DKIM (DomainKeys Identified Mail) adds a digital signature to every email you send. Receiving servers check that signature against a public key published in your DNS, which proves the message really came from your domain and wasn't changed on the way. DKIM is one of the main things Gmail, Outlook and Yahoo look at when deciding whether to trust your mail.
In StackCP, DKIM is set up with the DomainKeys tool, which creates a 2048-bit key and publishes the public part as a TXT record for you.
Set up DKIM
- Log in to your FimuroHost client area at https://app.fimurohost.com, go to Services, select your hosting plan and click Login to Control Panel / StackCP.
- Click the DomainKeys icon.
- Make sure the correct domain is selected at the top of the page.
- Type a Selector. This is just a label for the key, so pick something meaningful such as
mail2026oroffice. - Click Add Signature.
- If your domain uses FimuroHost nameservers (
ns1.stackdns.com/ns2.stackdns.com), the TXT record is added automatically. Allow some time for DNS to update before testing.
If your DNS is hosted somewhere else
When your domain's nameservers point to another provider (Cloudflare, your registrar, etc.), StackCP can't publish the record for you. After adding the signature, copy the DNS Name and DNS Value that StackCP shows and create a TXT record with those details at your DNS provider.
Advanced options explained
The defaults are fine for almost everyone, but here's what each option does:
| Option | What it does |
|---|---|
| Selector | A name you choose that identifies this key in DNS. Using a new selector lets you rotate keys later without breaking old ones. |
| Granularity / Identity | Defaults to * (all mailboxes). Enter a mailbox name such as sales to limit the key to that address. |
| Note | A private note for your own reference. It doesn't change the record. |
| Service Type | Email or *. |
| Canonicalization | Simple or Relaxed. Relaxed tolerates small changes made to messages in transit (such as whitespace) and is usually the safer choice. |
| Expiry Time | How long a signature stays valid. Default: 86400 seconds (1 day). |
| Flags | Production for normal use, or Testing while you experiment. |
Check that it works
- Send an email to a Gmail address, open it, choose Show original and look for
DKIM: PASS. - Remember to switch the flag to Production if you created the key in Testing mode.
- For full protection, combine DKIM with an SPF record and a DMARC policy.
Need help?
If something doesn't work as described, our team is happy to take a look. Open a support ticket or message us on WhatsApp at 01818160926.
Categories
Written by
FimuroHost Team
Technical Writer