🔐 How to Set Up DKIM for PodPitch
How to Set Up DKIM for PodPitch
DKIM (DomainKeys Identified Mail) adds a cryptographic signature to outgoing email. Receiving mail systems use a public key in your DNS to verify that the message was signed by an authorized service and was not altered after signing.
Important: DKIM values are generated for your domain by the service that sends your email. Never copy a selector, public key, or CNAME target from an example or another company.
How DKIM relates to PodPitch
PodPitch send outreach through a mailbox you connect to the applicable workspace. In PodPitch, manage it under Email Addresses. DKIM signing is controlled by that mailbox provider or by another service that actually sends mail for your domain.
Before you change DNS
- Confirm the domain used by the connected email address.
- Identify every service that sends email for that domain.
- Sign in to the sending service's administrator console.
- Confirm who manages the domain's DNS.
- If your organization has an email administrator, ask them to own the change.
1. Generate or reveal the DKIM records
Open the email authentication or DKIM area in your provider's administrator console. Select the exact custom domain you want to authenticate.
The provider will show one or more records. Depending on the provider, these may be:
- CNAME records that point to provider-hosted public keys; or
- TXT records containing a public key.
Copy the record type, host or selector, target or value, and any TTL guidance exactly as shown. Do not build the values yourself.
2. Publish the records in DNS
Add each record at the DNS host for the domain.
A DKIM host normally contains a selector followed by ._domainkey. Some DNS providers automatically append your domain name. Follow your DNS provider's format so the domain is not added twice.
Publish every selector the email provider requires. Multiple selectors can be valid and are commonly used for safe key rotation.
3. Return to the email provider and enable signing
Wait for the records to become visible in public DNS. Then return to the sending provider, verify the records, and enable DKIM signing if it is not enabled automatically.
Do not assume that publishing the DNS record alone starts signing.
Microsoft 365
Open the DKIM area in Microsoft Defender, select the custom domain, and use the two CNAME values shown for that domain. Publish both selectors, then return to Microsoft 365 and enable DKIM.
Microsoft's CNAME targets can be tenant- and domain-specific, and their format has changed over time. Always retrieve the current values from your own Microsoft 365 tenant; do not construct them from an online example.
Google Workspace
In the Google Admin console, open Apps → Google Workspace → Gmail → Authenticate email, select the domain, and generate a DKIM record. Use a 2048-bit key when your DNS provider supports it. Publish the exact TXT record Google provides, then return to the Admin console and start authentication.
Other email providers
Use the DKIM setup page in the provider's admin console or its official documentation. If the provider does not show a DKIM option, contact that provider before adding any DNS record.
Verify DKIM
- Send a fresh test message from the connected mailbox to an external inbox.
- Open the full message headers.
- Find
Authentication-Resultsand confirmdkim=pass. - Check that the DKIM signing domain shown as
d=is the domain you expect. - Repeat the test for other services that send as your domain.
For DMARC, the DKIM signing domain must align with the visible From domain. A DKIM pass for an unrelated provider domain may not satisfy DMARC.
Common DKIM problems
- The provider cannot find the record: confirm the record type, selector, target, and whether your DNS host appended the domain twice.
- Only one required Microsoft selector was added: publish both CNAME records shown by Microsoft 365.
- DNS is visible but messages are unsigned: return to the provider and enable or start authentication.
- DKIM fails after a gateway modifies the message: ask your email administrator about message modification and ARC support.
- A key is being rotated: publish the new selector before removing the old one, and follow the provider's rotation sequence.
Do not delete a working selector or private key during troubleshooting. Private DKIM keys must remain inside the sending provider and must never be shared with Support.
Before enforcing DMARC
Confirm that DKIM passes and aligns for every legitimate sender. If DKIM is failing, fix it before moving DMARC to quarantine or reject.
Need help?
Message Support through the chat in your PodPitch dashboard and share your sending domain, email provider, DKIM selector names, and the Authentication-Results from a test message. Do not share passwords, recovery codes, or private keys.
Official provider guidance
Updated on: 08/09/2026
Thank you!