DKIM (DomainKeys Identified Mail) is a public key that lives in your DNS. When we send mail as your domain, the mail server signs the message with a matching private key. The inbox on the other end looks up the TXT record and checks the signature. If it matches, the message was not altered after it left us, and it is more likely to land in the inbox.
We set this up with you. Unsure which product or DNS mode you are on? Open a support ticket and we will check.
DKIM is one of three authentication records. Also see SPF records explained and DMARC explained.
Which mail product
Signing happens on the product that actually sends the mail.
- Shared hosting (mailboxes you create in cPanel): enable DKIM in cPanel Email Deliverability. See Create an email account.
- LochStudios Mail (hosted business email): copy the DKIM value from the mail service in the portal. Open that service and use Log in to WebMail for the inbox. See What is Axigen webmail and how to sign in.
- A VPS you manage: generate the key pair on that server, then publish the public TXT in DNS. Credentials and the console are on the server in the portal.
- Another sending system (a newsletter tool, a CRM, or mail that is not hosted here): they give you a selector and a TXT value. Paste that value as written. Do not invent a key.
Do not mix those paths. A cPanel DKIM key will not sign LochStudios Mail, and the other way around.
Where the TXT record goes
The public key is a TXT record. AtlasDNS is the default. Do not send the domain to a third-party DNS host.
- Sign in at /portal.
- Open Domains, then the domain, then DNS.
- AtlasDNS (the usual case): add the TXT on that page. When the domain uses AtlasDNS, the nameservers are:
ns1.atlasdns.net.au
ns2.atlasdns.net.au
ns3.atlasdns.net.au
- cPanel Hosting DNS mode (the domain is paired with a shared hosting service): the portal says records are managed from the hosting control panel. Open the hosting service, click Log in to cPanel, and use Email Deliverability (it can write the record) or the Zone Editor.
Unsure which mode you are on? Open a support ticket.
Why DKIM matters
SPF only lists who may send. DKIM proves this message is the one we signed.
- Recipients can tell the body and signed headers were not changed in transit.
- Inboxes treat signed mail as more trustworthy.
- You can use a different selector (a different key) per sending system or subdomain.
- Filters weigh a valid signature when they decide inbox versus spam. See Why your emails go to spam.
- DMARC needs SPF or DKIM to align with the From domain.
How a signed message is checked
- The sending product holds a private key and publishes the public half as a TXT record.
- The name of that record is
{selector}._domainkey.yourdomain.com. - On send, the server signs selected headers and the body and adds a
DKIM-Signatureheader. - The receiving server looks up the TXT for that selector.
- If the signature matches the public key, DKIM passes.
A selector is the left-hand label (default, selector1, or whatever the product shows). It lets one domain publish more than one key. Use the selector the product displays. Do not invent one.
Enable DKIM on shared hosting
Open cPanel from the portal. Do not guess a hostname.
- Sign in at /portal, open the hosting service, and click Log in to cPanel.
- In the Email section, open Email Deliverability.
- Find the domain (or addon domain) that sends the mail.
- If DKIM is not valid, click Repair or Manage.
- Confirm DKIM is enabled for that domain. cPanel usually uses the selector
default.
If the domain is in cPanel Hosting DNS mode, Repair can write the TXT for you. Do not also paste a second copy of the same selector in the Zone Editor.
If the domain uses AtlasDNS, Repair enables the private key on the mail server but does not publish the public record. Copy the suggested TXT (name and full value) and add it under Domains → the domain → DNS.
The hostname is typically mail.yourdomain.com when this account sends the mail.
Enable DKIM on LochStudios Mail
- Sign in at /portal.
- Open the mail service for the domain.
- Copy the DKIM value shown there (name and full TXT, including
v=DKIM1). - Add that TXT on Domains → the domain → DNS (or in the Zone Editor only if the domain is in cPanel Hosting DNS mode).
If the mail service does not show a DKIM value, or the name is not obvious, open a support ticket and we will publish it with you.
Plans are on LochStudios Mail. Hostname is usually mail.yourdomain.com once DNS and MX point at this product.
What the DNS record looks like
Copy the entire TXT value the product shows, starting at v=DKIM1. Do not paste only the characters after p=. Do not add extra spaces or line breaks.
| Type | Name | Value |
|---|---|---|
| TXT | default._domainkey | v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC... |
Swap default for the selector you were given. On AtlasDNS, the name field is the left-hand label (default._domainkey), not the full default._domainkey.yourdomain.com, unless the form asks for the FQDN.
Example shape (not a real key):
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC...
You can have more than one DKIM TXT on the domain if each selector is different. Two different values on the same selector will not verify.
Record types: DNS record types explained.
Other senders on the same domain
A newsletter tool or another mail product may ask you to add s1._domainkey (or similar) with a value they supply. Add that row as written. Leave our selector in place if we still send mail as the same domain.
Do not replace the cPanel or LochStudios Mail DKIM record with a third-party one unless you have stopped sending from that product.
Check that it works
DNS changes are often quick. They can take a while to show everywhere. See DNS propagation explained.
Look up the published key (use your real selector and domain):
nslookup -type=TXT default._domainkey.yourdomain.com
You should see the same v=DKIM1 string you saved.
Then send a real message from the mailbox that should be signed.
- Shared hosting: Access Webmail (Roundcube), or a mail app.
- LochStudios Mail: Log in to WebMail on the mail service.
Send it to an inbox you control. In Gmail, open the message, use the three-dot menu, choose Show original, and look for DKIM=PASS (and a d= that matches your From domain).
If you would rather we check, open a support ticket and include the domain, the product, and the selector.
Good habits
- Leave the private key on the mail product. You never paste it into DNS.
- Stick to the selector the product already uses, unless you are adding a second sender.
- When you rotate a key, publish the new selector first, switch signing, then remove the old TXT.
- Sign every address that sends as the domain, including system and no-reply addresses on that product.
- For DMARC alignment, the domain in the DKIM signature should match the domain in the From address.
If something looks wrong
The public lookup is empty. Confirm you are editing the live zone (AtlasDNS versus cPanel Hosting). Confirm the name includes ._domainkey. Wait for propagation, then look up again.
The message is not signed. Enable DKIM on the product that sent it. A record in DNS does nothing if that server is not signing. Confirm MX still points at that same product.
The signature does not verify. The published TXT must match the live private key exactly. Re-copy the full value. A truncated p= string, a missing v=DKIM1, or a second TXT on the same selector will fail the check.
Selector not found. The DNS name is {selector}._domainkey, then the domain. default._domainkey.yourdomain.com is not the same as _domainkey.yourdomain.com.
More than one sending system. Give each one its own selector. Do not point two products at the same selector name.
Do not restart services yourself. If the record looks right and mail still is not signed, open a support ticket.
Subdomains
A subdomain that sends as itself (news@mail.yourdomain.com) needs its own DKIM name, for example default._domainkey.mail. Addresses that send as the root domain (news@yourdomain.com) use the root selector, even if the website is on a subdomain.
Keep mail, website, and authentication records on AtlasDNS (or on cPanel Hosting if that is the live mode). See Point your domain at your hosting.
Next steps
Once this selector verifies, publish SPF if it is not already there, then add a DMARC record starting at p=none. We can set all three with you if you open a support ticket.