How to enable DKIM in DirectAdmin

Turn on DKIM signing for your domain in DirectAdmin, check the key is published in DNS, and add it manually when DNS is hosted elsewhere.

How-to guideIntermediate2 min readUpdated

DKIM adds a cryptographic signature to every message your server sends. The receiving server checks it against a public key published in your DNS, proving the message came from your domain and wasn’t altered.

Enable DKIM

  1. Open E-mail Manager then E-mail Accounts.
  2. Look for the Enable DKIM option for your domain and select it.
  3. DirectAdmin generates a key pair and, if your DNS is at Traxio, adds the public key to your DNS automatically.

If DKIM is already enabled, you’ll see the option to disable it instead. Leave it on.

Check the record exists

Open Account Manager then DNS Management and look for a TXT record named:

x._domainkey

Its value starts v=DKIM1; k=rsa; p= followed by a long key. Check it from outside:

dig x._domainkey.yourdomain.co.uk TXT +short

If your DNS is elsewhere

DirectAdmin can sign messages, but the public key must be published where your DNS is live.

  1. Copy the x._domainkey TXT record’s value from Account Manager then DNS Management.
  2. At your DNS provider, add a TXT record named x._domainkey with that value.
  3. Paste it exactly; the key is long and a single missing character breaks it.

SPF, DKIM and DMARC when your DNS isn’t at Traxio

Testing DKIM

Send a message to a Gmail address, open it, and choose Show original. Look for DKIM: 'PASS' with your domain.

Common problems

ProblemCause
DKIM: failKey in DNS doesn’t match (copied incorrectly or regenerated)
No DKIM resultMail sent through another service, or DKIM not enabled
Passes, but DMARC failsMessage signed by a different domain than the From address

Popular

Tip: press / to search from any pageSee all results