If your business emails are routinely landing in recipients' spam folders, or worse, being silently rejected, the problem often comes down to missing email authentication records. DKIM (DomainKeys Identified Mail) is one of the three essential authentication standards — alongside SPF and DMARC — that every business using a custom domain email should configure. This guide walks you through setting up DKIM on a DirectAdmin hosting control panel from start to finish, including how to add the required DNS record and how to verify your configuration is working correctly.

What is DKIM and How Does It Work?

DKIM is an email authentication protocol that uses asymmetric cryptography (public-key cryptography) to prove that an email genuinely originated from the domain it claims. Here is how the process works at a high level:

If the signature validates successfully, the receiving server knows two things: the email came from the claimed domain (authentication), and the message body was not tampered with in transit (integrity). Both of these factors contribute to your domain's sender reputation, which is a key signal email providers use when deciding whether to deliver your email to the inbox or to spam.

Since early 2024, Google has required all bulk senders — those sending more than 5,000 emails per day to Gmail — to have DKIM in place. This announcement signals that DKIM has transitioned from a best practice to an industry requirement.

SPF, DKIM and DMARC — Understanding the Trio

These three email authentication standards work as a layered system. Each covers a different attack vector and they complement each other. Setting up all three is strongly recommended:

Standard How It Works What It Prevents DNS Record Format
SPF Lists IPs allowed to send email for your domain Spammers spoofing your sending address TXT @ — v=spf1 ...
DKIM Signs emails with a verifiable digital signature Message tampering and forgery TXT mail._domainkey — v=DKIM1; k=rsa; p=...
DMARC Policy for handling SPF/DKIM failures Brand impersonation and phishing TXT _dmarc — v=DMARC1; p=none/quarantine/reject

The recommended setup order is SPF first, then DKIM, then DMARC — because a DMARC policy only becomes meaningful once at least one of SPF or DKIM is properly aligned.

Step-by-Step: Enabling DKIM in DirectAdmin

DirectAdmin includes built-in DKIM support. You do not need SSH access or manual server configuration. Everything is handled through the control panel interface.

Step 1 — Log into DirectAdmin

Open a browser and navigate to your DirectAdmin control panel. The default URL is:

https://yourdomain.com:2222
or
https://your-server-ip:2222

Log in with your hosting account credentials (regular user level is sufficient — you do not need admin access).

Step 2 — Navigate to E-Mail Manager

From the DirectAdmin dashboard, locate the E-Mail Manager section. Depending on your DirectAdmin version, you will find DKIM under:

E-Mail Manager → Domain Administration → DKIM

In newer versions of DirectAdmin, a dedicated "DKIM Keys" menu item may appear directly within E-Mail Manager.

Step 3 — Generate the DKIM Key Pair

On the DKIM setup page, select the domain you want to configure, then click "Create DKIM Key" or "Generate DKIM". DirectAdmin will automatically generate a 2048-bit RSA key pair. The default selector name is mail.

After generation, DirectAdmin will display the Public Key as a DNS TXT record in the following format:

Name:  mail._domainkey.yourdomain.com
Type:  TXT
Value: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA
       xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
       xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx==

Copy the entire p= value carefully. A truncated key will cause all DKIM verifications to fail.

Step 4 — Add the DNS TXT Record

If your domain uses AsiaGB nameservers, DirectAdmin manages your DNS zone directly and may add the record automatically when you generate the key. To verify or add manually:

E-Mail Manager → DNS Administration → Add TXT Record

Hostname: mail._domainkey
TTL:      3600
Type:     TXT
Value:    v=DKIM1; k=rsa; p=YOUR_PUBLIC_KEY_HERE

If your domain uses external nameservers such as Cloudflare or your domain registrar's DNS, you will need to add this TXT record in their DNS management interface using the same values shown above.

Important: If the public key exceeds 255 characters (which 2048-bit keys typically do), some DNS providers require you to split it into multiple quoted strings: "part1" "part2". DirectAdmin displays the correct split format automatically. If you are copying to an external DNS panel, paste the entire value as-is and let the DNS provider handle splitting, or follow their specific instructions for long TXT records.

Configuring SPF Record Alongside DKIM

SPF should be configured together with DKIM for maximum effectiveness. Here is the recommended SPF record for a standard AsiaGB hosting setup:

Hostname: @ (or yourdomain.com)
Type:     TXT
Value:    v=spf1 a mx ip4:YOUR_SERVER_IP ~all

Breaking down each component:

If you also send email through third-party services such as Mailchimp or a CRM, include their SPF mechanisms:

v=spf1 a mx include:_spf.google.com include:servers.mcsv.net ip4:YOUR_SERVER_IP ~all

Critical rule: each domain must have exactly one SPF TXT record. Having multiple SPF records causes a permanent SPF error (PermError) that makes all email fail SPF validation.

Adding a DMARC Record

Once SPF and DKIM are working, add a DMARC record to tell receiving servers what to do when authentication checks fail. Start with a monitoring-only policy:

Hostname: _dmarc.yourdomain.com
Type:     TXT
Value:    v=DMARC1; p=none; rua=mailto:[email protected]; fo=1

Tag explanations:

After reviewing reports for one to two weeks and confirming SPF and DKIM are passing consistently, gradually tighten the policy to p=quarantine (route failing emails to spam), then eventually to p=reject (block failing emails outright).

How to Verify Your DKIM is Working

After adding the DNS record, wait at least 30 minutes (up to 24 hours for global propagation) before testing.

Method 1 — Use dig to Check the DNS Record

dig TXT mail._domainkey.yourdomain.com

# Expected output:
mail._domainkey.yourdomain.com. 3600 IN TXT "v=DKIM1; k=rsa; p=MIIBI..."

On Windows, use nslookup -type=TXT mail._domainkey.yourdomain.com instead.

Method 2 — Test with mail-tester.com

Visit mail-tester.com, copy the unique email address shown, and send a real email from your custom domain address to that address. After about a minute, click "Then check your score" to see whether SPF, DKIM and DMARC are all passing and receive a detailed deliverability score.

Method 3 — Inspect Gmail Headers

Send a test email to a Gmail account, open it, click the three-dot menu and select "Show original". Look for these lines:

Authentication-Results: mx.google.com;
   dkim=pass [email protected] header.s=mail header.b=AbCdEfGh;
   spf=pass (google.com: domain of [email protected] designates 1.2.3.4 as permitted sender)

Seeing dkim=pass and spf=pass confirms your configuration is working correctly.

Common Problems and How to Fix Them

Even when following the steps correctly, you may occasionally run into issues. Here are the most frequent problems and their solutions:

Frequently Asked Questions (FAQ)

What is DKIM and why does it matter for email deliverability?

DKIM (DomainKeys Identified Mail) is an email authentication protocol that uses digital signatures to verify that an email was genuinely sent from the domain it claims to come from. The sending server signs each outgoing email with a private key, and receiving servers verify the signature using the corresponding public key published in DNS. When emails pass DKIM validation, services like Gmail and Outlook treat them as more trustworthy, significantly reducing the chance of landing in spam folders.

I set up DKIM on DirectAdmin but it still fails. What should I check?

The most common cause is DNS propagation delay — it can take up to 24-48 hours for DNS changes to take effect globally. Wait and retest using mail-tester.com or dkimvalidator.com. If it still fails after 48 hours, verify that the TXT Record value in your DNS Management matches exactly with the public key shown in DirectAdmin. Also confirm the selector used in outgoing emails (mail._domainkey) matches the DNS record name you added.

Do I need all three — SPF, DKIM and DMARC — or is DKIM alone enough?

In 2024, both Google and Yahoo mandated that bulk email senders must have SPF and DKIM authentication plus a DMARC policy of at least p=none. Even if you are not a bulk sender, deploying all three builds long-term domain reputation and reduces the risk of important business emails landing in spam, especially when sending to Gmail or Outlook recipients.

What is the difference between 1024-bit and 2048-bit DKIM keys?

1024-bit DKIM keys are considered cryptographically weak by current standards. NIST and security experts have recommended at least 2048-bit keys since 2015. DirectAdmin supports 2048-bit key generation by default and most DNS providers can store keys of this length. The only downside is a larger TXT record value which may need to be split into multi-string format in some DNS systems — DirectAdmin handles this automatically.

Business Email Hosting with Your Own Domain

AsiaGB Email includes SPF, DKIM and DMARC support for high deliverability. Starting from 200 THB/year.

View Email Plans