DKIM record checker: FAQs

What is a DKIM record?

A DKIM record is a DNS TXT record that contains the public cryptographic key used to verify the DomainKeys Identified Mail (DKIM) signature on outgoing emails. The record allows receiving email servers to authenticate that messages weren’t altered during transit.

What does a valid DKIM record look like?

A valid DKIM record includes several required tags, such as v=DKIM1 (version) and k=rsa (key type). The record must be correctly published in the DNS under the appropriate selector, and it must be free of syntax errors to be considered valid.

What happens if a DKIM record is incorrect?

If a DKIM record is incorrect, email authentication will fail. This can result in messages being marked as Spam or rejected by receiving servers. An invalid record also increases the risk of cybercriminals spoofing the domain or launching phishing attacks.

How do you fix a DKIM misconfiguration?

To fix a DKIM misconfiguration, confirm that the correct selector and domain names are used, ensure the record is accurately published in the DNS, and verify that the key’s format and length (we recommend 2048 bits) meet security standards. Test DKIM after to validate the correct configuration.

How does DKIM affect email deliverability?

DKIM improves email deliverability by authenticating that emails are legitimate and unmodified. This reduces the likelihood that messages will be filtered into Spam or rejected by recipient email servers, improving inbox placement.

Can you have multiple DKIM records?

Yes, multiple DKIM records can be published by using different selectors. This allows for the rotation of cryptographic keys and the use of separate keys for different email sources, improving security and operational flexibility.

Is DKIM necessary if SPF is already in place?

Yes, DKIM is still necessary even if the Sender Policy Framework (SPF) protocol is implemented. While SPF verifies the sending IP address, DKIM verifies the integrity and authenticity of the message content. When used together with Domain-based Message Authentication, Reporting, and Conformance (DMARC), SPF and DKIM provide a more complete email authentication strategy.

To ensure proper configuration, test DKIM and SPF records with validation tools. This helps verify SPF and DKIM implementation.

Resources

Knowledgebase