← salesforce-sends-me-spam.org

What is X-SFDC-Binding?

And the other X-SFDC headers in email sent through Salesforce.

The short version X-SFDC-Binding is a header Salesforce adds to email sent through its servers. It identifies the sending pool the mail went out on, not the company that sent it. Lots of unrelated Salesforce customers can share one. If you want to know which customer sent an email, look at X-SFDC-LK instead: that's the org ID.

Where you'll see it

Every email that goes out through Salesforce's mail servers carries a set of headers starting with X-SFDC-. You won't see them in the normal view of an email. You have to open the full headers (in Gmail, the three dots next to Reply, then Show original). They look like this, from a real spam email I got:

Received: from smtp-03a6d7591fb0473cf.core1.sfdc-mchho0.mta.salesforce.com
X-SFDC-LK: 00Dd500000CqY6j
X-SFDC-User: 005d5000004fZ18
X-SFDC-Binding: iCBT705cy8bBFz3B
X-SFDC-EmailCategory: apiMassMail
X-SFDC-Interface: internal

What each one means

X-SFDC-Binding
A 16-character identifier for the sending pool, the slice of Salesforce's mail system the message went out through. Salesforce doesn't publish documentation on it that I've been able to find, so this is from reading a lot of these headers: the same binding shows up on mail from many unrelated customer accounts.
X-SFDC-LK
The org ID: the Salesforce customer account that sent the email. It starts with 00D and is 15 characters long. This is the one that identifies a customer.
X-SFDC-User
The user inside that org who sent it. It starts with 005.
X-SFDC-EmailCategory
How the email was sent. apiMassMail means a program sent it in bulk through Salesforce's interface for software, not a person clicking Send.
X-SFDC-EntityId
The Salesforce record the email was sent to. An ID starting with 00Q is a Lead record, meaning you're sitting in their system as a sales lead.

What the binding can and can't tell you

Out of the 189 spam emails I've gotten through Salesforce, 186 carried the same binding, iCBT705cy8bBFz3B. Those 186 came from 111 different Salesforce customer accounts and 123 different sender domains, pitching for dozens of different companies. The rest carried a different binding.

So two emails with the same binding didn't necessarily come from the same company. Don't claim they did in a report; you'll be wrong some of the time, and the abuse desk will discount the rest of what you say.

What the binding is good for is showing scale. If one pool carries spam from 111 customer accounts, that's a pattern Salesforce can look at as a whole, instead of one account at a time. Here's what happened when I asked them to.

How to use these headers in a spam report

Step-by-step: how to report spam sent through Salesforce. New to reading headers? Here's how to read email headers to find who really sent an email.