New
Are you ready for Agentforce? Take our assessment to find out today!
    • Expertise
          • Product

          • Sales Cloud
          • Service Cloud
          • Account Engagement
          • Marketing Cloud Next
          • Revenue Cloud
          • Agentforce
          • Data 360 (Data Cloud)
          • CRM Analytics
          • Tableau Next
          • Experience Cloud
          • Industry

          • Manufacturing
          • Healthcare
          • High Tech
          • Financial Services
          • Media & Entertainment
    • Solutions
      • Consulting
      • Implementation
      • Managed Services
      • Health Check
      • Training
    • About Nebula
      • We Are Nebula
      • Meet the Team
      • Join Our Team
    • Resources
    • Login
    • Get in Touch
Share:

Behind the Scenes with Email Authentication

by Nebula Consulting
29th November 2018 • 4 min read
Nebula Consulting
Share:

Earlier this year, Nicola gave you insights into how best to get your emails into people’s inboxes. 

If you’re anything like me, you like to know exactly how everything works under the bonnet, especially when it comes to email. 

With that in mind, here’s exactly what’s going on when you authenticate your emails through Pardot:

When you send an email, the receiving mail server has an important job to do: protect the user of that account from potentially harmful (or at the very least inauthentic) messages.

To do this, the mail server is going to ask a key question:

Is this email from who it says it’s from and how do I know?

As email marketers, it’s incredibly useful to see how this process works, as it can have a huge impact on our emails landing in inboxes.

To find this out, the receiving mail server looks for specific items of information in your email and in the DNS records, (domain name system – essentially the phone book of the web), of your domain.

In doing this, it is trying to determine whether the email is legitimate, safe for its users to receive and whether the email is being sent from an authorised source.

But what exactly is it looking for?

SPF Records

The first thing it will look for is a SPF, or ‘Sender Policy Framework’ record, which basically means the mail server is making sure that the email has come from an IP address that it’s allowed to come from.

For example, if you’re sending an email from email@nebulaconsulting.co.uk from an IP such as 84.126.18.127, you would need to make sure that an SPF record was set up.

This allows emails coming from that IP to send from that email address.

This prevents email spammers from using spoofed email addresses and getting inauthentic messages delivered to you.

If the email is sent from a sending host or IP that is not in the SPF record, the receiving mail server can determine that the email is not coming from an authorised IP, and mark it as illegitimate.

DKIM Records

The next thing it looks for is DKIM (Domain Keys Identified Mail). 

This is an authentication method based on encrypting your emails with a signature.

This is unlike the standard signature that goes at the end your email; it’s a special signature found in the email header.

Once you have put DKIM in place, your emails will be much better positioned to reach the inbox.

You will also be helping protect yourself and your users against spam and phishing attempts.

The technical process

  • DKIM records are placed and verified – upon sending, all emails will then have a DKIM encrypted signature added to the email header
  • This encrypted signature is generated based on the DKIM key that you have added to the DNS records of your domain. It includes a hash string based on elements of the specific email being sent. Thus, each individual email you send will carry a unique DKIM signature
  • The receiving mail server then decrypts the DKIM signature using the public key that is hosted in your DNS records
  • It will also simultaneously generate a new hash string based on the same elements of the email that were used when the email was sent
  • If the decrypted signature matches the newly generated hash string then the email successfully passes DKIM authentication

The server can now safely determine that the owner of the domain where the DKIM key is located was responsible for sending the email.

It can also now see that the contents of your email were not modified in transit between the sender and the recipient.

What does that mean?

In basic terms this means that your server has checked that you are who you say you are (SPF) and that no-one has stolen your identity (DKIM).

By enabling email authentication, you are mitigating the potential for email fraud, and helping deliverability.

As Nicola mentioned previously, there are other factors that can impact how successfully your emails land in inboxes, however from a technical standpoint, ensuring your emails are passing authentication is key (pun intended).

You can find all technical documentation here.

Find related resources by topic

Marketing

You may also be interested in

Fix the Foundations: Success in the Agentic Era Marketing Edition
Blog
Marketing

Fix the Foundations: Success in the Agentic Era Marketing Edition

We hear the announcements and on repeat about how the Agentic Era is here to transform the B2B and B2C landscapes. These changes will enable…

4 min read Read Blog
Laying the Right Foundations
Success Story
Account Engagement Sales Cloud

Laying the Right Foundations

Complex processes and cautious stakeholders hindered Redwheel's CRM adoption. Nebula's Account Engagement and Salesforce audits mapped the journey, restoring confidence and delivering a strategic roadmap for a powerful, sales-enabled CRM.

May 27, 2025 Read Customer Story
How to Avoid Completion Action Limits in Account Engagement (Pardot) Using Engagement Studio
Blog
Marketing

How to Avoid Completion Action Limits in Account Engagement (Pardot) Using Engagement Studio

Conditional completion actions and completion actions, while powerful, can quickly consume the available limits on your forms and form handlers. If you’ve been creating and managing…

3 min read Read Blog
Aligning Marketing and Sales for a Global Insurer
Success Story
Account Engagement Sales Cloud

Aligning Marketing and Sales for a Global Insurer

Poor email deliverability and disconnected data misaligned Lockton's sales and marketing. Nebula's Salesforce and Account Engagement integration established governance, delivering a 97% delivery rate, 25 empowered users, and transparent insights.

Apr 30, 2025 Read Customer Story
Upgrade Your Form UX with Toggle Switches
Blog
Marketing

Upgrade Your Form UX with Toggle Switches

If you would like to modernise your forms, provide a slicker user experience, and match contemporary web design, follow our mini guide that helps you…

2 min read Read Blog
Creating a seamless membership experience
Success Story
Account Engagement Sales Cloud Service Cloud

Creating a seamless membership experience

Data silos and disparate systems hindered the World Travel and Tourism Council's membership experience. Nebula's Cvent integration, record cleansing and automated invoicing delivered rapid efficiency, unified data, and a 10-year partnership.

Jan 30, 2025 Read Customer Story
Account Engagement Landing Page Conversion Mastery
Blog
Marketing

Account Engagement Landing Page Conversion Mastery

Building pages that truly perform in Account Engagement isn't just about clicking buttons; it's about strategy, technical finesse, and empathy for the user. Here’s my…

5 min read Read Blog
Targeted Sales Enablement for Users
Success Story
Account Engagement CRM Analytics Sales Cloud

Targeted Sales Enablement for Users

Stale opportunities and missing data delayed Clarion Events' pipeline. Nebula's Einstein Next Best Action delivered intuitive guidance, surging stage moves by 132%, doubling activities, capturing crucial VAT details, and boosting CRM adoption.

Jan 3, 2025 Read Customer Story
5 Hidden Snags in Account Engagement
Blog
Marketing

5 Hidden Snags in Account Engagement

Managing Salesforce Account Engagement (Pardot) requires more than just marketing knowledge. Even in a well-established org, you can sometimes hit some invisible walls. Below are…

4 min read Read Blog
5 new Marketing Cloud Next features we’re excited to try
Blog
Marketing

5 new Marketing Cloud Next features we’re excited to try

The Spring ’26 release is here, and it’s a significant milestone for Marketing Cloud Next (also known as Agentforce Marketing). This release focuses on making…

4 min read Read Blog
Nebula

Our journey started in 2012 with a clear vision and core values. Nebula is dedicated to empowering our customers through fostering relationships founded on collaboration, flexibility, and trust.

  • We Are Nebula
  • Resources
  • Join Our Team
  • Terms and Conditions
  • Privacy Policy
The Space Aldgate,
Irongate House,
22-30 Dukes Place,
London EC3A 7LP
+44 207 112 8026
Get in Touch
Copyright © 2026 Nebula Consulting. All Rights Reserved.