Skip to main content

Email

DKIM: the cryptographic signature that completes your email authentication trio.

Published 2026-04-29 · Last updated 2026-04-29 · Vantyris editorial

DKIM (DomainKeys Identified Mail) is the third leg of modern email authentication, alongside SPF and DMARC. SPF says 'these servers are allowed to send for me' and DMARC says 'here's what to do when SPF or DKIM fails'. DKIM adds a cryptographic signature to every outgoing email, which receiving servers check against a public key in your DNS. Without it, your DMARC enforcement is half-strength. Most email providers (Google Workspace, Microsoft 365, Mailgun, SendGrid) set up DKIM automatically. When it's missing, the reason is usually 'I didn't realise I had to enable it'.

What this means for your business

How to fix

In your email provider's admin console, enable DKIM signing. Copy the public key it generates and publish it as a TXT record at the <selector>._domainkey.<yourdomain> host.

  1. Locate the DKIM setting in your email provider. Google Workspace: Admin Console → Apps → Google Workspace → Gmail → Authenticate email → Generate new record. Microsoft 365: Security & Compliance Center → Threat management → Policy → DKIM. Mailgun / Postmark / SendGrid: the DKIM record is on the verification page of your sending-domain setup.
  2. Publish the TXT record. Your provider gives you a host (e.g., google._domainkey or selector1._domainkey) and a value (the public key, often 1000+ characters). At your DNS provider, add a TXT record at that host with that value. Some DNS panels split long values into 255-character strings. That's normal, and it works.
  3. Enable signing in the email provider's UI. Once the DNS record is live, go back to the email provider and click 'Start authentication' or 'Enable DKIM'. The provider checks the public key matches what it expects and starts signing outgoing mail.
  4. Test by sending yourself an email. Send a test message from your domain to a Gmail account you control. Open it and choose Show original from the three-dot menu. Look for dkim=pass in the headers. If you see dkim=fail, or no DKIM result at all, the public key didn't match.

Owner: Your email administrator (typically the same person who set up your inbox). · Time: 20 minutes once you've found the right setting.

Common gotchas

How to verify the fix

A Vantyris verified scan checks for DKIM support against your published TXT records. You can also send a test email to dkimvalidator.com (free), which checks the signature in detail.

Cyber Essentials alignment

This finding informs the following Cyber Essentials control areas (the UK government's baseline scheme, a sound checklist in any country):

Vantyris is not a CE certifying body. The mapping above is informational.

Common follow-up questions

Do I need DKIM if I already have SPF + DMARC?

Yes. SPF breaks on forwarded mail (mailing lists, redirect rules). DKIM survives forwarding because the signature is in the message itself. Without DKIM, your DMARC enforcement misses any mail that crosses a forwarder, which is much more common than it sounds.

What's a DKIM selector?

A label that lets you have multiple DKIM keys for the same domain. The selector appears in the DKIM-Signature header and tells receivers which public key to fetch. Common ones: default, google, selector1, s1. Pick any string. It only has to match the DNS host where you publish the public key.

Can I sign with multiple selectors at once?

Yes, and it's useful during key rotation. Publish the new selector, wait for it to propagate, switch the signing service to the new key, then retire the old selector. Most providers don't expose this directly. You'd need access to the SMTP-layer config.

References

Related explainers

Want Vantyris to check your domain for this and 196 other problems?

The teaser scan is free and needs no card. A verified scan starts at $10€10£10A$15¥1,500AED 40 and comes with the workspace: finding workflow, score trend, three PDF layouts, share links and monitoring.

Written by Vantyris