Setup checklist#
- ☐ Generate a 2048-bit key pair in your ESP or mail server (1024-bit keys are considered weak).
- ☐ Publish the public key as a TXT record at selector._domainkey.yourdomain.com.
- ☐ Enable signing in the sending platform and confirm the d= tag in outgoing headers matches your organizational domain.
- ☐ Send a test to a seed address and inspect the Authentication-Results header for dkim=pass.
- ☐ Schedule key rotation every 6 to 12 months using a second selector so old mail still verifies.
Audit checklist#
- ☐ Confirm you are not: signing with the ESP's domain (d=esp.com) instead of yours, which passes DKIM but fails DMARC alignment.
- ☐ Confirm you are not: copying the public key with line breaks or quotes broken, producing a permanent verification failure.
- ☐ Confirm you are not: modifying message bodies after signing (footers injected by gateways) which invalidates the signature.
- ☐ Confirm you are not: never rotating keys, leaving a compromised key valid indefinitely.
Ongoing monitoring#
- ☐ Weekly: review provider dashboards (Postmaster Tools, SNDS) and bounce logs
- ☐ Monthly: re-run the setup verification after any vendor or DNS change
- ☐ Quarterly: full audit against this checklist
Frequently asked questions#
What is a DKIM selector?
A label that lets one domain publish multiple keys. The selector appears in the s= tag and forms the DNS name selector._domainkey.domain.
Why does DKIM pass but DMARC fail?
Alignment. DMARC requires the d= domain to match the From header domain. If your vendor signs with their own domain, set up a custom DKIM domain with them.
Can I use one DKIM key for all my ESPs?
You can publish separate selectors per vendor. Never share private keys between platforms.