Identify the signing service
DKIM attaches a domain-associated signature to email. A receiver uses the published key to verify selected message data. The signing service keeps the private key; DNS normally publishes the public key or a provider-directed record. Do not paste a private key into DNS or a troubleshooting message.
Different sending services can use different selectors. A domain's ordinary mailbox provider and its approved invoicing service may each need their own documented setup.
Follow the provider's configuration
- Open the genuine administration controls for the sending service. Confirm the domain and locate the current DKIM instructions, including exact owner names, record types and values.
- Inspect existing DNS for those names. Save current values before changing them and check whether the provider wants TXT records or CNAME records. Do not substitute one type for another without instructions.
- Publish the required records using your DNS provider's naming conventions. Some panels append the zone name automatically; accidentally appending it twice creates a different owner name.
- Enable signing when the mail provider indicates publication is ready. Send a harmless message through the actual service to a separate mailbox you control.
Verify the signature in a real message
Inspect the receiver's trusted authentication summary and original headers. Record whether DKIM passed and which signing domain and selector were used. A DNS record existing is necessary for many setups, but it does not prove that the service is signing outbound mail.
If the result fails, investigate the published record, selector, service activation and any message changes along the delivery path. Do not rotate keys repeatedly as a first response; that can make the evidence harder to interpret.
Check alignment separately
A valid signature from an unrelated service domain can be useful delivery evidence while failing to align with the visible From domain for DMARC. Confirm the relevant identity rather than treating any DKIM pass as proof that your own domain is protected.
Keep rotation and retirement controlled
Follow the provider's supported key-rotation process, retaining required overlap where documented. Retire obsolete selectors only after confirming that legitimate mail no longer depends on them. Keep an owner and change record for each sending service so a future administrator can distinguish an old key from an active integration.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.