Symptoms#
- Messages landing in spam despite previously good placement
- Bounces mentioning policy, authentication, or reputation
- Provider dashboards showing a drop in reputation or authentication pass rate
Diagnosis steps#
- Confirm the configuration is live: query DNS from an external resolver and check the sending platform's settings page.
- Send to a seed mailbox and read the full headers, especially Authentication-Results.
- Compare the domains in From, Return-Path, and DKIM d= for alignment.
- Check provider dashboards (Google Postmaster Tools, Microsoft SNDS) for reputation and error rates.
- Review recent changes: new vendors, DNS edits, list imports, volume spikes.
Likely causes#
- Signing with the ESP's domain (d=esp.com) instead of yours, which passes DKIM but fails DMARC alignment.
- Copying the public key with line breaks or quotes broken, producing a permanent verification failure.
- Modifying message bodies after signing (footers injected by gateways) which invalidates the signature.
- Never rotating keys, leaving a compromised key valid indefinitely.
Fix and re-verify#
- Generate a 2048-bit key pair in your ESP or mail server (1024-bit keys are considered weak).
- Publish the public key as a TXT record at selector._domainkey.yourdomain.com.
- Enable signing in the sending platform and confirm the d= tag in outgoing headers matches your organizational domain.
- Send a test to a seed address and inspect the Authentication-Results header for dkim=pass.
- Schedule key rotation every 6 to 12 months using a second selector so old mail still verifies.
Frequently asked questions#
What is a DKIM selector?
A label that lets one domain publish multiple keys. The selector appears in the s= tag and forms the DNS name selector._domainkey.domain.
Why does DKIM pass but DMARC fail?
Alignment. DMARC requires the d= domain to match the From header domain. If your vendor signs with their own domain, set up a custom DKIM domain with them.
Can I use one DKIM key for all my ESPs?
You can publish separate selectors per vendor. Never share private keys between platforms.