Select location & language
  • Österreich German
  • Australia English
  • België Dutch
  • Canada English
  • Schweiz German
  • Deutschland German
  • Eesti English
  • Ελλάδα English
  • España Spanish
  • France French
  • Hrvatska English
  • Italia English
  • Latvija English
  • Lietuva English
  • Nederland Dutch
  • Norge Norwegian
  • Polska Polish
  • Portugal Portuguese
  • Slovensko English
  • Suomi Finnish
  • Sverige Swedish
  • United Kingdom English
  • United States English
  • American Samoa English
  • Andorra English
  • Anguilla English
  • Antarctica English
  • Bermuda English
  • British Indian Ocean Territory English
  • British Virgin Islands English
  • Cayman Islands English
  • Christmas Island English
  • Città del Vaticano English
  • Cocos (Keeling) Islands English
  • Falkland Islands English
  • French Southern Territories English
  • Gibraltar English
  • Guadeloupe French
  • Guam English
  • Guernsey English
  • Guyane française French
  • Heard & McDonald Islands English
  • Ireland English
  • Isle of Man English
  • Jersey English
  • Liechtenstein German
  • Luxembourg French
  • Malta English
  • Martinique French
  • Mayotte English
  • Monaco French
  • Montserrat English
  • New Zealand English
  • Norfolk Island English
  • Northern Mariana Islands English
  • Pitcairn Islands English
  • Puerto Rico Spanish
  • Réunion English
  • San Marino English
  • Slovenija English
  • St. Barthélemy English
  • St. Helena English
  • St. Martin English
  • St. Pierre & Miquelon English
  • Svalbard & Jan Mayen English
  • Turks & Caicos Islands English
  • U.S. Outlying Islands English
  • U.S. Virgin Islands English
  • Åland Islands English
  • Κύπρος English
  • Црна Гора English

What Is DKIM and How to Set It Up for Your Domain

1 min read

DKIM (DomainKeys Identified Mail) is an email authentication method that adds a digital signature to every message your domain sends. Receiving mail servers use that signature to confirm the message really came from your domain and was not altered along the way. Together with SPF and DMARC, DKIM is one of the pillars of good email deliverability and a strong defence against spoofing.

How DKIM works, in plain terms #

DKIM relies on a pair of cryptographic keys. A private key stays on your mail server and signs your outgoing messages, while a matching public key is published in your domain’s DNS as a TXT record. When your email arrives, the receiving server looks up the public key, checks the signature, and confirms the message is authentic and unchanged. If the check passes, your email is far more likely to be trusted.

Why you should enable DKIM #

  • Better inbox placement: signed mail is less likely to be treated as spam.
  • Protection against tampering: the signature proves the message was not modified.
  • Reputation: it strengthens your domain’s sending reputation over time.
  • Required for DMARC: DKIM (or SPF) alignment is needed for DMARC to work fully.

How to set up DKIM #

The good news is that most modern hosting control panels can generate the DKIM key for you, so you rarely need to handle the cryptography yourself. The general process is:

  • Log in to your control panel and open the Email or Authentication section.
  • Enable DKIM for your domain. The panel generates the key pair automatically.
  • If your DNS is managed by the same provider, the TXT record is usually added for you.
  • If your DNS is elsewhere, copy the DKIM TXT record shown and add it in your DNS manager.
  • Save and allow time for propagation.

Verifying DKIM is working #

After propagation, send a test email to an address you control and check the message headers, or use a free online DKIM checker. A passing result confirms your signature is valid. If you use an external email service, follow their specific DKIM instructions, since the record name and value are unique to each provider.

Troubleshooting #

  • DKIM check fails: confirm the TXT record was copied exactly, with no missing characters.
  • No signature on outgoing mail: make sure DKIM is enabled on the sending server.
  • Using multiple senders: each service needs its own DKIM record with its own selector.

Need help? #

If DKIM is not validating, our support team can help you check the key and DNS record over live chat.

What are your feelings