Skip to content

Home Topics Email Authentication DKIM

Email Authentication · DKIM

DKIM signing for Gmail: setup and requirements

Short answer

Gmail weighs DKIM signing directly when deciding inbox placement. Gmail enforces bulk-sender rules: authentication, one-click unsubscribe, and spam-rate thresholds under 0.3% in Postmaster Tools. Follow the setup steps below and verify with a test message to a Gmail mailbox.

Gmail enforces bulk-sender rules: authentication, one-click unsubscribe, and spam-rate thresholds under 0.3% in Postmaster Tools.

What DKIM signing is#

DKIM (DomainKeys Identified Mail) adds a cryptographic signature header to each message. The public key lives in DNS under a selector, and receivers verify the signature to confirm the message was not altered and was authorized by the signing domain.

Why it matters#

DKIM survives forwarding where SPF breaks, carries domain reputation across sending IPs, and is the most reliable path to DMARC alignment for third-party senders.

Setting up DKIM signing for Gmail#

  1. Generate a 2048-bit key pair in your ESP or mail server (1024-bit keys are considered weak).
  2. Publish the public key as a TXT record at selector._domainkey.yourdomain.com.
  3. Enable signing in the sending platform and confirm the d= tag in outgoing headers matches your organizational domain.
  4. Send a test to a seed address and inspect the Authentication-Results header for dkim=pass.
  5. Schedule key rotation every 6 to 12 months using a second selector so old mail still verifies.
Example DKIM record
s1._domainkey.example.com.  IN TXT  "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA..."

How Gmail reports results#

Open a delivered test message in Gmail and view the original or headers. Look for Authentication-Results and any provider-specific verdict headers. Use the provider's sender dashboard for aggregate reputation.

Common mistakes#

  • Signing with the ESP's domain (d=esp.com) instead of yours, which passes DKIM but fails DMARC alignment.
  • Copying the public key with line breaks or quotes broken, producing a permanent verification failure.
  • Modifying message bodies after signing (footers injected by gateways) which invalidates the signature.
  • Never rotating keys, leaving a compromised key valid indefinitely.

Frequently asked questions#

What is a DKIM selector?

A label that lets one domain publish multiple keys. The selector appears in the s= tag and forms the DNS name selector._domainkey.domain.

Why does DKIM pass but DMARC fail?

Alignment. DMARC requires the d= domain to match the From header domain. If your vendor signs with their own domain, set up a custom DKIM domain with them.

Can I use one DKIM key for all my ESPs?

You can publish separate selectors per vendor. Never share private keys between platforms.

Does Gmail require DKIM signing?

Gmail enforces bulk-sender rules: authentication, one-click unsubscribe, and spam-rate thresholds under 0.3% in Postmaster Tools. Treat DKIM signing as required for any meaningful volume.

Analyse your own setup

All analysers
Technical analysis

DMARC record analyser

Grade a DMARC record on enforcement, not just syntax.

Runs in your browser
Technical analysis

DKIM key analyser

Check a DKIM public key's strength, revocation state, and tags.

Runs in your browser
Technical analysis

Email header analyser

Read authentication, DMARC alignment, and hop-by-hop delays from raw headers.

Runs in your browser

Keep reading on DKIM