Email & SMTP

Fix DKIM Configuration

Get DKIM actually signing your outgoing mail correctly, selector and all.

The Problem

DKIM is published but not validating — usually a mismatched selector, a key that doesn't match what's in DNS, or signing that was never switched on at the mail server or sending platform.

About this problem

DKIM breaks in one of three places: the DNS record itself (missing, wrong format, or wrong selector), the key pair (the private key used for signing doesn't match the public key published in DNS), or the mail server's own configuration (signing simply isn't switched on).

This comes up most often after a server migration where the old DKIM key wasn't carried over, or when DKIM was configured once but never actually enabled on the sending side.

What's Included

What's NOT Included

How It Works

  1. Diagnose exactly which of the three failure points (DNS, key pair, or server config) is causing the issue.
  2. Generate a new key pair if the existing one is lost, mismatched, or was never properly created.
  3. Publish the correct DKIM selector record in DNS with the matching public key.
  4. Enable and configure signing on the mail server or sending platform to use that selector and private key.
  5. Send a real test email and confirm the DKIM-Signature header validates end to end.

In practice: you buy the service, send over whatever access or details the job needs, I investigate and do the work, and you confirm it's resolved before we call it done.

Frequently Asked Questions

Why is my DKIM signature invalid?
Usually because the private key used to sign no longer matches the public key published in DNS — this happens after key regeneration, a server migration, or a copy-paste error when the record was first set up.
Can I fix DKIM without server access?
No — enabling signing requires configuring the mail server or sending platform itself, not just DNS, so some level of access or admin control on that side is needed.
Will fixing DKIM affect emails already sent?
No, DKIM signing happens at send time; it has no effect on mail that's already been delivered, only on what goes out after the fix.
Do I need a new DKIM selector every time I fix it?
Not necessarily — if the existing selector and key pair are sound, only the server-side signing configuration needs fixing; a new selector is only needed if the key itself is being replaced.
How do I know the DKIM fix actually worked?
By sending a real test email and checking that the DKIM-Signature header in the received message validates against the DNS-published key — anything less is just assuming it works.
Does every email platform support DKIM?
Most modern ones do, but the exact steps to enable it vary a lot between platforms, which is often where the original misconfiguration came from.
Please note: the price shown applies to a standard case matching the description above. Every situation is different, and if your request falls outside the normal scope of this service, I will explain this before doing any additional chargeable work. I will never silently turn a small job into an expensive project.
Running into an issue with a service you've already bought, or unsure which one fits your problem? Message me directly on WhatsApp — no ticket system, no bot.