2 min read Sep 26, 2026

How to Set Up DKIM for Your Domain in StackCP

Turn on DKIM email signing in StackCP with the DomainKeys tool. Covers selectors, advanced options and what to do if your DNS is hosted elsewhere.

FimuroHost Team

FimuroHost Team

Technical Writer

Share Article

DKIM (DomainKeys Identified Mail) adds a digital signature to every email you send. Receiving servers check that signature against a public key published in your DNS, which proves the message really came from your domain and wasn't changed on the way. DKIM is one of the main things Gmail, Outlook and Yahoo look at when deciding whether to trust your mail.

In StackCP, DKIM is set up with the DomainKeys tool, which creates a 2048-bit key and publishes the public part as a TXT record for you.

Set up DKIM

  1. Log in to your FimuroHost client area at https://app.fimurohost.com, go to Services, select your hosting plan and click Login to Control Panel / StackCP.
  2. Click the DomainKeys icon.
  3. Make sure the correct domain is selected at the top of the page.
  4. Type a Selector. This is just a label for the key, so pick something meaningful such as mail2026 or office.
  5. Click Add Signature.
  6. If your domain uses FimuroHost nameservers (ns1.stackdns.com / ns2.stackdns.com), the TXT record is added automatically. Allow some time for DNS to update before testing.

If your DNS is hosted somewhere else

When your domain's nameservers point to another provider (Cloudflare, your registrar, etc.), StackCP can't publish the record for you. After adding the signature, copy the DNS Name and DNS Value that StackCP shows and create a TXT record with those details at your DNS provider.

Advanced options explained

The defaults are fine for almost everyone, but here's what each option does:

OptionWhat it does
SelectorA name you choose that identifies this key in DNS. Using a new selector lets you rotate keys later without breaking old ones.
Granularity / IdentityDefaults to * (all mailboxes). Enter a mailbox name such as sales to limit the key to that address.
NoteA private note for your own reference. It doesn't change the record.
Service TypeEmail or *.
CanonicalizationSimple or Relaxed. Relaxed tolerates small changes made to messages in transit (such as whitespace) and is usually the safer choice.
Expiry TimeHow long a signature stays valid. Default: 86400 seconds (1 day).
FlagsProduction for normal use, or Testing while you experiment.

Check that it works

  • Send an email to a Gmail address, open it, choose Show original and look for DKIM: PASS.
  • Remember to switch the flag to Production if you created the key in Testing mode.
  • For full protection, combine DKIM with an SPF record and a DMARC policy.

Need help?

If something doesn't work as described, our team is happy to take a look. Open a support ticket or message us on WhatsApp at 01818160926.

Categories

FimuroHost Team

Written by

FimuroHost Team

Technical Writer