Skip to content
Back to Blog
Hosting Support10 min read

Enable DKIM in cPanel: The Complete 2026 Checklist

A step-by-step checklist for enabling and verifying DKIM authentication in cPanel environments, from initial setup through testing and troubleshooting.

Written by Abdul AbrorTechnical Hosting Support Engineer
Enable DKIM in cPanel: The Complete 2026 Checklist
On this page

DKIM authentication is no longer optional for serious email delivery. Modern inbox providers use DKIM alongside SPF and DMARC to decide whether your messages reach the inbox or the spam folder. If you're running a cPanel server and haven't enabled DKIM, you're leaving email deliverability to chance. This checklist walks you through every step of enabling, configuring, and verifying DKIM in cPanel environments.

Pre-Flight Checks

Before you touch any settings, confirm your environment is ready.

☐ Verify cPanel Access Level

You need either root/WHM access or cPanel account access with email permissions. DKIM enablement happens at two levels: system-wide configuration in WHM and per-domain activation in cPanel accounts.

  • WHM access: Required for system-wide DKIM enablement and default key generation
  • cPanel access: Sufficient for enabling DKIM on domains you control

☐ Confirm DNS Control

DKIM requires publishing DNS records. Verify you can add TXT records to your domain's DNS zone. If your nameservers point elsewhere, you'll need access to that DNS provider's control panel.

Check current nameservers:

dig NS yourdomain.com +short

If the nameservers are not your cPanel server or a service you control, coordinate DNS changes with whoever manages the zone.

☐ Check Mail Server Hostname

Your mail server needs a valid hostname with matching forward and reverse DNS. Verify:

hostname
hostname -f
dig +short $(hostname -f)

The hostname should resolve to your server IP, and a reverse lookup of that IP should return the same hostname.

System-Wide DKIM Configuration (WHM)

If you manage the server, enable DKIM system-wide before configuring individual domains.

☐ Enable DKIM Globally in WHM

  1. Log into WHM as root
  2. Navigate to Home → Service Configuration → Exim Configuration Manager
  3. Switch to the Advanced Editor tab
  4. Locate the DKIM section or search for "dkim"
  5. Ensure DKIM signing is enabled
  6. Save changes

Alternatively, check the configuration file directly:

grep -i dkim /etc/exim.conf

You should see DKIM-related transport and signing directives. If absent, regenerate the Exim configuration through WHM after enabling DKIM.

☐ Verify Exim Is Running with DKIM Support

Restart Exim after configuration changes:

systemctl restart exim

Confirm Exim compiled with DKIM support:

exim -bV | grep -i dkim

You should see DKIM listed among supported features.

☐ Set Default DKIM Key Size

Modern best practice uses 2048-bit keys. In WHM, the default key size is typically configurable during DKIM setup. Verify your keys meet this standard:

ls -lh /var/cpanel/domain_keys/*/default

If you find 1024-bit keys (smaller file sizes), regenerate them with 2048-bit length.

Per-Domain DKIM Activation

With system-wide DKIM enabled, activate it for each domain that sends mail.

☐ Enable DKIM in cPanel Email Authentication

  1. Log into cPanel for the target account
  2. Navigate to Email → Email Deliverability (or Authentication)
  3. Locate your domain in the list
  4. Click Manage next to the domain
  5. Find the DKIM section
  6. Click Enable if DKIM is disabled
  7. cPanel generates a key pair and displays the public key

☐ Copy the DKIM Public Key Record

After enabling DKIM, cPanel shows the DNS record you need to publish. It looks like:

default._domainkey.yourdomain.com. 3600 IN TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA..."

Copy the entire record. Note:

  • Hostname: default._domainkey.yourdomain.com
  • Type: TXT
  • Value: The entire quoted string starting with v=DKIM1

☐ Publish the DKIM DNS Record

Add the TXT record to your DNS zone.

If using cPanel DNS:

  1. Go to Domains → Zone Editor in cPanel
  2. Click Manage for your domain
  3. Add a TXT record: - Name: default._domainkey - TTL: 3600 (or default) - Record: Paste the full v=DKIM1... value
  4. Save

If using external DNS:

Log into your DNS provider (Cloudflare, Route 53, etc.) and add the TXT record there. Some providers split long TXT records into multiple strings automatically; this is normal and correct.

☐ Wait for DNS Propagation

DNS changes take time. Allow at least 5-15 minutes for local propagation, longer for global caches.

Monitor propagation:

dig TXT default._domainkey.yourdomain.com +short

You should see the DKIM public key returned. If empty, wait longer or check the record syntax.

Verification and Testing

Don't assume DKIM is working until you've tested it.

☐ Verify DKIM Record Syntax

Use an online DKIM validator or command-line tools to confirm the record is well-formed:

dig TXT default._domainkey.yourdomain.com | grep -i "v=DKIM1"

The record must:

  • Start with v=DKIM1
  • Include k=rsa (algorithm)
  • Include p= followed by the public key

Missing quotes, extra spaces, or split records can break validation.

☐ Send a Test Email

Send an email from an account on your domain to an external address you control (Gmail, Outlook, etc.).

echo "DKIM test" | mail -s "Test DKIM" [email protected]

Or send through webmail or an email client configured for the domain.

☐ Check Email Headers for DKIM Signature

View the full headers of the received test email. Look for:

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
  d=yourdomain.com; s=default;
  h=...
  bh=...
  b=...

Key fields:

  • d=: Your domain
  • s=: Selector (usually default)
  • b=: The signature hash

If this header is missing, DKIM signing is not happening. Check Exim logs.

☐ Verify DKIM Pass in Authentication-Results

The receiving mail server adds an Authentication-Results header. Look for:

Authentication-Results: mx.google.com;
  dkim=pass [email protected] header.s=default header.b=xyz123;

A dkim=pass result confirms end-to-end success. If you see dkim=fail or dkim=neutral, there's a configuration mismatch.

☐ Test with an Email Authentication Tool

Send a test email to a DKIM testing service:

  • mail-tester.com: Provides a one-time address and scores your email
  • dkimvalidator.com: Returns detailed DKIM validation results

These services show exactly what went wrong if DKIM fails.

Troubleshooting Common Issues

☐ DKIM Signature Present but Validation Fails

Symptom: Headers show a DKIM-Signature but dkim=fail in Authentication-Results.

Likely causes:

  1. DNS record mismatch: The public key in DNS doesn't match the private key signing emails
  2. DNS record syntax error: Extra spaces, missing quotes, or line breaks
  3. Wrong selector: The s= in the signature doesn't match the DNS record name

Fix:

  1. Re-copy the public key from cPanel Email Deliverability
  2. Delete and re-add the DNS TXT record
  3. Wait for propagation and test again

☐ No DKIM-Signature Header

Symptom: Outgoing emails lack the DKIM-Signature header entirely.

Likely causes:

  1. DKIM not enabled for the specific domain in cPanel
  2. Exim not configured to sign mail for the domain
  3. Sending through a non-Exim transport (external SMTP relay)

Fix:

  1. Re-check Email Deliverability in cPanel; ensure DKIM shows as enabled
  2. Review Exim configuration for DKIM directives
  3. Check /var/log/exim_mainlog for signing errors:
grep -i dkim /var/log/exim_mainlog | tail -20

☐ DNS Record Not Found

Symptom: dig returns no results for default._domainkey.yourdomain.com.

Likely causes:

  1. DNS record not added
  2. Wrong DNS zone (nameservers elsewhere)
  3. TTL not expired if you corrected a mistake

Fix:

  1. Verify nameservers: dig NS yourdomain.com +short
  2. Check the correct DNS control panel
  3. Flush local DNS cache or test from a different network

☐ cPanel Shows DKIM Disabled After Enabling

Symptom: You enable DKIM, but the status reverts to disabled.

Likely causes:

  1. Permissions issue with the key directory
  2. Corrupted key files
  3. WHM-level DKIM disabled

Fix:

  1. Check key file permissions:
ls -la /var/cpanel/domain_keys/yourdomain.com/

The default file should be owned by the cPanel user or root with appropriate read permissions.

  1. Regenerate the key in cPanel Email Deliverability
  2. Verify WHM DKIM is enabled system-wide

Post-Deployment Checklist

Once DKIM passes validation, secure and maintain your setup.

☐ Document Key Location and Selector

Record where your DKIM private key lives and the selector name:

  • Key path: /var/cpanel/domain_keys/yourdomain.com/default
  • Selector: default
  • DNS record: default._domainkey.yourdomain.com

Store this in your runbook or documentation.

☐ Implement DMARC Policy

DKIM alone doesn't tell receivers what to do with failures. Add a DMARC record:

_dmarc.yourdomain.com. 3600 IN TXT "v=DMARC1; p=none; rua=mailto:[email protected]"

Start with p=none to monitor, then move to p=quarantine or p=reject once confident.

☐ Monitor Email Authentication Reports

If you configured DMARC reporting, review aggregate reports regularly. They show which sources send on your behalf and whether DKIM passes.

☐ Rotate DKIM Keys Periodically

Best practice rotates DKIM keys annually. Generate a new key in cPanel, update DNS, wait for propagation, then remove the old record.

☐ Test After Server or DNS Changes

After migrating servers, changing nameservers, or modifying Exim configuration, re-run the verification tests. DKIM breaks easily during infrastructure changes.

Multiple Domains and Reseller Accounts

☐ Enable DKIM for All Hosted Domains

If you host multiple domains, repeat the per-domain activation steps for each. cPanel doesn't enable DKIM globally for all accounts automatically.

List all domains on the server:

ls /var/cpanel/users/

For each user file, check the DNS entries or use WHM's "List Accounts" feature.

☐ Reseller Account Considerations

Resellers can enable DKIM for their own domains and their clients' domains through cPanel. WHM access is not required for per-domain DKIM, but system-wide enablement must be done by the root administrator first.

Conclusion

Enabling DKIM in cPanel is straightforward: enable system-wide support in WHM, activate per-domain in cPanel, publish the DNS record, and verify with test emails. The checklist above covers every step from pre-flight checks through troubleshooting. Once DKIM passes validation, layer on SPF and DMARC for complete email authentication. Modern inbox providers expect all three. Treat this checklist as your runbook, and revisit it whenever you onboard a new domain or change hosting infrastructure. Proper DKIM setup isn't just best practice—it's table stakes for reliable email delivery.