Guide · DKIM

Check and set up your DKIM signature

DKIM (DomainKeys Identified Mail) adds a digital signature to every email. Recipients verify it with a public key from your DNS and can tell whether the message really comes from you and was not altered on the way. Mailsecurity24 finds your DKIM keys automatically, checks them daily and shows in your DMARC reports which senders sign correctly with your domain.

How does DKIM work?

Your mail server or mail service signs outgoing messages with a private key. The header states which domain signed (d=) and under which selector (s=) the matching public key is published – for example at selector1._domainkey.your-company.com. The recipient fetches this key and verifies the signature. For DMARC, the signing domain must also match your visible sender address.

Good to know: Many services sign with their own domain by default. That passes DKIM but does not count for DMARC – enable signing with your own domain in the service.

Set up DKIM in three steps

1. Enable DKIM in your service

In Microsoft 365, Google Workspace, your mail server or newsletter service, enable DKIM for your domain. The service gives you the selector and key or the records you need.

2. Publish the key in DNS

Create the TXT or CNAME record at selector._domainkey.your-company.com. Some services use two records for key rotation.

3. Check the signature

Test with the domain check and watch in Mailsecurity24 whether messages from this service pass DKIM with your domain.

Common DKIM mistakes

DKIM problems often only show up when the DMARC policy gets stricter and emails are suddenly rejected. Mailsecurity24 shows them beforehand:

Good to know: Unlike SPF, DKIM usually survives forwarding intact – which makes it especially important on the safe path to p=reject.

Free domain check

Is your domain protected against email spoofing?

In seconds we check DMARC, SPF, DKIM, MX, MTA-STS, TLS reporting and BIMI for your domain – free and without signing up.

  • No sign-up
  • Result in seconds
  • We do not store your domain

Frequently asked questions about DKIM

In the source of a sent email, it appears in the DKIM-Signature header after s=. Many services also name it in their documentation. Mailsecurity24 picks up selectors automatically from your DMARC reports and checks common selectors of major providers.

Yes. Each service uses its own selector, and one service can also have several keys in parallel – that is common during key rotation.

Usually the selector is unknown or the record sits under the wrong name. Check the exact name selector._domainkey.your-company.com and store your own selectors per domain in Mailsecurity24.

Many recommendations suggest every six to twelve months. Large services such as Microsoft 365 and Google Workspace provide their own rotation features with two selectors.

Ready for secure email?

Try Mailsecurity24 free for 14 days. No payment details required.