Email & SMTP
Fix DKIM Configuration
Get DKIM actually signing your outgoing mail correctly, selector and all.
The Problem
DKIM is published but not validating — usually a mismatched selector, a key that doesn't match what's in DNS, or signing that was never switched on at the mail server or sending platform.
About this problem
DKIM breaks in one of three places: the DNS record itself (missing, wrong format, or wrong selector), the key pair (the private key used for signing doesn't match the public key published in DNS), or the mail server's own configuration (signing simply isn't switched on).
This comes up most often after a server migration where the old DKIM key wasn't carried over, or when DKIM was configured once but never actually enabled on the sending side.
What's Included
- Generating or correcting the DKIM key pair if needed
- Publishing the correct selector record in DNS
- Enabling and verifying signing on your mail server or sending platform
- Confirming with a real test email that the signature validates end to end
What's NOT Included
- Setting up DKIM for a platform with no API or admin access I can use
- Fixing SPF or DMARC (separate services)
- Supporting multiple DKIM selectors for different sending tools beyond the ones specified
How It Works
- Diagnose exactly which of the three failure points (DNS, key pair, or server config) is causing the issue.
- Generate a new key pair if the existing one is lost, mismatched, or was never properly created.
- Publish the correct DKIM selector record in DNS with the matching public key.
- Enable and configure signing on the mail server or sending platform to use that selector and private key.
- Send a real test email and confirm the DKIM-Signature header validates end to end.
In practice: you buy the service, send over whatever access or details the job needs, I investigate and do the work, and you confirm it's resolved before we call it done.
Frequently Asked Questions
- Why is my DKIM signature invalid?
- Usually because the private key used to sign no longer matches the public key published in DNS — this happens after key regeneration, a server migration, or a copy-paste error when the record was first set up.
- Can I fix DKIM without server access?
- No — enabling signing requires configuring the mail server or sending platform itself, not just DNS, so some level of access or admin control on that side is needed.
- Will fixing DKIM affect emails already sent?
- No, DKIM signing happens at send time; it has no effect on mail that's already been delivered, only on what goes out after the fix.
- Do I need a new DKIM selector every time I fix it?
- Not necessarily — if the existing selector and key pair are sound, only the server-side signing configuration needs fixing; a new selector is only needed if the key itself is being replaced.
- How do I know the DKIM fix actually worked?
- By sending a real test email and checking that the DKIM-Signature header in the received message validates against the DNS-published key — anything less is just assuming it works.
- Does every email platform support DKIM?
- Most modern ones do, but the exact steps to enable it vary a lot between platforms, which is often where the original misconfiguration came from.