dnswatchdog.iodocs

Missing DKIM Record

The zone receives mail but no DKIM record was found.

Severity: Low

What does this mean?

Your zone publishes MX records — so it is set up to send and receive mail — but no DKIM record was found. DKIM (DomainKeys Identified Mail) lets your mail server cryptographically sign outgoing messages so that recipients can verify the message was authorised by your domain and was not altered in transit.

DKIM is published per selector, at selector._domainkey.domain, where the selector is chosen by your email provider. Because the provider generates the key and the selector, DKIM is configured at the provider rather than written directly into your zone.

Why this is a problem

Without DKIM, recipients cannot cryptographically verify that a message genuinely came from your domain, and they cannot detect whether it was tampered with in transit. This weakens your email authentication and makes your legitimate mail more likely to be treated as suspect. DKIM also underpins DMARC alignment, so mail without it has fewer ways to pass a DMARC check.

What you should do

  • Enable DKIM signing at your email provider
  • Publish the selector record the provider gives you, at selector._domainkey.domain
  • Confirm the record resolves once your provider reports the key is active

On this page