Back to BlogEmail Security Guides

Zendesk Now Checks SPF and DKIM by Default: Will Your Emails Still Get Through?

StopSpoofingMe TeamPublished 7 min read

Zendesk is turning on inbound sender authentication by default. Starting September 23, 2026, it is gradually moving eligible accounts that have the feature switched off to a "Minimal" profile, which suspends email when SPF fails and DKIM is missing or fails. If you email any company's Zendesk support desk, check your SPF and DKIM now.

Key takeaways

  • Zendesk's new default sender authentication profile, called Minimal, suspends an incoming email when SPF fails and DKIM is either not set up or fails.
  • New Zendesk accounts already start on Minimal. From September 23, 2026, eligible existing accounts with sender authentication turned off are being moved to it in stages.
  • Zendesk's help center gives two end dates for that rollout, October 22 and December 16, 2026. Plan for the earlier one.
  • A working DKIM signature is your safety net: under Minimal, a message that fails SPF is not suspended if its DKIM signature passes.
  • Passing SPF and DKIM shows which domain authorized a message, not that the message is safe.

What happened?

Zendesk, the customer-service platform, is changing how it checks email arriving at its customers' support addresses. In a help center announcement, Zendesk says it is raising the minimum level of protection for all accounts by making a sender authentication profile called Minimal the default, as part of a move to a secure-by-default model. According to EasyDMARC, which analyzed the change, Zendesk published the announcement on June 18, 2026.

What does the Minimal profile do?

Zendesk's help center states the rule simply: under Minimal, an email is suspended when SPF fails and DKIM either isn't configured or fails.

As a refresher, SPF is a DNS record listing the servers allowed to send mail for a domain, and DKIM adds a digital signature to each message that the receiver checks against a public key in the sender's DNS. Based on Zendesk's description and EasyDMARC's analysis, Minimal works like this:

What Zendesk sees on an incoming email What happens under Minimal
SPF passes Not suspended by this rule
SPF fails, DKIM passes Not suspended by this rule
SPF fails, no DKIM signature Suspended
SPF fails, DKIM fails Suspended
No SPF record, DKIM fails Delivered but flagged as possible spoofing, according to EasyDMARC

When does the change reach existing accounts?

Zendesk is rolling this out in two phases:

  1. Phase 1: new accounts have sender authentication turned on and set to Minimal from the start.
  2. Phase 2: starting September 23, 2026, Zendesk is gradually moving eligible existing accounts that have sender authentication turned off to Minimal.

Zendesk's help center gives two different end dates for Phase 2: October 22, 2026 and December 16, 2026. EasyDMARC flagged the same mismatch. Until Zendesk clarifies, assume an affected account could switch at any point from September 23.

Why does this matter for your business?

If you email companies that use Zendesk

If a vendor, software provider or customer runs its support desk on Zendesk, and your domain's SPF check fails on a message without a valid DKIM signature, that message can be suspended instead of reaching an agent. As EasyDMARC's headline on the change puts it, your emails to Zendesk support desks may never arrive.

Common ways a legitimate business ends up with a failing SPF check:

  • A sending service isn't listed. Microsoft advises finding every source that sends mail for your domain, including on-premises servers, software-as-a-service providers and cloud hosting services, and covering each one in SPF.
  • The record is out of date. EasyDMARC warns that publishing an SPF record and then leaving it stale is now a real problem, because a failing SPF record with no working DKIM gets mail suspended.
  • The record is broken. Microsoft notes that more than one SPF record on a domain, or more than 10 DNS lookups, makes SPF return a permanent error instead of a pass.
  • The message was forwarded. Server-based forwarding breaks SPF, while a DKIM signature normally survives forwarding if the message isn't modified, according to Microsoft.

That last point is why DKIM carries so much weight: under Minimal, a message whose SPF check fails is not suspended by this rule as long as its DKIM signature passes.

EasyDMARC also points out an odd consequence: under Minimal, a broken SPF record can be worse than none, because suspension requires an SPF failure. Don't delete SPF, though. DMARC relies on SPF or DKIM passing, and other receivers, Microsoft 365 among them, check SPF too. Fix the record instead.

If you run a Zendesk account

Sender authentication matters because, as Microsoft's documentation explains, internet email by design makes no effort to confirm that senders are who they claim to be. Zendesk even has a help article on why accounts receive spoofed emails. Under Minimal, a forged message that fails SPF and lacks a valid DKIM signature is suspended. The cost is that real customers with broken authentication get suspended too.

What SPF and DKIM don't prove

Passing SPF and DKIM shows that some domain authorized a message, not that the message is safe or even that it came from the domain in the From line. Microsoft's documentation explains that an attacker can register a domain, set up SPF and DKIM for it, and send passing mail that shows a different domain in the From address; DMARC is what checks that those domains match. And no authentication check catches a lookalike domain or a genuine mailbox that criminals have taken over.

What should you do now?

For any business that emails support desks

  1. Scan your domain. Our free email domain scanner shows your SPF and DMARC records and looks for DKIM keys at common selector names. It can't guess every selector, so "no DKIM found" means "check," not "missing."
  2. List everything that sends as your domain. Include your mailbox provider, invoicing and billing tools, CRM, marketing platform, website forms and your own help desk. Cover them all in a single SPF record that stays within 10 DNS lookups. Our explainer on how SPF records work walks through the syntax.
  3. Turn on DKIM for every sending service, not just your main mailbox. Under Minimal, DKIM is the backstop when SPF fails.
  4. Send a test. Email a mailbox you control at a different provider, open the message headers and find the Authentication-Results line. You want to see spf=pass and dkim=pass, with header.d showing your own domain.
  5. Add DMARC and move toward enforcement. Microsoft recommends starting at p=none to collect reports, then moving to p=quarantine and finally p=reject. Our step-by-step DMARC setup guide covers each stage.

For Zendesk admins

  1. Check your current setting. Confirm whether sender authentication is on and which profile you use, and read Zendesk's announcement and its incoming email authentication article, both linked below.
  2. Plan for October 22, 2026, the earlier of the two end dates Zendesk lists.
  3. Watch suspended email after the switch. When a real customer or vendor gets caught, tell them their SPF or DKIM is failing so they can fix it.
  4. Fix causes rather than loosening checks. Relaxing sender authentication to clear suspensions reopens the door to spoofed senders.

If you'd like help finding every service that sends as your domain, call us at (818) 574-8240.

Frequently asked questions

Does this change affect email that Zendesk sends to my customers?

The change is about incoming email: the sender authentication checks Zendesk runs on messages arriving at a support address. Authenticating the replies your team sends from Zendesk under your own domain is a separate matter, though it's worth confirming while you're reviewing your email authentication anyway.

How can I tell whether my email to a Zendesk support desk was suspended?

You can't see another company's Zendesk account, so check your own side. Confirm that SPF and DKIM pass by sending a test message and scanning your domain. If a support desk seems to be ignoring you, contact them another way, such as by phone or chat, and ask whether your email was suspended.

Do I need DMARC for Zendesk's Minimal profile?

The Minimal rule itself is based on SPF and DKIM. Zendesk's incoming email authentication article also covers DMARC and ARC. Either way, DMARC is how you tell receivers to quarantine or reject email that forges your domain, so it belongs on every domain you send from, whether or not your contacts use Zendesk.

Sources

  1. Zendesk — Announcing a new security standard for sender authentication (June 18, 2026)
  2. Zendesk — Understanding and configuring incoming email authentication (SPF, DKIM, DMARC, and ARC) (help center article, undated)
  3. Zendesk — Why did I receive spoofed emails in my account? (help center article, undated)
  4. EasyDMARC — Broken SPF or DKIM? Your Emails to Zendesk Support Desks May Never Arrive (September 2026)
  5. Microsoft Learn — Email authentication in cloud organizations (reference documentation, undated)
  6. Microsoft Learn — Set up SPF to identify valid email sources for your custom cloud domains (reference documentation, undated)
  7. Microsoft Learn — Set up DKIM to sign mail from your cloud domain (reference documentation, undated)
  8. Microsoft Learn — Set up DMARC to validate the From address domain for cloud senders (reference documentation, undated)

Editor's note: This article was researched and written with AI assistance. Every factual claim was checked against the sources listed above; see our fact-check process for details.

Related Topics

zendesk sender authenticationzendesk suspended emailszendesk spf dkimemails to zendesk support not receivedzendesk minimal sender authentication profilecheck spf and dkim records

Ready to Secure Your Email?

Check your domain's email security status with our free scanner, or get professional help setting up DMARC, SPF, and DKIM.