Site AI Auditod Internet Solutions

DKIM Failing? How to Troubleshoot dkim=fail and dkim=none

11. září 2026Čtení: 8 minDoručitelnost e-mailů
DKIM Failing? How to Troubleshoot dkim=fail and dkim=none

Short answer: Start with the exact DKIM result in the message’s Authentication-Results header. dkim=none means the message was not signed, so enable signing in the sending service. dkim=fail with “no key” or a DNS error points to a missing or misnamed record at selector._domainkey. dkim=fail with “bad signature” or “body hash did not verify” means the message changed after signing or the published key does not match. permerror usually means a malformed or truncated key. And a pass for the wrong domain is an alignment problem, fixed with custom domain DKIM.

Step 1: get a real header and read the result

Troubleshooting DKIM without a real message header is guesswork. Send a message from the system you are investigating to a Gmail or Outlook.com address, open the full source (“Show original” in Gmail) and find two headers:

Messages can carry several DKIM signatures, for example one from your domain and one from the sending platform. Each is evaluated separately, and the receiver may report several results. For DMARC, what matters is whether at least one signature both passes and uses your domain.

Test from each system separately. A mailbox, a newsletter platform and a website form can all send with the same From domain but sign differently, and a problem in one says nothing about the others. Keep the test messages; comparing a passing and a failing header side by side often reveals the difference immediately.

Step 2: match the result to its likely cause

Result in headersMost likely causeWhere to look
dkim=noneSigning not enabled, or mail sent by a different system than you thinkService admin settings; Received headers
dkim=fail (no key for signature / key not found)Record missing, wrong selector, wrong host name, DNS not updated yetDNS lookup of selector._domainkey.domain
dkim=fail (bad signature / body hash did not verify)Message modified after signing, or key mismatch after regenerationGateways, footers, list servers; the published key
dkim=permerrorMalformed record: broken quotes, truncated key, wrong syntaxThe TXT value as served by DNS
dkim=temperrorTemporary DNS failureDNS provider status; retry later
dkim=pass but dmarc=failSignature from the vendor’s domain, not yoursThe d= value; custom domain setup in the platform

Step 3: when the message is not signed (dkim=none)

This is the simplest case and one of the most common. Check:

  1. Is signing enabled? Google Workspace requires pressing “Start authentication” after publishing the key. Microsoft 365 requires enabling DKIM for each custom domain in the Defender portal. Many newsletter and CRM tools have a separate “authenticate domain” step.
  2. Is the right system sending? Look at the Received headers. A website form may be sending directly from the web server instead of through your provider, and web servers typically do not sign.
  3. Is the right domain configured? If you have several domains or aliases, signing may be enabled for the primary domain only.

Step 4: when the key cannot be found

Take the selector and domain from the DKIM-Signature header and look up the record exactly: dig TXT selector._domainkey.yourdomain.com +short. If the platform uses CNAME records, use dig CNAME first and then look up the target.

Frequent causes:

Step 5: when the signature is bad

A “bad signature” or “body hash did not verify” result means the key was found, but the message no longer matches what was signed, or the key does not match the private key used.

If the message was modified:

Fix the order of operations: signing must be the last step before the message leaves your infrastructure. If a disclaimer tool runs after your mail server signs, move signing to the gateway or add the disclaimer earlier.

If the key does not match: the private key was regenerated in the service but the old public key is still in DNS, or two services share a selector name and overwrite each other’s records. Republish the current key from the service’s admin panel, and give each service its own selector.

Step 6: when the record is malformed

Look at the TXT value exactly as DNS serves it. A valid key record looks like v=DKIM1; k=rsa; p=MIIBIjANBg.... Problems include:

If your DNS provider cannot store long records reliably, use a CNAME-based setup where the service hosts the key, or choose a DNS host that handles long TXT records correctly.

Step 7: when DKIM passes for the wrong domain

Many platforms sign every message with their own domain by default. The result reads dkim=pass header.d=platform.example, which looks healthy but does nothing for your DMARC alignment. Look for “custom domain authentication”, “sender authentication” or “branded sending domain” in the platform’s settings, publish the records they provide, and verify that header.d shows your domain or a subdomain of it.

After each fix, test again with a fresh message and check the header. DMARC aggregate reports confirm the result at scale within a day or two. For the published side, Site AI Audit checks DKIM together with SPF (including the lookup limit), DMARC and MX records, and explains findings in plain words. A free check helps confirm the DNS part; paid plans alert you if a record disappears later.

Preventing DKIM problems in the future

Most DKIM failures are introduced by changes, not by the original setup. A few habits prevent the majority of them:

Related reading

The bottom line

DKIM failures fall into a few clear categories, and the header tells you which one you have. No signature means signing is off or the wrong system is sending. A missing key means DNS is wrong. A bad signature means the message changed or the key was replaced. A malformed record means the value was mangled. A pass for the wrong domain means the platform needs custom authentication. Fix the cause, test again, and confirm in DMARC reports.

FAQ

What does dkim=none mean?

The receiver found no DKIM signature to evaluate. Enable DKIM signing in the service that sent the message, and check that the message did not come from an unexpected system such as a web server.

What does “body hash did not verify” mean?

The message body changed after it was signed. Look for footers, disclaimers, link rewriting or re-encoding added by gateways, list servers or forwarding services.

Why does DKIM fail after I moved my DNS?

The DKIM records were probably not copied to the new DNS host, or the long key was truncated during the move. Look up the selector record and republish it from the service’s admin panel.

Can two services use the same DKIM selector?

They should not. Each service needs its own selector so that its public key lives at a unique DNS name.

Why does DKIM pass but DMARC fail?

Because the passing signature belongs to another domain, usually the sending platform’s. Set up custom domain authentication so the service signs with your domain.

How long does it take for a new DKIM record to work?

Often minutes, but it depends on DNS caching, including cached negative answers. Wait for the TTL and test again before changing anything else.

#DKIM#DNS#Email Authentication#Troubleshooting
Zkontrolujte svůj web — zdarma.Co na webu opravit — a čím začít.
Začít zdarma

Další z blogu

Všechny články →
Internet Solutions

Další od našeho týmu

Vytvořilo Internet Solutions. Vyzkoušejte i naše další produkty — každý vám ušetří čas jiným způsobem.

internet-solutions.net ↗
Site AI Audit
Přehled soukromí

Tento web používá cookies, abychom vám mohli poskytnout co nejlepší uživatelský zážitek. Informace z cookies se ukládají ve vašem prohlížeči a slouží například k tomu, aby vás web při návratu poznal a náš tým viděl, které části webu jsou pro vás nejzajímavější a nejužitečnější.