✓OutboundAuth
← All guides
News · SPF · Zendesk

Zendesk is now silently suspending emails with broken SPF — check yours in 30 seconds

If your business receives customer emails through Zendesk, some of them may have quietly stopped arriving. Since September 23, 2026, Zendesk suspends emails that fail SPF without a valid DKIM signature — filing them in the Suspended tickets view that most teams never check.

What changed on September 23, 2026?

Zendesk began phase 2 of its sender-authentication rollout. Accounts are being moved to what Zendesk calls a "Minimal" sender-authentication profile. Under this profile, an email that fails SPF — and doesn't have a valid DKIM signature to fall back on — no longer reaches your support inbox. Instead, Zendesk files it under the Suspended tickets view, a corner of the dashboard most teams never open.

Zendesk is migrating accounts on a rolling basis through December 2026, so even if your tickets look fine today, enforcement may not have reached you yet.

Why a broken SPF record is now worse than none

This is the part that surprises people. A missing SPF record gets treated with some leniency. But a record that exists and is misconfigured — too many DNS lookups, wrong syntax, outdated include entries — fails the check outright, and the email gets suspended. In other words: a sloppy SPF record now actively loses you customer emails, where having no record at all might have squeaked through.

The most common ways SPF breaks: exceeding the 10 DNS-lookup limit (each include and redirect counts), publishing more than one SPF record, and stale includes from tools you stopped using years ago.

Where do the suspended emails go?

To Admin → Suspended tickets in your Zendesk dashboard. Zendesk holds them there instead of creating tickets — no notification to the sender, no ticket for your agents. If you use Zendesk, check that view now: anything sitting there from the last few weeks may be legitimate customer email killed by authentication failures.

Check your own setup in 30 seconds

  1. Run your domain through the free SPF checker — it flags syntax errors and the 10-lookup limit that breaks most records.
  2. Check DKIM too — a valid DKIM signature can save emails that stumble on SPF. Every service that sends as your domain needs its own selector and signing enabled.
  3. Set a DMARC policy so you get aggregate reports when authentication fails — instead of finding out from missing customers. Start at p=none and move toward enforcement with the DMARC rollout guide.

What to do if tickets are already missing

  • Open the Suspended tickets view and release any legitimate messages.
  • Fix the underlying SPF/DKIM problem first — releasing tickets without fixing authentication just fills the suspended queue again.
  • Ask your email provider for the exact SPF include and DKIM selector to publish; don't guess the syntax.

Losing Zendesk tickets to failed authentication?

I fix SPF, DKIM, and DMARC setups for businesses — usually within a day, working with you directly.

WhatsApp Saqib See packages

Sources: SecurityBoulevard's coverage of the September 2026 Zendesk enforcement change, and Zendesk's official documentation on incoming email authentication (SPF, DKIM, DMARC and ARC).