Email & SMTP

Fix "DKIM Failed" Error

Diagnose and fix a DKIM signature failure showing up on your outgoing mail.

The Problem

Your mail is showing "DKIM: FAIL" or a report is flagging DKIM signature failures — meaning the cryptographic signature meant to prove the message wasn't altered either doesn't match or isn't verifying, even though you thought DKIM was already working.

About this problem

A DKIM failure means the signature attached to a message doesn't match what the DNS record says it should be — this can happen because the message was genuinely altered in transit (some mailing lists and security gateways modify content, legitimately breaking the signature), because the DKIM key was rotated without updating DNS, or because the sending platform's configuration has a subtle mismatch with the published selector.

It's particularly common right after switching email service providers, after a mailing list or forwarding service touches the message body or headers, or when a DKIM key was regenerated on one side without the other being updated.

What's Included

What's NOT Included

How It Works

  1. Pull the exact failing message headers and identify the DKIM selector being used to sign it.
  2. Look up that selector's public key in DNS and compare it against what the sending platform's private key should produce.
  3. Check whether anything in the delivery path (mailing list, security gateway, forwarding rule) modified the message after signing, which would legitimately break DKIM regardless of key correctness.
  4. If it's a genuine mismatch, correct the DNS record or re-point the sending platform to the right selector.
  5. If a key was recently rotated, confirm both the new key is published and the old one is still valid during any transition window.
  6. Send a live test message and inspect the resulting DKIM-Signature header and verification result to confirm it passes.

In practice: you buy the service, send over whatever access or details the job needs, I investigate and do the work, and you confirm it's resolved before we call it done.

Frequently Asked Questions

What does "DKIM failed" mean?
It means the cryptographic signature attached to a message doesn't match what your domain's DNS says it should, so receiving servers can't confirm the message is genuinely from you and unaltered.
Can DKIM fail even if I didn't change anything?
Yes — a mailing list, forwarding service or security gateway that modifies the message in transit can break a perfectly correct DKIM signature without any change on your end at all.
Is a DKIM failure as serious as an SPF failure?
It depends on your DMARC alignment settings — DMARC passes if either SPF or DKIM aligns, so a DKIM failure alone isn't always fatal if SPF is passing and aligned correctly.
Why did DKIM stop working after I changed email providers?
Each provider typically uses its own DKIM key and selector, so switching providers without updating the DNS selector record for the new one will cause signatures to fail verification.
Can an old, unused DKIM selector cause problems?
Generally no on its own, but leaving outdated selectors in DNS alongside the current one can cause confusion when debugging — it's good practice to remove ones you're certain are no longer used.
How do I check if DKIM is working correctly right now?
Sending a test message to a mailbox that shows full headers (or a dedicated DKIM-checking address) and reading the DKIM-Signature result in those headers confirms it directly.
Please note: the price shown applies to a standard case matching the description above. Every situation is different, and if your request falls outside the normal scope of this service, I will explain this before doing any additional chargeable work. I will never silently turn a small job into an expensive project.
Running into an issue with a service you've already bought, or unsure which one fits your problem? Message me directly on WhatsApp — no ticket system, no bot.