Activating a DKIM key
DKIM puts a digital signature on every message that leaves through 2Mail. The receiving server checks that signature against a public key in the DNS of your domain. Activation takes two moves: putting the record in your DNS and switching on signing in the dashboard.
Step 1: create the key in the dashboard
Open your sending domain in the 2Mail dashboard and have a DKIM key created under authentication. 2Mail then shows you two things: the name of the record, prefixed with a selector, and the value that goes in it. The private half of the key stays on our servers; you never have to enter it anywhere.
Step 2: put the record in your DNS
- Go to the DNS management of your registrar or hosting panel.
- Create a record of the type the dashboard indicates.
- As the name, enter only the part before your domain, i.e. the selector and the _domainkey part. Many panels append the domain themselves; if you type it in again, the record becomes unfindable.
- Paste the value literally. Some panels split long values automatically; that is fine, as long as you do not add spaces or line breaks yourself.
- Save.
Step 3: check and activate
Back in the dashboard, let 2Mail check the record. Once that succeeds, switch on signing. From that moment every message through our relay carries a signature on behalf of your domain. Send a test message to an external address straight away and look at the headers: the authentication results should show dkim=pass.
Several domains
DKIM is per sending domain. If you send from several domains, repeat these steps for each one. A subdomain — for instance a separate domain for newsletters — has its own record.
Replacing the key later
If you want to rotate the key, for example after a staff change or because a security policy requires it, create a new key in the dashboard with a different selector. Put the new record in your DNS, activate it, and only remove the old record a few days later. That keeps messages still in transit valid.
Where it goes wrong
- Record not found — the name was entered twice or the selector was copied wrongly.
- Invalid value — a space or line break slipped into the pasted value.
- dkim=fail at the recipient — an intermediate application alters the message after signing, for instance a signature tool or a disclaimer add-on.
Then switch on DMARC as well; how to read its reports is explained in reading DMARC reports in 2Mail. The background on all three records is on SPF, DKIM and DMARC.
Still stuck?
Send us your domain name and a screenshot of the record in your DNS panel via contact. We check what differs.
Does it behave differently than described above, or are you stuck anyway? Get in touch with your domain name or customer number at hand and we will take a look with you.
Contact support