Email Authentication

DKIM record check

DKIM puts a tamper-proof signature on every email you send. Receivers use it to prove the message really came from you.

Check this on your own domain now. It is free with a DomainGuard account, reads only public records, and gives you a report you can send to whoever runs your website.

What we look at

We look for DKIM public keys under the selectors common mail providers use (for example selector1._domainkey for Microsoft 365 and google._domainkey for Google Workspace) and check that the key is published and usable.

Why it matters to your business

SPF can break when mail is forwarded. DKIM survives forwarding, which makes it the signature DMARC relies on most. Without it, legitimate mail from you is easier to mistake for spam, and you cannot move DMARC to a policy that blocks forgeries without risking your own mail.

How to fix it

  1. Turn on DKIM signing in your mail provider's admin console (Microsoft 365 Defender portal, or Google Admin under Apps → Gmail → Authenticate email).
  2. Publish the CNAME or TXT records the provider gives you, then switch signing on.
  3. Do the same for every other service that sends as your domain; most offer a DKIM setup page.

If you would rather not touch DNS or server settings yourself, forward this page and your report to whoever manages your website, or ask us to do it.

Keep an eye on it

A one-off check tells you how things stand today. On Starter and up, DomainGuard re-checks the domains it watches every day and alerts you in the app when something important changes, so you hear about it before a customer does.