---
title: How do I enable DKIM signing and configure primary and additional domain records?
description: DomainKeys Identified Mail (DKIM) is an open protocol for protecting email users against email address identity theft and email message content tampering.
---

[Skip to content](https://knowledge.mdaemon.com/configure-dkim-signing#main-content)

[![](https://knowledge.mdaemon.com/hs-fs/hubfs/MDaemon-Technologies_logo.png?width=200&height=150&name=MDaemon-Technologies_logo.png)](https://mdaemon.com/)

- [Knowledge Base Home](https://knowledge.mdaemon.com/)
- [Go to www.mdaemon.com](https://mdaemon.com/)

Open main navigation

Close main navigation

- [Knowledge Base Home](https://knowledge.mdaemon.com/)
- [Go to www.mdaemon.com](https://mdaemon.com/)
- [Contact Us](https://mdaemon.com/pages/contact-us)

[Contact Us](https://mdaemon.com/pages/contact-us)

 Knowledge Base

- There are no suggestions because the search field is empty.

1. [Knowledge Base Home](https://knowledge.mdaemon.com/?hsLang=en)
2. [MDaemon Email Server](https://knowledge.mdaemon.com/mdaemon-email-server?hsLang=en)

# How do I enable DKIM signing and configure primary and additional domain records?

## DomainKeys Identified Mail (DKIM) is an open protocol for protecting email users against email address identity theft and email message content tampering.

DKIM works by providing positive identification of the signer’s identity along with an encrypted “hash” of the message content.

To configure and use DKIM: The system administrator creates a private/public key pair for the server and publishes the public key in the domain’s domain name server. Using the private key, the sending server creates a signature for each outgoing message. The resulting signature data is stored in a “DKIM-Signature” header within the message. The receiving server obtains the signature from the “DKIM-Signature” header, uses DNS to lookup the public key and policy. 

In order for a message to be signed, it must meet the criteria designated under the Define which messages are eligible for signing button and be received by MDaemon for delivery on an authenticated session. There is also a Content Filter action, "Sign with DKIM selector..." that you can use to cause messages to be signed.

If the incoming SMTP session does not authenticate with MDaemon, the message will not be signed.

1. Select **Security**
2. Select **Security Settings**
3. Expand **Sender Authentication**
4. Select **DKIM Signing**  
   ![mdaemon email server DKIM Signing GUI menu](https://knowledge.mdaemon.com/hs-fs/hubfs/DKIM04.png?width=670&name=DKIM04.png)
5. Check **Sign eligible outbound messages using DKIM**  
   ![enable DKIM signing on the MDaemon email server ](https://knowledge.mdaemon.com/hs-fs/hubfs/DKIM05.png?width=670&name=DKIM05.png)
6. Check **...sign mailing list messages also** (optional).    
   ![enabling the option to DKIM sign mailing list messages in the MDaemon email server](https://knowledge.mdaemon.com/hs-fs/hubfs/DKIM06.png?width=670&name=DKIM06.png)
   
   This will sign every message for all mailing list users, processing times are likely to increase for large lists.  
    ![informational pop-up notification for enabling DKIM signing for mailing list message in MDaemon email server](https://knowledge.mdaemon.com/hs-fs/hubfs/DKIM09.png?width=507&name=DKIM09.png)
7. Either enter a new selector or use the default selector, MDaemon.  
   ![creating a default selector to setup dkim signing on the MDaemon email server](https://knowledge.mdaemon.com/hs-fs/hubfs/DKIM07.png?width=670&name=DKIM07.png)
8. Click **Create new public and private keys**.  
   ![creating public and private keys for DKIM signing configuration in the mdaemon email server](https://knowledge.mdaemon.com/hs-fs/hubfs/DKIM08.png?width=670&name=DKIM08.png)
9. Select **Yes** to have MDaemon generate keys used to create your published DKIM record.  
   ![notification pop-up when creating dkim keys in the mdaemon email server](https://knowledge.mdaemon.com/hs-fs/hubfs/DKIM10.png?width=478&name=DKIM10.png)

MDeamon creates the **dns\_readme.txt** file in the \\MDaemon\\Pem\\MDaemon\\ directory and opens the file onscreen. 

In the DNS server, create a TXT record called **MDaemon.\_domainkey.domain.com**

- Where **MDaemon** is the selector name and **domain.com** is your MDaemon domain name.

![using the generated DKIM key to assist in configuring public DNS record for DKIM signing in the mdaemon email server](https://knowledge.mdaemon.com/hs-fs/hubfs/DKIM11.png?width=670&name=DKIM11.png)

The highlighted public key should be entered inside the **MDaemon.\_domainkey.domain.com** TXT record and  published in the domain's DNS provider.  

**NOTE\*\*** Do not use this public key! Use the key generated in the **dns\_readme.txt** file.

 

![copying the value for the DKIM public DNS record for DKIM signing in the mdaemon email server](https://knowledge.mdaemon.com/hs-fs/hubfs/DKIM12.png?width=670&name=DKIM12.png)

 

**DKIM Signing with Multiple Domains**

MDaemon can be configured to sign messages based on certain criteria, such as choosing a specific DKIM selector and/or domain to sign the message.  This is useful if there are multiple domains that are configured in MDaemon.  The same selector can be used to sign messages from multiple domains.  However, for best results, addresses and/or domains should be defined to sign messages as their domain, regardless of the selector.  Not doing so can result in invalid or undesired DKIM verification results.  

Follow the steps below to sign messages using a separate selector and/or domain.

- Click the **Define which messages are eligible for signing **and review the following information to create DKIM signing rules. 
    - The syntax for entries here are as follows:  
      \<HEADER\> \<HEADER VALUE\> \<SELECTOR\> \<DOMAIN\> 
          - Selector and Domain values are optional.

- - ? and \* Wildcards are allowed
    - For example, to sign messages from company1.test using the MDaemon1 selector and the company1.test domain, enter the following:  
      **From \*@company1.test s=MDaemon1 d=company1.test**  
          - Any header value can be used here (To, Reply-To, Sender, etc..).
          - Signing mail for another domain using the same selector is acceptable, though the domain should be defined.  For example:  
            **From \*@company2.test s=MDaemon1 d=company2.test**
          - Other acceptable examples: 
                  - From user01@example.com
                  - To \*@example.com
                  - Reply-To \*@domain123.example.com s=s1024
                  - Sender \*@domain123.example.com s=January05 d=example.com
    - Please use one entry per line.

 

- [MDaemon Email Server](https://knowledge.mdaemon.com/mdaemon-email-server?hsLang=en#main-content)

    - [Mobile Device Management](https://knowledge.mdaemon.com/mdaemon-email-server?hsLang=en#mobile-device-management)
- [MDaemon AntiVirus (SecurityPlus)](https://knowledge.mdaemon.com/mdaemon-antivirus-securityplus?hsLang=en)
- [ActiveSync for MDaemon](https://knowledge.mdaemon.com/activesync-for-mdaemon?hsLang=en)
- [MDaemon Connector for Outlook (Outlook Connector)](https://knowledge.mdaemon.com/mdaemon-connector-for-outlook-outlook-connector?hsLang=en)
- [SecurityGateway for Email Servers](https://knowledge.mdaemon.com/securitygateway-for-email-servers?hsLang=en)
- [RelayFax Network Software](https://knowledge.mdaemon.com/relayfax-network-software?hsLang=en)

[![Chill listening crop-3](https://knowledge.mdaemon.com/hs-fs/hubfs/belch.io/template-assets/MDaemon-Technologies_logo.png?width=199&height=41&name=MDaemon-Technologies_logo.png "Chill listening crop-3")](https://www.mdaemon.com)

[Knowledge Base Home](https://knowledge.mdaemon.com?hsLang=en)

<https://www.youtube.com/c/MDaemonTechnologies> <https://www.linkedin.com/company/mdaemon-technologies/> <https://www.facebook.com/MDaemon.Technologies/> <https://www.twitter.com/MDaemon_Email>

Copyright © 2025, MDaemon Technologies