DKIM (DomainKeys Identified Mail) is an email authentication method that adds a digital signature to your outgoing emails so receiving mail servers can verify they really came from your domain and haven’t been altered in transit. This helps improve email security, deliverability, and reputation, and works together with SPF and DMARC to protect your domain from spoofing and phishing attacks.
🧠 What Is DKIM and Why It Matters
DKIM works by signing outgoing email with a private key and publishing the matching public key in your domain’s DNS records. When a mail server receives your email, it checks that public key to confirm:
✔ The message really came from an authorized sender
✔ The message has not been tampered with since it was signed
If the check passes, the email is more likely to reach the inbox instead of being marked as spam.
📋 Requirements Before You Start
Before you set up DKIM you’ll need:
✔ Access to your domain’s DNS settings (usually through your registrar or hosting provider).
✔ The ability to generate or obtain DKIM keys (public and private).
✔ Access to your email service or server configuration so outgoing mail can be signed.
🛠️ Step-by-Step DKIM Setup
1️⃣ Generate DKIM Keys
Most email service providers (like Google Workspace or Microsoft 365) generate DKIM keys for you. If you’re running your own mail server, you can use tools like OpenDKIM or a DKIM generator. The process creates:
A private key — installed on your email server to sign outgoing messages
A public key — added to your domain’s DNS so receivers can verify signatures
If your provider doesn’t generate keys automatically, you can use a DKIM key generator (like online tools).
2️⃣ Choose a DKIM Selector
A selector is like a label that helps mail servers find the right DKIM key in DNS. It’s usually a short name like default, mail, or key1. You’ll use this selector in your DNS record host name.
Example selector value:
selector1._domainkey.yourdomain.com
3️⃣ Publish the DKIM Public Key in DNS
You’ll now add the public key as a DNS record for your domain:
Log in to your DNS management panel.
Go to DNS settings or DNS zone editor.
Create a new TXT record with:
Host / Name:
<selector>._domainkey.<yourdomain.com>Value: The DKIM public key string starting with something like
v=DKIM1; k=rsa; p=...TTL: You can usually leave this at its default.
After saving, allow time for DNS propagation (up to 48 hours).
4️⃣ Enable DKIM Signing on Your Email System
Once the DNS record is live, you need to tell your email provider or server to start signing outgoing mail with the private key:
✔ If your email provider has a DKIM toggle (e.g., in admin console), turn it on.
✔ If you manage your own server (like OpenDKIM on a VPS), configure it to use the private key you generated.
5️⃣ Verify DKIM is Working
After setup:
✔ Use a DKIM checker tool (like MXToolbox DKIM lookup).
✔ Send a test email to an external address (e.g., Gmail) and check the email’s header — look for DKIM=pass.
This confirms that DKIM signing and DNS are configured properly.
📌 Best Practices
📍 Use a strong key length: 2048 bits is recommended if supported by your provider and DNS.
📍 Rotate keys periodically: Replace DKIM keys regularly (e.g., every 6–12 months) to keep your authentication strong.
📍 Keep SPF and DMARC configured too: DKIM works best alongside SPF and DMARC policies to prevent spoofing and improve deliverability.
📍 Test after changes: DNS propagation and setup verification are essential whenever you update your DKIM records.
🤔 Common Questions (FAQ)
Q1. What does DKIM stand for?
DKIM stands for DomainKeys Identified Mail — a method to authenticate email sent from your domain.
Q2. Why should I set up DKIM?
DKIM improves email deliverability, reduces spam filtering, and protects your domain from being spoofed or misused.
Q3. How long does DKIM setup take?
DNS changes can take up to 48 hours to fully propagate, but many setups work sooner.
Q4. Do I need DKIM if I already have SPF?
Yes — SPF only validates the sending server. DKIM adds authentication of the email content and is needed for stronger security, especially when using DMARC.
Q5. Can I use DKIM for multiple domains?
Yes — each domain you send mail from needs its own DKIM key and DNS record.
🛟 For Support
If you send email using a domain hosted with FimuroHost and want help configuring DKIM (including key generation, DNS records, or server signing setup), contact our 24/7 support via Live Chat, support tickets, or official social media pages — we’re happy to assist you at every step.
Categories
Written by
FimuroHost Team
Technical Writer