Set up DKIM: Sign emails and improve deliverability
DKIM adds a verifiable domain signature to outgoing email. This guide explains keys and selectors, shows how to configure the DNS record, and helps you verify DKIM in Google Workspace, Microsoft 365 or another email service.
Marco | 1 Oct 2026
Learn how DKIM works, how to create the correct DNS record, how to fix common errors and how to combine DKIM with SPF and DMARC for stronger email authentication.
The technical recommendations and sender requirements were reviewed on 1 October 2026. Email services can change their menus, DNS specifications and delivery policies. Always use the values provided for your own account.
What is DKIM?
DKIM stands for DomainKeys Identified Mail. It adds a cryptographic signature to outgoing email. The receiving mail server retrieves the corresponding public key from the sender domain's DNS and uses it to verify the signature.
A successful DKIM check shows that the message was signed by a system with access to the private key for the stated domain. It also helps detect whether protected parts of the message were changed after signing. DKIM does not encrypt the message and does not confirm the identity of an individual sender.
DKIM connects an email to a domain through a digital signature. The private key remains with the sending service, while the public key is published in DNS.
Why is DKIM important?
DKIM helps protect your domain against forged senders and creates a stronger technical basis for trust. Together with SPF and DMARC, it is now a core part of email authentication.
Gmail requires senders to personal Gmail accounts to use at least SPF or DKIM. Senders delivering more than 5,000 messages per day to Gmail accounts must use SPF, DKIM and DMARC. Google recommends using all three even below that threshold. Passing authentication does not guarantee inbox placement, but missing or faulty authentication can lead to spam placement or rejection.
DKIM is particularly useful for forwarded messages. SPF can fail because the forwarding infrastructure is not listed in the original domain's SPF record. An unchanged DKIM signature can still be verified.
How DKIM works

- Create a key pair: Your email provider or mail server generates a private key and a public key.
- Publish the public key: You add it to DNS as a TXT record or as the CNAME specified by your provider.
- Sign the message: The sending server calculates hashes for selected headers and the message body, then signs them with the private key.
- Read the selector: The receiving server takes the signing domain and selector from the DKIM signature.
- Query DNS: The selector points the recipient to the correct public key.
- Verify the signature: If the calculated values match, the result is normally
dkim=pass.
DKIM protects the signature against undetected changes. The message itself remains readable unless transport or end-to-end encryption is used separately.
What is a DKIM selector?
A selector is an identifier for a specific DKIM key. It appears in the signature as the s= parameter. Combined with the signing domain from d=, it creates the DNS name used to retrieve the key:
selector._domainkey.example.com
If your provider uses the selector mail2026, the complete name is mail2026._domainkey.example.com. Multiple selectors allow different sending services to use separate keys and make it possible to rotate keys without interrupting delivery.
Structure of a DKIM record
A public DKIM key published as a TXT record may begin like this:
v=DKIM1; k=rsa; p=MIIBIjANBgkqh...
v=DKIM1identifies the DKIM version.k=rsaidentifies the key type.p=contains the public key without any private key material.
This is only a shortened example and will not work for your domain. Copy the complete value supplied by your email service. Our guide to TXT records and examples explains the DNS record type in more detail.
How to set up DKIM step by step
1. Identify every sending service
List every service that sends email using your domain: normal mailboxes, newsletters, online shops, CRM systems, help desks, invoicing tools and transactional email services. Each service requires an appropriate DKIM configuration. One record does not automatically authenticate every sender.
2. Enable DKIM at the email service
Generate the key in your provider's administration area. If you operate your own mail server, the mail software handles key generation and signing. The private key must remain on the signing system and must never be published in DNS.
3. Add the DNS record
Create the record at the provider that manages your DNS zone. Some services require a TXT record, while others use one or more CNAME records. Copy the name, record type and target exactly as supplied. The article about TXT records provides additional DNS guidance.
4. Check DNS resolution
Allow for the update time stated by your DNS provider, then query the full selector name. The public key or CNAME target must be accessible externally. Check whether the DNS control panel automatically appends your domain; otherwise the domain can accidentally appear twice.
5. Start signing
For many services, publishing the DNS record is not enough. You must verify the record or explicitly start DKIM signing in the administration area. Send a new test message afterwards; previously sent messages are not changed retroactively.
6. Inspect the email headers
Open the full headers of the test message. The Authentication-Results field should show dkim=pass for the expected domain. Also inspect d= for the signing domain and s= for the selector.
Different sending services can use different DKIM selectors. Remove an existing record only after confirming that no active system still signs with that key.
DKIM in Google Workspace
Google Workspace generates a DKIM key in the administration console and displays the required TXT record. Google recommends 2048-bit keys when the DNS provider supports them. Sending to personal Gmail accounts requires a key of at least 1024 bits. After publishing the record, you start authentication in the Admin console.
Google notes that there may be a delay between enabling Gmail and generating a first DKIM key. A newly published DNS record can also take time to be detected.
DKIM in Microsoft 365
Microsoft 365 normally uses two selectors and corresponding CNAME records for custom domains. They point to public keys managed by Microsoft. After creating the CNAME records, you enable DKIM for the custom domain in the Microsoft 365 or Defender portal.
The two selectors support key rotation. The exact CNAME targets depend on the tenant and domain, so use only the values displayed for your own Microsoft 365 environment.
DKIM, SPF and DMARC compared
| Method | Main check | Important limitation |
|---|---|---|
| SPF | whether a sending server is authorised for a domain | can fail when mail is forwarded |
| DKIM | domain signature and unchanged signed message parts | does not determine whether the content is wanted |
| DMARC | alignment with the visible From domain and the domain policy | requires aligned SPF or DKIM authentication to pass |
For a reliable configuration, make sure SPF and DKIM work first. You can then introduce DMARC reporting and tighten the policy gradually.
What is DKIM alignment?
DMARC does not merely check whether any DKIM signature is valid. The domain in the DKIM d= parameter must also align with the visible domain in the From: header. Depending on the DMARC mode, the same organisational domain may be sufficient or an exact match may be required.
A message can therefore return dkim=pass and still fail DKIM alignment for DMARC. This can happen when a newsletter platform signs only with its own domain while your domain is shown as the visible sender.
Common DKIM errors
- Incorrect host name: The DNS provider automatically appends the domain and creates a duplicated name.
- Selector mismatch: The signature and published DNS name use different selectors.
- Signing not enabled: The DNS record exists, but the email service does not add a DKIM signature.
- Incomplete key: Characters are missing, quotation marks were copied incorrectly or the value was truncated.
- Message changed afterwards: Gateways, forwarding services or disclaimers modify signed parts.
- Wrong signing domain: DKIM passes, but the domain does not align with the visible sender.
- Old key removed too early: Messages signed with the previous selector are still in transit.
How to rotate DKIM keys safely
Create a new selector, publish its public key and wait until it resolves reliably in DNS. Only then switch the sending service to the new private key.
Keep the old public key available for a transition period so delayed messages can still be verified. Remove it only when no system signs with it. Document the selector, responsible service, activation date and planned rotation date.
DKIM setup checklist
- Every service that sends using the domain is documented.
- The private key exists only on the signing system.
- Selector, DNS name and record type match the provider's instructions.
- The public key can be resolved externally.
- DKIM signing has been enabled at the email service.
- A new test message returns
dkim=pass. - The DKIM domain aligns correctly for DMARC.
- SPF and DMARC have also been configured and checked.
If you still need a suitable service for mailboxes using your own domain, compare offers in our email hosting comparison.
Frequently asked questions about DKIM
Is DKIM mandatory?
There is no universal technical requirement for every domain. Major mailbox providers nevertheless impose authentication requirements. Gmail requires SPF or DKIM for all senders and SPF, DKIM and DMARC for bulk senders to personal Gmail accounts.
Can a domain have several DKIM records?
Yes. Each selector uses its own DNS name, allowing multiple sending services and old and new keys to operate at the same time.
How can I tell whether DKIM works?
Send a new message to an external mailbox and open the full headers. The Authentication-Results field should show dkim=pass for the expected domain.
Is DKIM enough without SPF and DMARC?
DKIM alone is better than no authentication, but it does not cover every risk. SPF authorises sending servers, while DMARC checks alignment with the visible sender and defines how failures should be handled.
Why can DKIM fail after forwarding?
Forwarding systems can alter the message body or protected headers. Even small changes such as footers, subject modifications or re-encoding can invalidate the signature.
DKIM is a central component of trustworthy email delivery. Configure a suitable selector for every sending service, publish the correct key in DNS and verify real test messages. Together with SPF, DMARC and regular key rotation, DKIM helps protect your domain against abuse and provides a stronger technical foundation for reliable delivery.
Write a comment
More web hosts
More interesting articles
What is Roundcube and what are the benefits?
Roundcube is a way to manage your emails with many web hosting providers. We show you the pros and cons.
What is IPv6 and what advantages does it offer?
IPv6 is supposed to be the answer to the scarcity of IPv4 addresses. What exactly changes and what are the advantages?