What Is DKIM?
DKIM (DomainKeys Identified Mail) is a security standard that proves an email genuinely came from your business and hasn't been tampered with in transit. Think of it as a wax seal on a letter: it tells the recipient that the message is authentic and hasn't been opened or altered along the way.
Without DKIM, anyone can send an email that appears to come from your domain (your web address, such as yourshop.co.uk). Fraudsters do this constantly to scam your customers, and it can push your legitimate emails into spam folders too.
Why should a small business owner care?
If you send emails from your own domain, whether that's order confirmations, newsletters, or quotes, DKIM affects whether those emails actually land in inboxes.
Here is what happens without it:
- Your emails are more likely to be flagged as spam
- Scammers can impersonate your business by spoofing (faking) your email address
- Your customers could receive fraudulent emails that look like they came from you
- Your sender reputation (how trustworthy email providers think you are) gradually declines
Setting up DKIM takes around 15 to 30 minutes if you know where to look. This guide walks you through it step by step.
DKIM works best as part of a trio of email security settings. The other two are SPF and DMARC. You do not need all three today, but DKIM is a very solid place to start.
How does DKIM actually work?
DKIM uses two matching keys (codes), one private and one public, in a system defined by internet standard RFC 6376.
- Your private key lives on your email server and signs every outgoing email invisibly
- Your public key is published in your domain's DNS records (DNS stands for Domain Name System, which is the internet's address book that points people to your website and email)
- When an email arrives, the recipient's email server checks your public DNS record to verify the signature matches
If the signature checks out, the email passes. If it doesn't match, or there's no signature at all, the email looks suspicious.
You never actually see any of this happening. It runs behind the scenes automatically, once you've set it up.
Before you start: what you will need
| What you need | Where to find it |
|---|---|
| Access to your domain's DNS settings | Your domain registrar (e.g. 123 Reg, GoDaddy, Namecheap) |
| Access to your email platform | e.g. Google Workspace, Microsoft 365, Mailchimp |
| About 20 to 30 minutes | A quiet moment and a cup of tea |
💡 Not sure who manages your domain? Search your inbox for the original registration confirmation email, or check your bank statements for a payment to a domain provider.
Step 1: Generate your DKIM keys
Your DKIM keys are generated by your email sending platform, not by you manually. Most major platforms do this automatically and simply ask you to copy a DNS record and paste it into your domain settings.
Here is how to find your DKIM key in the most common platforms:
Google Workspace
Go to your Google Admin console at admin.google.com. Click Apps, then Google Workspace, then Gmail. Select Authenticate Email and choose your domain. Click Generate New Record and leave the settings on their defaults. Google will show you a DNS record to copy.
Microsoft 365
Log in to the Microsoft 365 Defender portal at security.microsoft.com. Go to Email and Collaboration, then Policies and Rules, then Threat Policies. Select DKIM and choose your domain. Toggle DKIM on. Microsoft will display two CNAME records (a type of DNS entry that points one address to another) for you to add to your DNS.
Mailchimp
Mailchimp sets up DKIM automatically when you authenticate your domain. Go to Account, then Domains, and follow the steps to verify your sending domain. Mailchimp will give you DNS records to add.
Zoho Mail
Go to the Zoho Mail Admin Console, click Domains, and select your domain. Choose Email Authentication, then DKIM. Click Add Selector, accept the default settings, and Zoho will generate the DNS record for you.
Step 2: Add the DNS record to your domain
Once you have your DKIM record from your email platform, you need to add it to your domain's DNS settings. This is where most people feel a little nervous, but it's simpler than it sounds.
- Log in to your domain registrar (where you bought your domain)
- Find the DNS management area, sometimes called DNS Zone, DNS Settings, or Manage DNS
- Add a new TXT record (a text-based DNS entry used for verification purposes)
- In the Name or Host field, paste the selector your email platform gave you (it usually looks something like
google._domainkey) - In the Value or Content field, paste the long string of characters your email platform generated
- Set the TTL (Time to Live, which controls how quickly the change spreads across the internet) to the default, usually 3600 or Auto
- Save the record
⚠️ DNS records are case-sensitive. Copy and paste them exactly as shown by your email platform. Do not retype them manually, as a single wrong character will cause the whole thing to fail.
Step 3: Verify that DKIM is working
DNS changes can take anywhere from a few minutes to 48 hours to spread across the internet, though most take effect within an hour or two.
Once you've waited a short while, go back to your email platform and look for a Check Status or Verify button. Most platforms will confirm whether DKIM is now active.
You can also test it for free using these tools:
- MXToolbox DKIM Lookup at mxtoolbox.com/dkim.aspx
- Mail Tester at mail-tester.com, which lets you send a test email and get a full report
- Google Admin Toolbox at toolbox.googleapps.com
Common problems and how to fix them
| Problem | Likely cause | Fix |
|---|---|---|
| DKIM shows as not found | DNS has not propagated yet | Wait an hour and check again |
| DKIM verification fails | Record copied incorrectly | Delete the record and re-paste it exactly |
| Multiple DKIM records conflicting | Old records left behind | Delete outdated DKIM records for the same selector |
| Platform says DKIM is active but emails still go to spam | Other issues at play | Check SPF and DMARC settings too |
If your emails are still ending up in spam folders after setting up DKIM, other factors may be involved. Our guide on why emails go to spam covers the full picture in plain English.
What about DMARC?
DMARC (Domain-based Message Authentication, Reporting and Conformance) is the third piece of the email security puzzle, after SPF and DKIM. It tells receiving email servers what to do if an email fails your DKIM or SPF checks, for example, reject it or send it to spam.
You don't need to set up DMARC today, but once your DKIM is working, it's the natural next step. Our guide on what DMARC is and how to set it up walks you through it clearly.
A quick summary
- DKIM proves your emails are genuinely from you
- It works using a digital signature checked automatically by receiving email servers
- You generate the key in your email platform, then add one DNS record to your domain
- The whole process takes under 30 minutes
- It helps your emails reach inboxes instead of spam folders
- It protects your customers from scammers pretending to be you
Check your current email setup for free
If you're not sure whether DKIM, SPF, or DMARC are already set up on your domain, or set up correctly, you can run a free check at website.auditmy.co.uk. It checks your domain and gives you a plain-English summary of what's in place and what's missing, with no technical knowledge required.
💡 Once DKIM is live, take five minutes to check your SPF record too. The two work together, and having both in place significantly strengthens your email security. Our guide on SPF and stopping emails going to spam is a good next read.
Sources: RFC 6376 (DKIM Signatures), Google Workspace Admin Help, Microsoft 365 Defender documentation, NCSC Email Security Guidance for small organisations.
Top comments (0)