Broken DKIM key: how to fix the record
Why a DKIM record's key can't be read, from copy-and-paste damage to badly split strings, and how to republish it so signatures verify.
By the Domain Health Hub team · Updated
- The p= value in a DKIM record is a base64 public key. One wrong character and it can't be read.
- The usual causes are copy-and-paste damage and long keys split badly into DNS strings.
- Copy the record from the email service again and republish it as one TXT record.
What the error means
A DKIM record holds tags such as v=DKIM1, k=rsa and p=, the public key in base64. Receivers decode the key and use it to check each signature. If the key doesn't decode, or decodes to something that isn't a valid key, every signature with that selector fails, even though a record exists.
"v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAx..." "...IDAQAB"
Common causes
- Split strings
- A TXT string holds at most 255 characters, so a 2048-bit key is split into several strings in one record. Splitting it into two separate records, or losing a part, breaks it.
- Copy and paste
- A missing first or last character, a line break, a space or a smart quote from a document or email.
- Literal quotes
- Quotes typed into a panel that adds its own end up inside the key.
- Wrong value
- The private key, or another selector's key, pasted by mistake.
How to confirm it
Look up the TXT record and compare the p= value, character by character at the start and end, with what the email service shows. Then send an email to a mailbox you can read: a dkim=fail or dkim=permerror result in the Authentication-Results header confirms it. The email test shows the same.
How to fix it
Delete the damaged record, copy the key again from the source, and publish it as a single TXT record at the same name.
Microsoft 365
Microsoft's DKIM records are CNAMEs to Microsoft, so the key itself is Microsoft's. If one is broken, check the two CNAME values match the Defender portal exactly.
Google Workspace
Copy the record again from Apps, Google Workspace, Gmail, Authenticate email. If your DNS provider can't take a 2048-bit key, Google lets you generate a 1024-bit one instead, though a provider that handles long records is the better fix.
Cloudflare DNS
Paste the whole value into one TXT record's content box. Cloudflare splits values over 255 characters into strings itself, so there's no need to break the key up.
Questions
Does an empty p= mean the record is broken?
No. An empty p= is how RFC 6376 marks a key as revoked: signatures with that selector fail on purpose. We don't count it as broken.
Do I need the quotes?
Only if your DNS provider asks for the record as quoted strings. Most add them for you, and typed quotes then end up inside the key.
Hear about it the day it breaks.
Daily checks on every client domain, alerts when something changes, and a monthly report card your clients will understand.