Outbound Wiki

Article

Create and manage a DKIM record

ncsc.gov.uk

Open at publisher

Quoted on this wiki

Every place a page here uses this source, in the order the words come in it.

  1. Generate the key How you go about creating and implementing a DKIM key will vary depending on your email service. If you are configuring DKIM on your email servers directly, you will need to generate an RSA public/private key pair. We recommend you use a 2048-bit key. There are several good guides on how to generate RSA key pairs for Windowsor Linux.

    In DKIM signing

  2. Generate the key If you use a cloud-based email service, your DKIM configuration will be automated to some extent. If you are configuring DKIM on your email servers directly, you will need to generate an RSA public/private key pair. We recommend you use a 2048-bit key. There are several good guides on how to generate RSA key pairs for Windowsor Linux.

    In DKIM signing

  3. Generate the key Look for a DKIM option in your administration panel, or contact your service provider. If you are configuring DKIM on your email servers directly, you will need to generate an RSA public/private key pair. We recommend you use a 2048-bit key. There are several good guides on how to generate RSA key pairs for Windowsor Linux.

    In DKIM signing

  4. How you go about creating and implementing a DKIM key will vary depending on your email service. If you use a cloud-based email service, your DKIM configuration will be automated to some extent. Look for a DKIM option in your administration panel, or contact your service provider. If you are configuring DKIM on your email servers directly, you will need to generate an RSA public/private key pair. DKIM keys do not expire, but you should rotate them periodically (we suggest every 12 months). Create a new key with a new selector and follow the same steps as above. Keep the old DNS record live for a few days after making changes, to give the DNS time to update.

    In DKIM signing

  5. How you go about creating and implementing a DKIM key will vary depending on your email service. If you use a cloud-based email service, your DKIM configuration will be automated to some extent. Look for a DKIM option in your administration panel, or contact your service provider. We recommend you use a 2048-bit key. DKIM keys do not expire, but you should rotate them periodically (we suggest every 12 months). Create a new key with a new selector and follow the same steps as above. Keep the old DNS record live for a few days after making changes, to give the DNS time to update.

    In DKIM signing

  6. If you are configuring DKIM on your email servers directly, you will need to generate an RSA public/private key pair. We recommend you use a 2048-bit key. There are several good guides on how to generate RSA key pairs for Windowsor Linux. DKIM keys do not expire, but you should rotate them periodically (we suggest every 12 months). Create an entry in the public DNS record

    In DKIM signing

  7. If you are configuring DKIM on your email servers directly, you will need to generate an RSA public/private key pair. We recommend you use a 2048-bit key. There are several good guides on how to generate RSA key pairs for Windowsor Linux. Create a new key with a new selector and follow the same steps as above. Create an entry in the public DNS record

    In DKIM signing

  8. v=DKIM1, k=rsa, You can check this has been applied using a DKIM lookup service and your selector. v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCG26OM/bk0vNm/TM2DnOQjPZNLIWspF4xtIX12LGHHjfushjsaudfysuf+DUigzM6h2oJMEdNt1S/CWVXW0pUBqfU0fzdw90+jyqOduh4cCnEk0z0w1w1j4xOYy0FLHhKoeoZJwWQFtwrlhrjxD6jM+sGeeRnbn2rQIDAQAB

    In Email authentication testing