DKIM (DomainKeys Identified Mail) puts a digital signature on every email your domain sends. Receiving servers such as Gmail and Outlook check that signature against a public key in your DNS, which tells them the message really came from your domain and was not changed on the way. This guide explains how DKIM works, what a DKIM record looks like, how to turn it on in the common control panels, and how to fix it when it fails.
DKIM needs two things: a mail server that signs outgoing mail with a private key, and a TXT record named selector._domainkey.yourdomain.com that publishes the matching public key. Most hosting panels create both for you; your job is to make sure the record is published in the DNS your domain actually uses. Use a 2048-bit key, run DKIM together with SPF and DMARC, and test by sending a message to Gmail and checking Show original.
1. What DKIM does and why it matters
Anyone can type your address into the From line of an email. DKIM gives receivers a way to tell your real mail apart from a forgery:
- Authenticity. Only a server holding your private key can create a valid signature for your domain.
- Integrity. The signature covers the message body and key headers, so a message altered in transit fails the check.
- Reputation. Mailbox providers track the reputation of the signing domain. Consistently signed mail builds a track record that helps it reach the inbox.
Since 2024, Gmail and Yahoo have required bulk senders to have SPF, DKIM and DMARC, and every sender needs at least SPF or DKIM. Microsoft applies similar rules for Outlook.com. In practice, a domain that sends business mail without DKIM is more likely to land in spam.
DKIM does not encrypt your email and does not stop spam on its own. It proves who sent a message; DMARC then tells receivers what to do when that proof is missing.
2. How DKIM works
- A key pair is created.The private key stays on the sending mail server. The public key goes into your DNS.
- The server signs each message.It hashes the body and chosen headers, signs the result with the private key, and adds a
DKIM-Signatureheader. - The receiver looks up the key.It reads the domain (
d=) and selector (s=) from the header and fetches the TXT record atselector._domainkey.domain. - The receiver verifies.If the signature matches the published key and the body hash matches the message, DKIM passes.
A signature header looks like this (shortened):
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yourdomain.com; s=default;
h=from:to:subject:date:message-id; bh=2jUSOH9N...; b=AuUoFEfDxT...3. The DKIM record explained
The public key is published as a TXT record. Its name is the selector followed by ._domainkey and your domain:
default._domainkey.yourdomain.com. IN TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA..."| Tag | Meaning | Notes |
|---|---|---|
| v=DKIM1 | Record version | Recommended; if present it must come first |
| k=rsa | Key type | RSA is the default and the one every receiver supports |
| p= | The public key | A long base64 string; an empty p= means the key is revoked |
| t=s | Strict mode | Optional; stops subdomains using this key |
The selector is just a label. It lets one domain publish several keys at once, for example one for your hosting server, one for Google Workspace and one for a newsletter service. Each sender uses its own selector, so the records never clash.
A 2048-bit RSA key is too long for a single 255-character DNS string. Most DNS editors split it for you; if yours asks for the value in parts, enter it as several quoted strings one after another, which receivers join back together.
4. Setting up DKIM on your own mail server
If you run your own mail server, for example Postfix on a VPS, you create the key yourself. OpenDKIM is the usual signing tool:
sudo apt install opendkim opendkim-tools # Debian/Ubuntu
sudo mkdir -p /etc/opendkim/keys/yourdomain.com
cd /etc/opendkim/keys/yourdomain.com
sudo opendkim-genkey -b 2048 -s mail2026 -d yourdomain.com
sudo chown opendkim:opendkim mail2026.private
sudo cat mail2026.txtThis creates mail2026.private (keep it secret and readable only by OpenDKIM) and mail2026.txt, which holds the TXT record to publish as mail2026._domainkey. Then configure OpenDKIM with the domain, selector and key path, connect it to Postfix as a milter, and restart both services. On AlmaLinux or Rocky Linux, OpenDKIM comes from the EPEL repository.
Our guide to setting up a mail server on your VPS covers the full Postfix setup. Before you run a mail server on a Domain India VPS, ask support about outbound port 25 and reverse DNS (PTR) for your IP.
5. DKIM in hosting control panels
On shared hosting you never handle the private key: the panel creates the key pair and signs your mail.
| Panel | Where DKIM lives | Selector |
|---|---|---|
| cPanel | Email › Email Deliverability, then Manage for the domain | default |
| DirectAdmin | E-mail Manager › E-mail Accounts shows Enable DKIM when it is off | x |
| Plesk | Mail settings for the domain, where the version offers DKIM signing | Set by Plesk |
| Google Workspace | Admin console › Apps › Gmail › Authenticate email |
cPanel. On Domain India cPanel hosting, DKIM is on by default for new accounts. Email Deliverability shows whether the DKIM and SPF records are valid, shows the exact values your domain needs, and can repair them when your domain uses our hosting nameservers.
DirectAdmin. On our DirectAdmin server the selector is x and most domains already have a key. The full walkthrough is in how to check and manage DKIM in DirectAdmin.
Plesk (Windows hosting). Menu names vary between Plesk versions. If you can't find a DKIM option for your domain, ask support.
Newsletter and transactional services such as Mailgun, SendGrid or Amazon SES give you their own DKIM records, often CNAMEs. Add them exactly as shown.
A panel writes the DKIM record into its own DNS zone. That zone only counts if your domain uses the hosting nameservers. If your DNS is at Cloudflare, your registrar or another provider, copy the TXT record there yourself, or DKIM fails for every message. Check where your DNS is managed in how do I change my nameservers.
6. Testing DKIM
- Gmail. Send a message to a Gmail address, open it, and choose Show original. Look for
DKIM: 'PASS' with domain yourdomain.com. - DNS lookup. Run
dig +short TXT default._domainkey.yourdomain.com(use your selector). On Windows:nslookup -type=TXT default._domainkey.yourdomain.com. You should see a value startingv=DKIM1. - Online checkers. MXToolbox's DKIM lookup takes your domain and selector. Mail-Tester scores a real message and shows the DKIM result along with SPF and DMARC.
To find your selector, look at the s= value in the DKIM-Signature header of a message you sent.
7. Common problems and fixes
| Symptom | Likely cause | Fix |
|---|---|---|
| No DKIM record found | Record missing where your DNS is hosted | Publish the TXT record at your active DNS provider |
| Signature fails: key mismatch | DNS holds an old key after a server move | Replace the TXT value with the current key |
| Body hash did not verify | A forwarder or mailing list changed the message | Test with a direct message; forwarded mail can fail legitimately |
| Record looks cut off | Value was pasted with line breaks or truncated | Paste the whole key again, with no added spaces |
| Pass for some mail, not all | A second service sends as your domain unsigned | Set up DKIM on every service that sends for you |
New DNS records usually work within minutes but can take longer depending on the TTL. Wait before assuming a fresh record is wrong.
8. Best practices
- Use 2048-bit keys. 1024-bit keys still validate but are weak for 2026; replace them when you can.
- Rotate keys. For your own mail server, publish a new selector, switch signing to it, and remove the old record after a week or two. On shared hosting, the panel manages the key.
- Don't use the
l=body-length tag. It lets someone append content to a signed message. - Pair DKIM with SPF and DMARC. DMARC checks that the DKIM domain aligns with your From address. Start with
p=none, read the reports, then tighten. See understanding SPF and setting up DMARC. - Review your senders. Each time you add a CRM, billing tool or newsletter service, add its DKIM record before it starts sending.
9. DKIM with Domain India
DKIM signing is available on our cPanel and DirectAdmin shared hosting. On cPanel it is on by default for new accounts, and on DirectAdmin most domains already have a key. Domain India Business Email, our separate per-mailbox email product, signs every message with DKIM and provides SPF and DMARC records for your domain.
- 25 GB NVMe SSD Storage
- 50 GB Monthly Bandwidth
- 1 Website
- 10 Email Accounts
- Priced per mailbox - start with one
- Email at your own domain ([email protected])
- Add and remove mailboxes yourself
- Webmail with calendar, contacts and tasks
Prices on the cards are live Domain India list prices and exclude 18% GST. For the full picture of SPF, DKIM, DMARC, MTA-STS and BIMI together, read the email deliverability deep-dive.
Frequently asked questions
What is DKIM in simple terms?
DKIM is an email authentication method. Your mail server signs each outgoing message with a private key, and receiving servers check the signature against a public key published in your domain's DNS. A valid signature shows the message came from your domain and was not altered.
What is a DKIM selector?
A selector is a label in the DKIM record name, as in selector._domainkey.yourdomain.com. It lets one domain publish several keys, one per sending service. cPanel uses the selector default and Domain India's DirectAdmin server uses x.
Is DKIM enabled on Domain India cPanel hosting?
Yes. DKIM is on by default for new cPanel accounts. You can check and repair the record in cPanel under Email › Email Deliverability.
Do I need to add the DKIM record myself?
Only if your domain's DNS is managed outside our hosting nameservers, for example at Cloudflare. Then copy the DKIM TXT record from your control panel to that DNS provider exactly as shown.
Should I use a 1024-bit or 2048-bit key?
Use 2048-bit. Receivers still accept 1024-bit keys, but 2048-bit is the current recommendation for security.
Why does DKIM fail for forwarded email?
Forwarders and mailing lists sometimes change the subject or body, which breaks the signature. This is expected. Test DKIM with a message sent directly to the recipient.
Is DKIM enough to keep my mail out of spam?
No. DKIM is one signal. You also need one correct SPF record, a DMARC record, a good sending reputation and sensible content.
Ready to check your domain? Look up your DKIM record, send a test message to Gmail, and compare the result with your panel's Email Deliverability page. If a record won't validate, open a support ticket with your domain name, or see Business Email for mail that is signed from day one.
Tell us your domain and where its DNS is managed, and we will check the DKIM key and record with you.
Open a support ticket