How to add a DKIM signature for your domain
DKIM adds a digital signature to every message so the receiving server can confirm the mail really came from you and was not altered in transit. It is one of the three pillars of deliverability alongside SPF and DMARC. Set it up right after SPF.
Check your site
-
Open Email Deliverability
In cPanel, under Email, open Email Deliverability and find your domain in the list. Its DKIM status is shown next to it.
-
Click Manage
Click Manage next to the domain. In the DKIM block cPanel has already generated a key pair and shows the recommended TXT record.
-
Install the record automatically if DNS is local
When the domain zone is served on this same server, just click Install the Suggested Record and cPanel adds the default._domainkey record for you.
-
Copy the record to external DNS if it lives elsewhere
If the domain uses your registrar's DNS or Cloudflare, copy the name default._domainkey and the value (v=DKIM1; k=rsa; p=...) and add a TXT record there by hand.
-
Paste the long value in full
A DKIM key is long. Some DNS panels require splitting it into quoted chunks - paste the value exactly, with no extra spaces or line breaks.
-
Confirm the status shows Valid
Return to Email Deliverability and refresh. The DKIM status should turn green and read Valid once DNS has propagated.
How to verify the result
Check the domain in the TechGuard email checker - it reports whether a DKIM record was found and whether the signature is correct.
Tip: Never trim the key value; losing even a few characters makes the signature invalid.
Related guides
Found problems?
Slow hosting, SSL trouble or frequent downtime? Move to TomisHost: fast hosting with free SSL, daily backups and free migration help.
TomisHost hosting