Email & SMTP
Fix "DKIM Failed" Error
Diagnose and fix a DKIM signature failure showing up on your outgoing mail.
The Problem
Your mail is showing "DKIM: FAIL" or a report is flagging DKIM signature failures — meaning the cryptographic signature meant to prove the message wasn't altered either doesn't match or isn't verifying, even though you thought DKIM was already working.
About this problem
A DKIM failure means the signature attached to a message doesn't match what the DNS record says it should be — this can happen because the message was genuinely altered in transit (some mailing lists and security gateways modify content, legitimately breaking the signature), because the DKIM key was rotated without updating DNS, or because the sending platform's configuration has a subtle mismatch with the published selector.
It's particularly common right after switching email service providers, after a mailing list or forwarding service touches the message body or headers, or when a DKIM key was regenerated on one side without the other being updated.
What's Included
- Reviewing the exact failing message and headers to see what specifically broke the signature
- Checking the DKIM selector and public key in DNS against what the sending platform is actually using
- Confirming whether a mailing list, gateway or forwarding step is legitimately altering the message
- Correcting the DKIM key/selector mismatch and republishing DNS records as needed
- Verifying the fix with a real test send and inspecting the resulting signature
What's NOT Included
- DKIM failures caused by a third-party mailing list or security gateway that legitimately modifies messages (a known limitation, not a fixable misconfiguration)
- Setting up SPF or DMARC if they're also missing (separate or bundled services)
- Ongoing key rotation policy or ongoing DKIM key management
How It Works
- Pull the exact failing message headers and identify the DKIM selector being used to sign it.
- Look up that selector's public key in DNS and compare it against what the sending platform's private key should produce.
- Check whether anything in the delivery path (mailing list, security gateway, forwarding rule) modified the message after signing, which would legitimately break DKIM regardless of key correctness.
- If it's a genuine mismatch, correct the DNS record or re-point the sending platform to the right selector.
- If a key was recently rotated, confirm both the new key is published and the old one is still valid during any transition window.
- Send a live test message and inspect the resulting DKIM-Signature header and verification result to confirm it passes.
In practice: you buy the service, send over whatever access or details the job needs, I investigate and do the work, and you confirm it's resolved before we call it done.
Frequently Asked Questions
- What does "DKIM failed" mean?
- It means the cryptographic signature attached to a message doesn't match what your domain's DNS says it should, so receiving servers can't confirm the message is genuinely from you and unaltered.
- Can DKIM fail even if I didn't change anything?
- Yes — a mailing list, forwarding service or security gateway that modifies the message in transit can break a perfectly correct DKIM signature without any change on your end at all.
- Is a DKIM failure as serious as an SPF failure?
- It depends on your DMARC alignment settings — DMARC passes if either SPF or DKIM aligns, so a DKIM failure alone isn't always fatal if SPF is passing and aligned correctly.
- Why did DKIM stop working after I changed email providers?
- Each provider typically uses its own DKIM key and selector, so switching providers without updating the DNS selector record for the new one will cause signatures to fail verification.
- Can an old, unused DKIM selector cause problems?
- Generally no on its own, but leaving outdated selectors in DNS alongside the current one can cause confusion when debugging — it's good practice to remove ones you're certain are no longer used.
- How do I check if DKIM is working correctly right now?
- Sending a test message to a mailbox that shows full headers (or a dedicated DKIM-checking address) and reading the DKIM-Signature result in those headers confirms it directly.