If your business emails are routinely landing in recipients' spam folders, or worse, being silently rejected, the problem often comes down to missing email authentication records. DKIM (DomainKeys Identified Mail) is one of the three essential authentication standards — alongside SPF and DMARC — that every business using a custom domain email should configure. This guide walks you through setting up DKIM on a DirectAdmin hosting control panel from start to finish, including how to add the required DNS record and how to verify your configuration is working correctly.
What is DKIM and How Does It Work?
DKIM is an email authentication protocol that uses asymmetric cryptography (public-key cryptography) to prove that an email genuinely originated from the domain it claims. Here is how the process works at a high level:
- Your mail server holds a private key securely on the server side.
- When sending an email, the server adds a cryptographic digital signature to the email header using this private key.
- You publish the corresponding public key as a DNS TXT record under a subdomain like
mail._domainkey.yourdomain.com. - When the receiving server (Gmail, Outlook, etc.) gets your email, it queries your DNS for the public key and uses it to verify the signature in the header.
If the signature validates successfully, the receiving server knows two things: the email came from the claimed domain (authentication), and the message body was not tampered with in transit (integrity). Both of these factors contribute to your domain's sender reputation, which is a key signal email providers use when deciding whether to deliver your email to the inbox or to spam.
Since early 2024, Google has required all bulk senders — those sending more than 5,000 emails per day to Gmail — to have DKIM in place. This announcement signals that DKIM has transitioned from a best practice to an industry requirement.
SPF, DKIM and DMARC — Understanding the Trio
These three email authentication standards work as a layered system. Each covers a different attack vector and they complement each other. Setting up all three is strongly recommended:
| Standard | How It Works | What It Prevents | DNS Record Format |
|---|---|---|---|
| SPF | Lists IPs allowed to send email for your domain | Spammers spoofing your sending address | TXT @ — v=spf1 ... |
| DKIM | Signs emails with a verifiable digital signature | Message tampering and forgery | TXT mail._domainkey — v=DKIM1; k=rsa; p=... |
| DMARC | Policy for handling SPF/DKIM failures | Brand impersonation and phishing | TXT _dmarc — v=DMARC1; p=none/quarantine/reject |
The recommended setup order is SPF first, then DKIM, then DMARC — because a DMARC policy only becomes meaningful once at least one of SPF or DKIM is properly aligned.
Step-by-Step: Enabling DKIM in DirectAdmin
DirectAdmin includes built-in DKIM support. You do not need SSH access or manual server configuration. Everything is handled through the control panel interface.
Step 1 — Log into DirectAdmin
Open a browser and navigate to your DirectAdmin control panel. The default URL is:
https://yourdomain.com:2222 or https://your-server-ip:2222
Log in with your hosting account credentials (regular user level is sufficient — you do not need admin access).
Step 2 — Navigate to E-Mail Manager
From the DirectAdmin dashboard, locate the E-Mail Manager section. Depending on your DirectAdmin version, you will find DKIM under:
E-Mail Manager → Domain Administration → DKIM
In newer versions of DirectAdmin, a dedicated "DKIM Keys" menu item may appear directly within E-Mail Manager.
Step 3 — Generate the DKIM Key Pair
On the DKIM setup page, select the domain you want to configure, then click "Create DKIM Key" or "Generate DKIM". DirectAdmin will automatically generate a 2048-bit RSA key pair. The default selector name is mail.
After generation, DirectAdmin will display the Public Key as a DNS TXT record in the following format:
Name: mail._domainkey.yourdomain.com
Type: TXT
Value: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx==
Copy the entire p= value carefully. A truncated key will cause all DKIM verifications to fail.
Step 4 — Add the DNS TXT Record
If your domain uses AsiaGB nameservers, DirectAdmin manages your DNS zone directly and may add the record automatically when you generate the key. To verify or add manually:
E-Mail Manager → DNS Administration → Add TXT Record Hostname: mail._domainkey TTL: 3600 Type: TXT Value: v=DKIM1; k=rsa; p=YOUR_PUBLIC_KEY_HERE
If your domain uses external nameservers such as Cloudflare or your domain registrar's DNS, you will need to add this TXT record in their DNS management interface using the same values shown above.
Important: If the public key exceeds 255 characters (which 2048-bit keys typically do), some DNS providers require you to split it into multiple quoted strings: "part1" "part2". DirectAdmin displays the correct split format automatically. If you are copying to an external DNS panel, paste the entire value as-is and let the DNS provider handle splitting, or follow their specific instructions for long TXT records.
Configuring SPF Record Alongside DKIM
SPF should be configured together with DKIM for maximum effectiveness. Here is the recommended SPF record for a standard AsiaGB hosting setup:
Hostname: @ (or yourdomain.com) Type: TXT Value: v=spf1 a mx ip4:YOUR_SERVER_IP ~all
Breaking down each component:
v=spf1— declares this as an SPF version 1 recorda— authorizes the IP address in your domain's A recordmx— authorizes all IPs listed in your domain's MX recordsip4:YOUR_SERVER_IP— explicitly authorizes your server's IP address~all— SoftFail for any unlisted IPs (recommended when starting out; safer than-all)
If you also send email through third-party services such as Mailchimp or a CRM, include their SPF mechanisms:
v=spf1 a mx include:_spf.google.com include:servers.mcsv.net ip4:YOUR_SERVER_IP ~all
Critical rule: each domain must have exactly one SPF TXT record. Having multiple SPF records causes a permanent SPF error (PermError) that makes all email fail SPF validation.
Adding a DMARC Record
Once SPF and DKIM are working, add a DMARC record to tell receiving servers what to do when authentication checks fail. Start with a monitoring-only policy:
Hostname: _dmarc.yourdomain.com Type: TXT Value: v=DMARC1; p=none; rua=mailto:[email protected]; fo=1
Tag explanations:
p=none— monitor only, do not block any email yetrua=— send aggregate daily reports to this addressfo=1— generate forensic reports when either SPF or DKIM fails
After reviewing reports for one to two weeks and confirming SPF and DKIM are passing consistently, gradually tighten the policy to p=quarantine (route failing emails to spam), then eventually to p=reject (block failing emails outright).
How to Verify Your DKIM is Working
After adding the DNS record, wait at least 30 minutes (up to 24 hours for global propagation) before testing.
Method 1 — Use dig to Check the DNS Record
dig TXT mail._domainkey.yourdomain.com # Expected output: mail._domainkey.yourdomain.com. 3600 IN TXT "v=DKIM1; k=rsa; p=MIIBI..."
On Windows, use nslookup -type=TXT mail._domainkey.yourdomain.com instead.
Method 2 — Test with mail-tester.com
Visit mail-tester.com, copy the unique email address shown, and send a real email from your custom domain address to that address. After about a minute, click "Then check your score" to see whether SPF, DKIM and DMARC are all passing and receive a detailed deliverability score.
Method 3 — Inspect Gmail Headers
Send a test email to a Gmail account, open it, click the three-dot menu and select "Show original". Look for these lines:
Authentication-Results: mx.google.com; dkim=pass [email protected] header.s=mail header.b=AbCdEfGh; spf=pass (google.com: domain of [email protected] designates 1.2.3.4 as permitted sender)
Seeing dkim=pass and spf=pass confirms your configuration is working correctly.
Common Problems and How to Fix Them
Even when following the steps correctly, you may occasionally run into issues. Here are the most frequent problems and their solutions:
- DKIM fails immediately after setup — Almost always caused by DNS propagation not yet complete. Wait 1-24 hours and do not modify the key during this period, as changes reset the propagation clock.
- Truncated public key — Caused by incomplete copy-paste of the
p=value. Use DirectAdmin's "Copy to Clipboard" button rather than manually selecting the text to ensure the full key is captured. - Multiple DKIM records for the same selector — If you have generated keys multiple times, old records may still exist. Delete any duplicate
mail._domainkeyTXT records before adding a fresh one. - Forwarded emails fail DKIM — This is expected behavior. Email forwarders modify headers, which breaks the signature. The fix is to keep your DMARC policy at
p=noneorp=quarantinerather thanp=reject, since forwarded email is a legitimate edge case that DMARC does not handle well by design. - Score improves but email still goes to spam — DKIM is one of many spam signals. Check whether your server's IP address is listed on any blacklists using MXToolbox Blacklist Check. An IP reputation problem requires a different solution from authentication records.
Frequently Asked Questions (FAQ)
What is DKIM and why does it matter for email deliverability?
DKIM (DomainKeys Identified Mail) is an email authentication protocol that uses digital signatures to verify that an email was genuinely sent from the domain it claims to come from. The sending server signs each outgoing email with a private key, and receiving servers verify the signature using the corresponding public key published in DNS. When emails pass DKIM validation, services like Gmail and Outlook treat them as more trustworthy, significantly reducing the chance of landing in spam folders.
I set up DKIM on DirectAdmin but it still fails. What should I check?
The most common cause is DNS propagation delay — it can take up to 24-48 hours for DNS changes to take effect globally. Wait and retest using mail-tester.com or dkimvalidator.com. If it still fails after 48 hours, verify that the TXT Record value in your DNS Management matches exactly with the public key shown in DirectAdmin. Also confirm the selector used in outgoing emails (mail._domainkey) matches the DNS record name you added.
Do I need all three — SPF, DKIM and DMARC — or is DKIM alone enough?
In 2024, both Google and Yahoo mandated that bulk email senders must have SPF and DKIM authentication plus a DMARC policy of at least p=none. Even if you are not a bulk sender, deploying all three builds long-term domain reputation and reduces the risk of important business emails landing in spam, especially when sending to Gmail or Outlook recipients.
What is the difference between 1024-bit and 2048-bit DKIM keys?
1024-bit DKIM keys are considered cryptographically weak by current standards. NIST and security experts have recommended at least 2048-bit keys since 2015. DirectAdmin supports 2048-bit key generation by default and most DNS providers can store keys of this length. The only downside is a larger TXT record value which may need to be split into multi-string format in some DNS systems — DirectAdmin handles this automatically.
Business Email Hosting with Your Own Domain
AsiaGB Email includes SPF, DKIM and DMARC support for high deliverability. Starting from 200 THB/year.
View Email Plans