DKIM authentication is no longer optional for serious email delivery. Modern inbox providers use DKIM alongside SPF and DMARC to decide whether your messages reach the inbox or the spam folder. If you're running a cPanel server and haven't enabled DKIM, you're leaving email deliverability to chance. This checklist walks you through every step of enabling, configuring, and verifying DKIM in cPanel environments.
Pre-Flight Checks
Before you touch any settings, confirm your environment is ready.
☐ Verify cPanel Access Level
You need either root/WHM access or cPanel account access with email permissions. DKIM enablement happens at two levels: system-wide configuration in WHM and per-domain activation in cPanel accounts.
- WHM access: Required for system-wide DKIM enablement and default key generation
- cPanel access: Sufficient for enabling DKIM on domains you control
☐ Confirm DNS Control
DKIM requires publishing DNS records. Verify you can add TXT records to your domain's DNS zone. If your nameservers point elsewhere, you'll need access to that DNS provider's control panel.
Check current nameservers:
dig NS yourdomain.com +short
If the nameservers are not your cPanel server or a service you control, coordinate DNS changes with whoever manages the zone.
☐ Check Mail Server Hostname
Your mail server needs a valid hostname with matching forward and reverse DNS. Verify:
hostname
hostname -f
dig +short $(hostname -f)
The hostname should resolve to your server IP, and a reverse lookup of that IP should return the same hostname.
System-Wide DKIM Configuration (WHM)
If you manage the server, enable DKIM system-wide before configuring individual domains.
☐ Enable DKIM Globally in WHM
- Log into WHM as root
- Navigate to Home → Service Configuration → Exim Configuration Manager
- Switch to the Advanced Editor tab
- Locate the DKIM section or search for "dkim"
- Ensure DKIM signing is enabled
- Save changes
Alternatively, check the configuration file directly:
grep -i dkim /etc/exim.conf
You should see DKIM-related transport and signing directives. If absent, regenerate the Exim configuration through WHM after enabling DKIM.
☐ Verify Exim Is Running with DKIM Support
Restart Exim after configuration changes:
systemctl restart exim
Confirm Exim compiled with DKIM support:
exim -bV | grep -i dkim
You should see DKIM listed among supported features.
☐ Set Default DKIM Key Size
Modern best practice uses 2048-bit keys. In WHM, the default key size is typically configurable during DKIM setup. Verify your keys meet this standard:
ls -lh /var/cpanel/domain_keys/*/default
If you find 1024-bit keys (smaller file sizes), regenerate them with 2048-bit length.
Per-Domain DKIM Activation
With system-wide DKIM enabled, activate it for each domain that sends mail.
☐ Enable DKIM in cPanel Email Authentication
- Log into cPanel for the target account
- Navigate to Email → Email Deliverability (or Authentication)
- Locate your domain in the list
- Click Manage next to the domain
- Find the DKIM section
- Click Enable if DKIM is disabled
- cPanel generates a key pair and displays the public key
☐ Copy the DKIM Public Key Record
After enabling DKIM, cPanel shows the DNS record you need to publish. It looks like:
default._domainkey.yourdomain.com. 3600 IN TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA..."
Copy the entire record. Note:
- Hostname:
default._domainkey.yourdomain.com - Type: TXT
- Value: The entire quoted string starting with
v=DKIM1
☐ Publish the DKIM DNS Record
Add the TXT record to your DNS zone.
If using cPanel DNS:
- Go to Domains → Zone Editor in cPanel
- Click Manage for your domain
- Add a TXT record:
- Name:
default._domainkey- TTL: 3600 (or default) - Record: Paste the fullv=DKIM1...value - Save
If using external DNS:
Log into your DNS provider (Cloudflare, Route 53, etc.) and add the TXT record there. Some providers split long TXT records into multiple strings automatically; this is normal and correct.
☐ Wait for DNS Propagation
DNS changes take time. Allow at least 5-15 minutes for local propagation, longer for global caches.
Monitor propagation:
dig TXT default._domainkey.yourdomain.com +short
You should see the DKIM public key returned. If empty, wait longer or check the record syntax.
Verification and Testing
Don't assume DKIM is working until you've tested it.
☐ Verify DKIM Record Syntax
Use an online DKIM validator or command-line tools to confirm the record is well-formed:
dig TXT default._domainkey.yourdomain.com | grep -i "v=DKIM1"
The record must:
- Start with
v=DKIM1 - Include
k=rsa(algorithm) - Include
p=followed by the public key
Missing quotes, extra spaces, or split records can break validation.
☐ Send a Test Email
Send an email from an account on your domain to an external address you control (Gmail, Outlook, etc.).
echo "DKIM test" | mail -s "Test DKIM" [email protected]
Or send through webmail or an email client configured for the domain.
☐ Check Email Headers for DKIM Signature
View the full headers of the received test email. Look for:
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=yourdomain.com; s=default;
h=...
bh=...
b=...
Key fields:
- d=: Your domain
- s=: Selector (usually
default) - b=: The signature hash
If this header is missing, DKIM signing is not happening. Check Exim logs.
☐ Verify DKIM Pass in Authentication-Results
The receiving mail server adds an Authentication-Results header. Look for:
Authentication-Results: mx.google.com;
dkim=pass [email protected] header.s=default header.b=xyz123;
A dkim=pass result confirms end-to-end success. If you see dkim=fail or dkim=neutral, there's a configuration mismatch.
☐ Test with an Email Authentication Tool
Send a test email to a DKIM testing service:
- mail-tester.com: Provides a one-time address and scores your email
- dkimvalidator.com: Returns detailed DKIM validation results
These services show exactly what went wrong if DKIM fails.
Troubleshooting Common Issues
☐ DKIM Signature Present but Validation Fails
Symptom: Headers show a DKIM-Signature but dkim=fail in Authentication-Results.
Likely causes:
- DNS record mismatch: The public key in DNS doesn't match the private key signing emails
- DNS record syntax error: Extra spaces, missing quotes, or line breaks
- Wrong selector: The
s=in the signature doesn't match the DNS record name
Fix:
- Re-copy the public key from cPanel Email Deliverability
- Delete and re-add the DNS TXT record
- Wait for propagation and test again
☐ No DKIM-Signature Header
Symptom: Outgoing emails lack the DKIM-Signature header entirely.
Likely causes:
- DKIM not enabled for the specific domain in cPanel
- Exim not configured to sign mail for the domain
- Sending through a non-Exim transport (external SMTP relay)
Fix:
- Re-check Email Deliverability in cPanel; ensure DKIM shows as enabled
- Review Exim configuration for DKIM directives
- Check
/var/log/exim_mainlogfor signing errors:
grep -i dkim /var/log/exim_mainlog | tail -20
☐ DNS Record Not Found
Symptom: dig returns no results for default._domainkey.yourdomain.com.
Likely causes:
- DNS record not added
- Wrong DNS zone (nameservers elsewhere)
- TTL not expired if you corrected a mistake
Fix:
- Verify nameservers:
dig NS yourdomain.com +short - Check the correct DNS control panel
- Flush local DNS cache or test from a different network
☐ cPanel Shows DKIM Disabled After Enabling
Symptom: You enable DKIM, but the status reverts to disabled.
Likely causes:
- Permissions issue with the key directory
- Corrupted key files
- WHM-level DKIM disabled
Fix:
- Check key file permissions:
ls -la /var/cpanel/domain_keys/yourdomain.com/
The default file should be owned by the cPanel user or root with appropriate read permissions.
- Regenerate the key in cPanel Email Deliverability
- Verify WHM DKIM is enabled system-wide
Post-Deployment Checklist
Once DKIM passes validation, secure and maintain your setup.
☐ Document Key Location and Selector
Record where your DKIM private key lives and the selector name:
- Key path:
/var/cpanel/domain_keys/yourdomain.com/default - Selector:
default - DNS record:
default._domainkey.yourdomain.com
Store this in your runbook or documentation.
☐ Implement DMARC Policy
DKIM alone doesn't tell receivers what to do with failures. Add a DMARC record:
_dmarc.yourdomain.com. 3600 IN TXT "v=DMARC1; p=none; rua=mailto:[email protected]"
Start with p=none to monitor, then move to p=quarantine or p=reject once confident.
☐ Monitor Email Authentication Reports
If you configured DMARC reporting, review aggregate reports regularly. They show which sources send on your behalf and whether DKIM passes.
☐ Rotate DKIM Keys Periodically
Best practice rotates DKIM keys annually. Generate a new key in cPanel, update DNS, wait for propagation, then remove the old record.
☐ Test After Server or DNS Changes
After migrating servers, changing nameservers, or modifying Exim configuration, re-run the verification tests. DKIM breaks easily during infrastructure changes.
Multiple Domains and Reseller Accounts
☐ Enable DKIM for All Hosted Domains
If you host multiple domains, repeat the per-domain activation steps for each. cPanel doesn't enable DKIM globally for all accounts automatically.
List all domains on the server:
ls /var/cpanel/users/
For each user file, check the DNS entries or use WHM's "List Accounts" feature.
☐ Reseller Account Considerations
Resellers can enable DKIM for their own domains and their clients' domains through cPanel. WHM access is not required for per-domain DKIM, but system-wide enablement must be done by the root administrator first.
Conclusion
Enabling DKIM in cPanel is straightforward: enable system-wide support in WHM, activate per-domain in cPanel, publish the DNS record, and verify with test emails. The checklist above covers every step from pre-flight checks through troubleshooting. Once DKIM passes validation, layer on SPF and DMARC for complete email authentication. Modern inbox providers expect all three. Treat this checklist as your runbook, and revisit it whenever you onboard a new domain or change hosting infrastructure. Proper DKIM setup isn't just best practice—it's table stakes for reliable email delivery.
