Blog

Email Deliverability articles

How to Set Up DKIM for Your Domain

A practical DKIM setup guide: how signing works, enabling it in Google Workspace and Microsoft 365, signing your own server with OpenDKIM, and testing.

5 min read Email Deliverability

DKIM puts a tamper-evident digital signature on every email your domain sends. Receiving servers check the signature against a public key in your DNS, and if it verifies, they know the message really was sent with your domain's authority and was not altered in transit. Major mailbox providers now expect it, and DMARC relies on it. This DKIM setup guide covers how it works, how to switch it on with the common providers, and how to sign mail from your own server.

How DKIM works in one minute

DKIM (DomainKeys Identified Mail, RFC 6376) uses a key pair. Your sending service holds the private key and uses it to sign selected headers and the body of each outgoing message. It adds the signature as a DKIM-Signature header:

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=example.com;
  s=mail2026; h=from:to:subject:date:message-id;
  bh=...; b=...

The two tags that matter for setup are d=, the signing domain, and s=, the selector. The receiver combines them to find the public key in DNS, at selector._domainkey.domain, in this case mail2026._domainkey.example.com. It then verifies the signature. Selectors let one domain have several keys at once: one per sending service, or an old and a new key during rotation.

A DKIM record looks like this:

mail2026._domainkey.example.com.  IN  TXT  "v=DKIM1; k=rsa; p=MIIBIjANBgkqh...IDAQAB"

Some providers instead ask you to create a CNAME at the selector name that points to a key they host, which lets them rotate keys without you editing DNS.

Before you start

  • Make a list of every service that sends email as your domain. Each one needs DKIM configured separately, using its own selector.
  • Have access to your DNS control panel. A WHOIS lookup shows which name servers your domain uses, if you are not sure where DNS is managed.
  • Use 2048-bit RSA keys where the provider offers a choice. 1024-bit keys are still accepted by many receivers but are considered weak.

DKIM setup in Google Workspace

  1. In the Google Admin console, go to Apps, Google Workspace, Gmail, then Authenticate email.
  2. Select your domain and generate a new record. Choose 2048-bit if your DNS provider supports long TXT values. The default selector is google.
  3. Copy the host name (google._domainkey) and the TXT value into a new TXT record at your DNS provider.
  4. Wait for DNS to update, then return to the Admin console and click Start authentication.

Until you do this, Google signs your mail with a default key for a Google-owned domain, which does not align with your own domain for DMARC.

DKIM setup in Microsoft 365

  1. In the Microsoft Defender portal, open Email & collaboration, Policies & rules, Threat policies, then Email authentication settings and the DKIM tab.
  2. Select your custom domain. Microsoft shows two CNAME records, for the selectors selector1._domainkey and selector2._domainkey, with tenant-specific targets.
  3. Create both CNAME records exactly as shown at your DNS provider.
  4. Once they resolve, enable signing for the domain in the portal.

Microsoft uses two selectors so it can rotate keys automatically: one is active while the other is prepared.

Marketing and transactional email services

Newsletter platforms, CRMs and transactional services such as Mailchimp, SendGrid, Amazon SES or Postmark all have a "domain authentication" or "sender authentication" section. They generate the records, usually CNAMEs, for you to publish. Do this even if mail "already sends fine": without it, they sign with their own domain, and your messages will fail DMARC alignment once you enforce a policy.

Signing mail from your own server

If you run your own Postfix server, OpenDKIM is a common choice on Linux. In outline, on Debian or Ubuntu:

sudo apt install opendkim opendkim-tools
sudo mkdir -p /etc/opendkim/keys/example.com
sudo opendkim-genkey -b 2048 -d example.com -s mail2026 \
     -D /etc/opendkim/keys/example.com
sudo chown -R opendkim:opendkim /etc/opendkim/keys

This creates mail2026.private (keep it secret) and mail2026.txt, which contains the DNS record to publish. You then configure OpenDKIM's key table and signing table to use that key for your domain, and connect it to Postfix as a milter using the smtpd_milters and non_smtpd_milters settings. Consult the OpenDKIM documentation for your distribution, because file locations differ.

Note that a 2048-bit public key is longer than 255 characters, the maximum length of a single TXT string. It must be split into several quoted strings in the same record, for example "v=DKIM1; k=rsa; p=MIIB..." "...IDAQAB". Most DNS control panels do this automatically when you paste the full value.

Testing DKIM

  1. Check the record exists: dig mail2026._domainkey.example.com TXT +short, or enter the domain and selector in our SPF, DKIM and DMARC checker.
  2. Send a message to an external mailbox and view the original message or full headers.
  3. In the Authentication-Results header, look for dkim=pass and header.d=example.com. If header.d shows the provider's domain instead of yours, custom-domain signing is not active yet.

Common failures

  • dkim=fail (body hash did not verify): something modified the message after signing, often a footer added by a gateway or mailing list.
  • no key for signature: the selector record is missing, at the wrong name, or not yet visible. Check for a doubled domain such as mail2026._domainkey.example.com.example.com.
  • Key syntax errors: stray spaces, quotes or line breaks pasted into the p= value.

Rotating keys

Changing keys periodically limits the damage if a private key leaks. Hosted providers often handle rotation for you. For your own server, publish a new selector, switch signing to it, then remove the old record a week or so later, once mail signed with the old key is no longer in transit.

Key takeaways

  • DKIM signs outgoing mail with a private key; receivers verify it with a public key published at selector._domainkey.
  • Every service that sends as your domain needs its own DKIM configuration with your domain in d=.
  • Use 2048-bit keys and confirm dkim=pass with your domain in real message headers.
  • DKIM survives forwarding, which makes it essential alongside SPF for DMARC.

Need help with this?

Netifi helps businesses around the world with Email Deliverability. Tell us what you are working on.