-content\/uploads\/2026\/09\/Zendesk-SPF-DKIM-Hero.png","datePublished":"2026-09-29T20:19:08+00:00","dateModified":"2026-09-29T20:21:51+00:00","description":"Zendesk is making sender authentication the default. Learn how broken SPF or DKIM can suspend emails and what senders should do to avoid issues. Pasted markdown","breadcrumb":{"@id":"https:\/\/easydmarc.com\/blog\/zendesk-sender-authentication-spf-dkim\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/easydmarc.com\/blog\/zendesk-sender-authentication-spf-dkim\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/easydmarc.com\/blog\/zendesk-sender-authentication-spf-dkim\/#primaryimage","url":"https:\/\/easydmarc.com\/blog\/wp-content\/uploads\/2026\/09\/Zendesk-SPF-DKIM-Hero.png","contentUrl":"https:\/\/easydmarc.com\/blog\/wp-content\/uploads\/2026\/09\/Zendesk-SPF-DKIM-Hero.png","width":1440,"height":910},{"@type":"BreadcrumbList","@id":"https:\/\/easydmarc.com\/blog\/zendesk-sender-authentication-spf-dkim\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Startseite","item":"https:\/\/easydmarc.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https:\/\/easydmarc.com\/blog\/category\/blog\/"},{"@type":"ListItem","position":3,"name":"Email Security","item":"https:\/\/easydmarc.com\/blog\/category\/blog\/email-security\/"},{"@type":"ListItem","position":4,"name":"Email Authentication","item":"https:\/\/easydmarc.com\/blog\/category\/blog\/email-security\/email-authentication\/"},{"@type":"ListItem","position":5,"name":"Broken SPF or DKIM? Your Emails to Zendesk Support Desks May Never Arrive"}]},{"@type":"WebSite","@id":"https:\/\/easydmarc.com\/blog\/#website","url":"https:\/\/easydmarc.com\/blog\/","name":"EasyDMARC","description":"Blog","publisher":{"@id":"https:\/\/easydmarc.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/easydmarc.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/easydmarc.com\/blog\/#organization","name":"EasyDMARC","url":"https:\/\/easydmarc.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/easydmarc.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/easydmarc.com\/blog\/wp-content\/uploads\/2021\/09\/cropped-android-chrome-512x512-1.png","contentUrl":"https:\/\/easydmarc.com\/blog\/wp-content\/uploads\/2021\/09\/cropped-android-chrome-512x512-1.png","width":512,"height":512,"caption":"EasyDMARC"},"image":{"@id":"https:\/\/easydmarc.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/EasyDMARC\/","https:\/\/x.com\/easydmarc","https:\/\/www.linkedin.com\/company\/easydmarc\/mycompany\/"]},{"@type":"Person","@id":"https:\/\/easydmarc.com\/blog\/#\/schema\/person\/740e38b8d7f98e6c4141ae2931ca5a2a","name":"Hagop K.","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/bb6e65e2ae3c6e57f798515a978995b899d1d972034c909397efad978249be85?s=96&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/bb6e65e2ae3c6e57f798515a978995b899d1d972034c909397efad978249be85?s=96&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/bb6e65e2ae3c6e57f798515a978995b899d1d972034c909397efad978249be85?s=96&r=g","caption":"Hagop K."},"sameAs":["https:\/\/www.linkedin.com\/in\/hagopkhatchoian\/"],"url":"https:\/\/easydmarc.com\/blog\/author\/hagop-khatchoian\/"}]}},"jetpack_featured_media_url":"https:\/\/easydmarc.com\/blog\/wp-content\/uploads\/2026\/09\/Zendesk-SPF-DKIM-Hero.png","_links":{"self":[{"href":"https:\/\/easydmarc.com\/blog\/wp-json\/wp\/v2\/posts\/63674","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/easydmarc.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/easydmarc.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/easydmarc.com\/blog\/wp-json\/wp\/v2\/users\/25"}],"replies":[{"embeddable":true,"href":"https:\/\/easydmarc.com\/blog\/wp-json\/wp\/v2\/comments?post=63674"}],"version-history":[{"count":3,"href":"https:\/\/easydmarc.com\/blog\/wp-json\/wp\/v2\/posts\/63674\/revisions"}],"predecessor-version":[{"id":63678,"href":"https:\/\/easydmarc.com\/blog\/wp-json\/wp\/v2\/posts\/63674\/revisions\/63678"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/easydmarc.com\/blog\/wp-json\/wp\/v2\/media\/63675"}],"wp:attachment":[{"href":"https:\/\/easydmarc.com\/blog\/wp-json\/wp\/v2\/media?parent=63674"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/easydmarc.com\/blog\/wp-json\/wp\/v2\/categories?post=63674"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/easydmarc.com\/blog\/wp-json\/wp\/v2\/tags?post=63674"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}