How to Set Up DKIM for Your Domain: A Step-by-Step Guide
Set up DKIM for your business domain: how selectors and keys work, TXT vs CNAME records, key length and rotation, testing, and fixing common DKIM errors.
On this page
To set up DKIM, enable signing in your email provider, which generates a key pair and gives you a selector. Then publish the public key in DNS at selector._domainkey.yourdomain, either as a TXT record containing the key or as a CNAME pointing to a key the provider hosts. Finally, send a test message and confirm the header shows dkim=pass for your domain.
What DKIM does and why it matters
DKIM (DomainKeys Identified Mail, RFC 6376) lets a receiving server verify two things about a message: that a particular domain took responsibility for it, and that the signed parts were not changed in transit. Your provider signs each outgoing message with a private key; receivers fetch the matching public key from your DNS and check the signature.
DKIM matters more than ever for three reasons:
- DMARC depends on it. DMARC passes when SPF or DKIM passes and aligns with the visible
From:domain. Because SPF breaks on forwarding, an aligned DKIM signature is often the only thing that keeps forwarded mail passing. - Mailbox providers require it. Since 2024 Gmail and Yahoo require bulk senders to have both SPF and DKIM, and DKIM strengthens reputation for everyone else.
- Reputation is tied to your domain. With aligned DKIM, receivers build sending reputation for
example.comrather than for a shared provider domain.
If you are new to the three standards, start with SPF, DKIM and DMARC explained.
How a DKIM signature works
When a message is signed, the provider adds a header like this:
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=example.com; s=zm1;
t=1791446400; h=from:to:subject:date:message-id:mime-version;
bh=2jUSOH9NhtVGCQWNr9BrIAPreKQjO6Sn7XIkfJVOzv8=;
b=dGhpcyBpcyBub3QgYSByZWFsIHNpZ25hdHVyZQ...The important tags:
d=— the signing domain. For DMARC alignment it must match (or, in relaxed mode, share the organisational domain with) yourFrom:domain.s=— the selector. It tells the receiver which key to fetch, so you can have several keys at once.h=— the list of headers covered by the signature.Fromis always included.bh=— a hash of the body;b=— the signature itself.c=— canonicalisation.relaxed/relaxedtolerates harmless whitespace and header-case changes.
The receiver combines selector and domain to find the key: zm1._domainkey.example.com.
Two ways to publish the key: TXT or CNAME
TXT record with the public key
The classic method. Your provider shows a record like:
selector1._domainkey.example.com. TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA..."A 2048-bit RSA key is about 400 characters long, more than the 255-character limit of a single TXT string. Good DNS providers split it into several quoted strings automatically; some older control panels need you to do it, or they truncate the value silently. When you rotate keys later, you must add a new TXT record yourself.
CNAME delegation to the provider
The modern method. You publish a CNAME at the selector name that points into the provider's DNS, and the provider publishes and rotates the actual key there:
zm1._domainkey.example.com. CNAME <target shown on your domain page>
zm2._domainkey.example.com. CNAME <target shown on your domain page>You set it up once. Key rotation happens on the provider's side without further DNS changes, and long-key formatting problems disappear. This is how Zomail publishes DKIM: two CNAMEs, zm1 and zm2, with automatic key rotation between them. The exact targets are shown on your domain page.
| TXT with key | CNAME delegation | |
|---|---|---|
| Records to create | One per selector | Two, once |
| Long-key splitting issues | Possible | None |
| Key rotation | Manual DNS change each time | Automatic |
| Who controls the key | You publish it | Provider publishes it |
Step-by-step: set up DKIM
- Enable DKIM in your email provider. In most services this is under domain settings. The provider generates the key pair and shows the DNS records. In Zomail, the keys are created automatically when you open the domain page.
- Copy the records exactly. Note the host name carefully. Many DNS panels automatically append your domain, so you enter
zm1._domainkey, notzm1._domainkey.example.com; otherwise you end up withzm1._domainkey.example.com.example.com. - Create the records at your DNS provider. For CNAMEs on Cloudflare, set them to DNS only (grey cloud). A proxied CNAME will not resolve to the key.
- Wait for DNS and verify. Check with:
dig +short CNAME zm1._domainkey.example.com
dig +short TXT zm1._domainkey.example.comThe second query follows the CNAME and should return a v=DKIM1 key.
- Send a test message to a Gmail or Outlook.com address. In Gmail, open Show original: you should see
DKIM: 'PASS' with domain example.com. TheAuthentication-Resultsheader shows the detail:
Authentication-Results: mx.google.com;
dkim=pass header.i=@example.com header.s=zm1 header.b=dGhpcyBp- Repeat for every other sender. Your newsletter tool, helpdesk and invoicing software should each sign with your domain (
d=example.com), using their own selectors such ass1._domainkeyormte1._domainkey. Otherwise their mail may pass DKIM for the vendor's domain but fail DMARC alignment for yours.
Key length and rotation
- Key length: RFC 8301 requires verifiers to support RSA keys of 1024 to 4096 bits and says signers should use at least 2048 bits. Use 2048-bit RSA; 1024-bit keys are considered weak and some receivers treat them with suspicion.
- Ed25519: RFC 8463 adds Ed25519 signatures, which are short and fast, but receiver support is not universal, so it is used alongside RSA rather than instead of it.
- Rotation: rotating keys limits the damage if a private key leaks. With TXT records, publish the new key under a new selector, switch signing to it, and keep the old public key in DNS for several days so messages still in transit can be verified. With CNAME delegation, the provider does this for you. Zomail publishes the new key under the second selector, switches once DNS shows it, and retires the old one later.
- Revoking a key: publishing a record with an empty
p=value tells receivers the key has been revoked.
Troubleshooting DKIM failures
- **
dkim=neutral (no key)orpermerror** — the record is missing, at the wrong name, or the key was truncated. Check the host name and the full value withdig. - **
dkim=fail (body hash did not verify)** — something changed the body after signing: a mailing list footer, an antivirus gateway adding a disclaimer, or an outbound relay rewriting content. Sign at the last hop or disable modification. - DKIM passes but DMARC fails — the signature is for another domain (
d=vendor.example). Configure the vendor to sign with your domain. - Works for some recipients, not others — often a DNS change that has not propagated everywhere, or a selector record that was deleted while mail signed with it was still being delivered.
- **Avoid the
l=tag** (body length limit) if your provider offers it; it allows content to be appended to a signed message.
DKIM is the foundation for DMARC enforcement. Once your signatures pass, follow the DMARC policy guide to move from monitoring to p=reject, and keep your SPF record tidy as well.
DKIM with Zomail
Zomail creates DKIM keys for each domain automatically and publishes them through the two zm1/zm2 CNAMEs, so rotation needs no further DNS work. The domain page checks both records live alongside MX, SPF and DMARC, and you can import them with a zone file or one-click Domain Connect where supported. Read the getting started guide for the full walkthrough, or see plans on the pricing page.
FAQ
What is a DKIM selector?
A selector is a label that tells receivers which public key to use. It appears as s= in the signature and as the first part of the DNS name, for example zm1 in zm1._domainkey.example.com. Selectors let a domain have several keys at once, for different services or during rotation.
Can I have more than one DKIM record?
Yes. Unlike SPF, you can have any number of DKIM keys, each under its own selector. Your mailbox provider, newsletter tool and helpdesk can all sign with your domain using different selectors.
Should I use a 1024-bit or 2048-bit DKIM key?
Use 2048-bit RSA. RFC 8301 recommends at least 2048 bits for signers, and 1024-bit keys are considered weak. If your DNS panel struggles with long TXT values, CNAME delegation avoids the problem entirely.
How do I check if DKIM is working?
Send a message to a Gmail address, open Show original and look for DKIM: 'PASS' with domain yourdomain. You can also look up the key with dig TXT selector._domainkey.yourdomain and confirm it returns a v=DKIM1 record.
Why does DKIM fail on forwarded mail?
DKIM usually survives forwarding. It fails when the forwarder changes the signed content, typically a mailing list adding a footer or rewriting the subject. In that case the receiver may rely on ARC headers added by the forwarder, if it trusts them.