← back to the release
new featureExperience Cloud

Send Sensitive Emails Securely with a Secondary Sender Email Address

You can configure a verified secondary sender email address so that sensitive site emails (such as Forgot Password) are sent directly from the Salesforce MTA rather than through your corporate email relay, helping meet DMARC requirements without changing your primary domain's DKIM. Non-sensitive site emails still go through your configured relay. First released in late Summer '26.

identifiers
Secondary Sender EmailDMARCDKIMSalesforce MTA
flags
off by defaultno action required
how
Verify the email-sending subdomain, then in Workspaces > Administration > Emails set Secondary Sender Email and verify the address.
who
when
where
Aura, LWR, and Visualforce sites; Enterprise, Performance, Unlimited, and Developer editions.
read it on salesforce.com