Skip to content
DKIM

DKIM not found: how to fix it

Why a checker finds no DKIM key for a domain, how to confirm it, and how to turn on DKIM signing in Microsoft 365, Google Workspace and other services.

By the Domain Health Hub team · Updated

In short
  • DKIM keys live at <selector>._domainkey.<domain>, and nobody can list a domain's selectors: a checker has to know or guess the name.
  • No key found means either DKIM isn't set up, or it uses a selector the checker didn't try.
  • Turn on signing in each service that sends your email and publish the key or CNAMEs it gives you.

What the error means

DKIM (DomainKeys Identified Mail, RFC 6376) adds a signature to every email. The receiving server reads the selector named in the signature and looks up the public key at <selector>._domainkey.<domain>. There is no DNS query that lists every selector, so a checker that hasn't seen one of your emails has to guess.

Without a selector to go on, we try the common ones: selector1, selector2, google, k1, s1, s2, default and mail. “Not found” means none of those has a key. If you've told us a selector in the domain's settings and it has no key, that's a firmer failure: the name you gave doesn't answer.

Why it matters

Without DKIM, a domain's email relies on SPF alone to pass DMARC. SPF breaks when email is forwarded, so forwarded messages fail DMARC, and once the policy is quarantine or reject they go to spam or bounce. Google and Yahoo also expect bulk senders to sign with DKIM.

How to confirm it

Send an email from the domain to a mailbox you can read, open the full headers, and find the DKIM-Signature header. Its s= tag is the selector and d= the signing domain. If there's no signature, or d= is the provider's domain instead of yours, DKIM isn't set up for your domain. The email test reads this for you.

How to fix it

Turn on DKIM in each service that sends as the domain, publish what it gives you, then add the selector name in the domain's settings so we check the right one.

Microsoft 365

In the Microsoft Defender portal, open the DKIM settings under email authentication and pick the domain. It shows two CNAME records, selector1._domainkey and selector2._domainkey. Copy their values exactly as shown, publish both, then switch signing on.

Google Workspace

In the Admin console go to Apps, Google Workspace, Gmail, Authenticate email. Generate a record with a 2048-bit key (the selector is google unless you change it), publish it as a TXT record, then press Start authentication.

Mailchimp and SendGrid

Both authenticate a domain with CNAME records shown on their domain authentication pages: SendGrid uses s1._domainkey and s2._domainkey, and Mailchimp two of its own (such as k2._domainkey). Copy the names and values they show.

google._domainkey.example.com TXT
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...

Questions

Does every sending service need its own DKIM key?

Yes. Each service signs with its own private key, so each needs its own selector in your DNS. Microsoft 365, a newsletter tool and a helpdesk would usually mean three sets of records.

Can I use DKIM without SPF?

DMARC passes if either SPF or DKIM passes and lines up with the From domain, so DKIM alone can carry DMARC. DKIM is the stronger of the two because it survives forwarding. Set up both if you can.

Hear about it the day it breaks.

Daily checks on every client domain, alerts when something changes, and a monthly report card your clients will understand.

Start 28-day free trial