Solved

DKIM record always fails

  • 29 July 2021
  • 3 replies
  • 325 views

I have followed the instructions for DKIM and published the 4 records.

As you know, one of the records instructed to publish does not end in “_domainkey”.  it is simply “fddkim” which resolves to “spfmx1.domainkey.freshemail.io”.

That fddkim dkim key always fails and I assume it is because the string _domainkey is a fixed part of the specification. 

I have tried to add it to my DNS provider both ways (with and without “_domainkey”), and it always fails.

 

What is recommendation?  It would seem that you are recommending that we publish a record that violates the DKIM standard. 

 

Thank You

icon

Best answer by Keer 15 September 2021, 11:49

View original

3 replies

I should mention that I updated my DKIM records and the one record that does not have the _domainkey suffix still fails.

Userlevel 5
Badge +12

Hi @sboxer, I hope you are doing well. Ideally, this shouldn’t be the case. Did you try looking up for the CNAME once the records are added to see if they are added right? The settings for each DNS varies but I hope with a bit more context on this front, we’d be able to help you fix this. We’ll create a ticket on your behalf and reach out to you via mail to check this further. 

Thanks!

Userlevel 5
Badge +12

@sboxer, thanks for confirming over mail that this has been sorted. I am adding a gist of our discussion here so that it could help others as well :)

The fourth record spfmx1.domainkey.freshemail.io is an SPF entry and is not a direct DKIM entry. When you do a TXT lookup of the same, the following would be returned: 

v=spf1 include:sendgrid.net include:fdspfus.freshemail.io include:fdspfeuc.freshemail.io include:fdspfind.freshemail.io include:fdspfaus.freshemail.io ~all

This is added to ensure email deliverability happens fine. That's why the first three selectors have a different format than the last one. I hope this clarifies.

Have a good day!

Reply