Revenue Teams, Sales | June 20, 2026

What You Need to Know About Salesforce’s Security Update

Read time: 5 minutes

Written by:

  • Gerry Marletta
    Partner, SVP of Revenue Operations

Right now, in many Salesforce orgs, automated emails are failing to send. This is happening without an error log or bounce. The first anyone hears of it is a customer asking why the contract was never sent over.

This is just one result of the new security enforcements that Salesforce is rolling out through the end of July.

Every Salesforce admin in your organization would have seen the email, titled “Action Needed: Upgrade the Security of Your Salesforce Experience.” But the email itself makes it a riddle to find out which parts apply to your org, which actions are mandatory, and the deadlines for each change.

As we’ll get into in a second, this is going to result in real revenue loss for a lot of companies.

Deadlines to Watch For

Salesforce is enforcing MFA for all internal users, and a stricter phishing-resistant MFA for admins and anyone holding privileged permissions.

Sandboxes start June 22nd. Production starts July 1st and rolls out over roughly 30 days, so your org’s actual date could land anywhere from July 1st to late July. To keep everything running smoothly, you’ll want to make sure you’ve completed all of the mandatory actions for your org by July 1st.

What Happens if You Don’t Do This?

The next time a privileged user logs in after enforcement reaches your Salesforce org, they get prompted to register a phishing-resistant method. If they haven’t set one up ahead of time, that prompt is where they get stuck, and a stuck admin becomes a locked-out admin fast.

“Phishing-resistant” is specific, and it trips people up. It means a passkey, a built-in authenticator like Touch ID or Windows Hello, or a physical security key.

The authenticator app your team already uses does not qualify for these users. Neither do SMS or email codes.

This part will hurt some companies: if anyone needs a physical security key, it has to ship. That isn’t something you can quickly sort out the morning someone is locked out.

What’s Already Happening

Domain validation has been enforced in production for a few weeks now. If your sending domains aren’t verified, Salesforce silently drops the emails sent from your Flows, Apex, and workflow alerts.

No bounce. No error code. This makes it impossible to catch if someone isn’t looking for it.

Your sequenced follow-ups and your renewal reminders simply don’t arrive. This can easily lead to lost revenue for the company.

The check takes two minutes: Setup > DKIM Keys, and confirm you have an active key for each sending domain.

Integrations Will Start Breaking Next

This is the one we’d check first if we ran your Salesforce org.

A lot of third-party tools (the marketing platforms, data tools, and dialers plugged into your stack) don’t connect cleanly. Instead of authenticating through a dedicated API-only integration user or a proper External Client App, they log in as a normal, fully-licensed Salesforce user.

And that user has usually been handed broad admin permissions to make the integration work.

Once phishing-resistant MFA enforcement hits, Salesforce treats that login like any other privileged human. It expects a passkey, or a Touch ID tap, or a security key.

A headless integration running in the background has no way to present any of those.

So, that tool just stops. The connection fails to authenticate, the sync breaks, and data stops flowing. Again, this will happen with no visible error until something downstream is noticed.

Salesforce isn’t exactly making this easy to prepare for:

  • Salesforce only exempts true integration users that authenticate purely through the API. The exemption is judged by how the connection actually logs in, not by a setting you can toggle on
  • The old “Waive MFA for Exempt Users” permission no longer auto-exempts UI logins
  • Restoring an exemption for legitimate automation now means filing a case with Salesforce Support

What You Can Do Now

No two orgs walk into this the same way. How many admins you have, and the way each of your integrations actually authenticates, changes what’s urgent for you.

This is why we’re offering free 30-minute sessions to go through every action your org needs to take, tailored to you.

Due to the time commitment of this offer, it will only be available to the orgs we’re best at serving: B2B tech companies with over $50M ARR.

If this sounds like you:

Simply fill out the form below to let us know you’re interested in a free Salesforce Security Update Readiness Session.

Salesforce Security Update Readiness Session

This field is for validation purposes and should be left unchanged.
Your Name(Required)

 

But if that’s not for you, here’s a quick, general to-do list for your team:

  • Pull the list of everyone with System Administrator or privileged permissions, and confirm each one has a phishing-resistant method registered
  • Order security keys today for anyone who needs one
  • Check Setup > DKIM Keys and confirm your sending domains are verified
  • Audit how every connected app logs in, and flag any that authenticate as a licensed user with admin rights

Either way, get ahead of it while you still have room to. Once the deadlines pass, your options get a lot smaller.