What is DKIM and how does it work?
DKIM adds a digital signature to your emails so receivers can confirm they came from your domain. Learn how to turn it on in Google Workspace.
DKIM (DomainKeys Identified Mail) adds a hidden digital signature to every email you send. Receivers use a public key published in your DNS to check the signature. If it matches, they know the email really came from your domain and was not altered on the way.
How DKIM works
- Your email provider holds a private key and signs each outgoing email with it.
- You publish the matching public key in DNS, under a name made of a selector and
._domainkey, for examplegoogle._domainkey.example.com. - The receiving server reads the signature, fetches your public key and verifies it.
- A valid signature for your own domain is a strong trust signal, and it is what lets DMARC pass even when email is forwarded.
The selector lets one domain have several keys, one for each service that sends for it.
What it means for Distro users
Distro sends through your own Google account, so Google signs your emails. What matters is which domain the signature belongs to.
- Google Workspace on your own domain: Google Workspace provides DKIM keys in the Admin console. Until you turn DKIM on for your domain, Google may sign with a default Google key, but that signature does not match your domain, so it does not help DMARC.
- Free @gmail.com address: Google signs for gmail.com automatically. Nothing to set up.
- Alias on a different domain: that domain needs DKIM set up with whichever service sends its mail. See Send cold email from your custom-domain email.
Turn on DKIM in Google Workspace
Menu names change over time, so follow Google's current documentation alongside these general steps. You need a Google Workspace admin account and access to your DNS.
- In the Google Admin console, open the Gmail settings for your organisation and find the email authentication (DKIM) section.
- Select your domain and generate a new record. Google offers a key length; 2048-bit is the stronger option if your DNS provider supports long TXT values.
- Google shows a host name (usually
google._domainkey) and a long TXT value starting withv=DKIM1. - In your DNS provider, create a TXT record with that host name and value.
- Wait for DNS to update, then return to the Admin console and start authentication.
Example record
This is an example of the shape of a Google Workspace DKIM record. The key is shortened here. Always copy the exact value Google generates for your domain.
Type: TXT
Host: google._domainkey
Value: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...How to check it
- Run
nslookup -type=txt google._domainkey.example.com(Windows) ordig TXT google._domainkey.example.com +short(macOS, Linux). You should see thev=DKIM1value. - Send an email to a Gmail address, open it, choose Show original from the message menu and look for DKIM: PASS with your own domain.
Common mistakes
- Publishing the record but never starting authentication in the Admin console. Google keeps signing with its default key until you do.
- Broken values. Some DNS providers split long values or add quotes incorrectly. Paste the value exactly, and check your provider's guidance for long TXT records.
- Wrong host name. Some DNS providers add your domain automatically, so entering
google._domainkey.example.combecomesgoogle._domainkey.example.com.example.com. Enter only the part your provider expects. - Forgetting other senders. Each service that sends as your domain needs its own DKIM key with its own selector.
Once DKIM passes, set up DMARC to tell receivers what to do when checks fail.
Email us at hello@usedistro.com with what you tried and what you see. Signed in? Help & support in the app has walkthrough videos and a message form.