Blog

3

min read

Admin

DKIM Record Not Found: Why It Happens and How to Fix It

DKIM Record Not Found: Why It Happens and How to Fix It

DKIM Record Not Found: Why It Happens and How to Fix It

DKIM record not found? Learn the five usual causes, how to find your selector, and how to set up DKIM correctly for cold email domains.

A "DKIM record not found" error means a receiving server looked for your public key at selector._domainkey.yourdomain.com and found nothing. Without that key, your emails cannot be signed or verified. The usual causes are a wrong selector, a record added in the wrong place, DNS that has not updated yet, or DKIM never being switched on in your mail provider.

To test your domain in one step, use the free Rhycon email deliverability checker. It probes the common selectors and tells you which ones exist.

What DKIM does

DKIM (DomainKeys Identified Mail) adds a digital signature to every email you send. The signature is made with a private key held by your mail provider. The matching public key sits in your DNS. The receiver fetches the public key, checks the signature, and knows the message really came from your domain and was not changed on the way.

The signature names a selector, which tells the receiver where to look. If the selector is google and your domain is example.com, the key lives at google._domainkey.example.com.

Why DKIM matters for cold email

DKIM is the authentication method that survives forwarding, and it is what DMARC leans on most. Gmail and Yahoo require bulk senders to authenticate, and for cold email a missing DKIM signature is one of the easiest ways to land in spam on a new domain.

Why the record is "not found"

  1. DKIM was never turned on. In Google Workspace, you generate the key in the Admin console and then click Start authentication. In Microsoft 365 you enable DKIM per domain in the Defender portal. Creating a record is not enough.

  2. Wrong selector. You are checking default but your provider uses google, selector1, selector2 or something custom. Check the DKIM-Signature header on a sent message for the s= value.

  3. Record in the wrong place. Some DNS hosts add your domain name automatically. If you enter google._domainkey.example.com and the host appends .example.com, the record ends up at the wrong name.

  4. DNS has not propagated. New records can take minutes or a few hours. Wait before you panic.

  5. The key is broken. Long keys are often split across multiple strings. If the value is cut off or has stray spaces or line breaks, validation fails.

How to find your selector

Send an email to a Gmail address, open the message, choose Show original, and look for the line starting DKIM-Signature. The s= tag is your selector and d= is the signing domain. Common defaults are google for Google Workspace and selector1 and selector2 for Microsoft 365.

Key length and rotation

Use a 2048-bit key where your DNS host supports it. 1024-bit still works but is weaker. Rotate keys once or twice a year, and when someone with access to your mail or DNS leaves.

DKIM and DMARC alignment

For DMARC to pass, the domain in the DKIM signature has to align with the domain in your From address. If your sending tool signs with its own domain instead of yours, DKIM can pass while DMARC fails. Set up custom DKIM for every platform that sends as you. See our guide to DMARC policies.

Cold email setup that works

Every sending domain needs its own DKIM key, switched on before you send a single email. If you run many domains this is the step teams forget. You can verify any domain with the checker. If you would rather not manage this yourself, Rhycon's managed infrastructure uses Rhycon-owned domains and mailboxes for your outreach.

DKIM FAQs

How long does a DKIM record take to work?

Usually minutes, sometimes up to a few hours depending on your DNS host. Google says it can take up to 48 hours in some cases.

Can I have more than one DKIM record?

Yes. Each sending service gets its own selector, so you can have many keys on one domain.

Do I need DKIM if I have SPF?

Yes. SPF breaks when mail is forwarded, and DMARC works best when both are in place. For cold email, set up both.

Is DKIM a CNAME or a TXT record?

Either. Google uses TXT. Microsoft 365 uses CNAME records that point to keys it hosts. Follow your provider's instructions exactly.

Ready to book more meetings?

Good AI Tools