Email verification, Flex Credits, and Triple DES: Get ahead of these Salesforce changes

Email verification, Flex Credits, and Triple DES: Get ahead of these Salesforce changes

DHM Team
26 March 2026
Two people, men looking at a computer screen, working together. ,Furnituremaker
Two people, men looking at a computer screen, working together.
Two people, men looking at a computer screen, working together. ,Furnituremaker
Two people, men looking at a computer screen, working together.

Email verification, Flex Credits, and Triple DES: Get ahead of these Salesforce changes

DHM Team
26 March 2026

Email verification, Flex Credits, and Triple DES: Get ahead of these Salesforce changes

A few Salesforce updates are moving from helpful to operationally important, and they sit across security, cost visibility and release readiness. Taken together, they point to the same pattern. Teams need tighter control over how Salesforce sends emails, how consumption is tracked, and how quickly environments are prepared for upcoming platform changes.

Email domain verification

Salesforce now requires organisations to verify any email sending domains they own with DKIM or an authorised email domain, and emails from unverified domains are no longer delivered even if the individual email address itself is verified. For many organisations, that reaches further than marketing or sales emails and into system generated messages, workflow notifications and organisation wide email addresses. In practice, that means a technical setup issue can quickly become a service and communications issue if it’s left unchecked.

Note: this change applies to your Salesforce org email, not to your marketing platform, which uses separate domain authentication.

The timing matters. Salesforce says the requirement takes effect shortly after Spring ’26 patch 11, with allowlisted domains in sandboxes requiring verification from 7 April 2026 and allowlisted domains in production and other orgs requiring verification from 27 April 2026. If your team has relied on older email configurations, now is the time to verify every active domain and subdomain and enable a substitute email address for unverified domains to reduce disruption while that work is completed.

Digital Wallet

At the same time, Digital Wallet is becoming more useful as a day-to-day management tool rather than just a reporting layer. As Data 360 Services Credits move to Flex Credits, organisations can track consumption from Data 360 and Agentforce in one shared pool. That matters because it gives teams a clearer operational view of how data and AI activity are drawing on the same commercial model, instead of treating them as separate conversations. Salesforce also notes that volume based multipliers reduce cost as monthly consumption increases, which creates a stronger incentive to monitor usage patterns closely as adoption scales.

The addition of custom consumption tags makes that view more useful for the business. Teams can create their own tags around categories such as department or cost centre, which means consumption can be analysed in a way that reflects how the organisation actually budgets, governs and measures value. That’s a meaningful step for leaders trying to move AI and data programs beyond experimentation, because it becomes easier to see who is using what, where spend is concentrated and which parts of the business may need different controls or support. Salesforce says the staggered rollout began on 3 March 2026.

Preparing for Salesforce’s Summer ‘26 release

Looking ahead, release planning also needs attention. Salesforce’s Sandbox Preview Instructions confirm that preview sandboxes move to Summer ’26 on 8 and 9 May 2026, with non preview instances moving on 12 and 13 June 2026. Those dates matter because they shape the real testing window for configuration, integration and security checks before production changes land. Teams that treat release timing as a technical detail usually end up compressing testing into a much smaller window than expected.

One of the clearest reasons to start early is the retirement of Triple DES for SAML Single Sign On. Salesforce has confirmed that SAML SSO configurations using Triple DES will stop working in Summer ’26. For organisations still carrying older identity and access settings, this isn’t a background platform change. It’s a defined dependency with a fixed end point, and it needs to be handled as part of release readiness rather than left to a later security workstream.

The practical takeaway is straightforward. Verify your email sending domains now, use Digital Wallet to build a clearer view of shared Flex Credits consumption, and use custom tags to connect that usage back to business ownership. In parallel, confirm your sandbox and production upgrade windows in Salesforce Trust and check whether any SAML configurations still rely on Triple DES. Teams that act early will have more room to test properly and fewer surprises when Summer ’26 arrives.

If you need help with any of these updates, please get in touch with us.

InsightsRecent Articles