Zone records · Intermediate · 10 minutes
DKIM: The Signature Travels With the Message, the Key Stays in Your Zone
Switching DKIM on is a two-minute job at the mail host; the part that actually decides whether it works is a record in a zone that may not be the one you are looking at.
The short answer
DKIM splits into two halves that live in two different places: a private key that signs outgoing mail at the sending host, and a public key you publish as a record at selector._domainkey.yourdomain in your own DNS zone. Get the second half wrong and every message goes out signed against a key nobody in the world can fetch. Allow 10 minutes at intermediate level.
Everything else follows from that split — selectors stack, so each sending service can hold its own; long 2048-bit keys have to be split into quoted chunks in some editors; and a change of nameservers takes the public half away while the signing carries on regardless.
By the Hosting & Domains team · Reviewed 18 August 2026
Intermediate
Assumed knowledge
5
Stages end to end
Free
Support cost
Proven
Verification
Written for whoever holds the name rather than for whoever runs the server. Registry, registrar, DNS host and mail host are kept apart throughout, because most of the confusion in this subject comes from treating the four as one thing.
Nothing on this page is a one-way door. Where a change carries a clock with it — a cache timer, a registry lock, a renewal date — the page says so before you act rather than afterwards.
The two halves of a DKIM key, and which one is yours to publish
The private key never leaves the sending host. It signs each outgoing message and stamps a DKIM-Signature header naming a domain (d=) and a selector (s=). The public half is a string you publish in DNS, and it is the only part of the arrangement that belongs to whoever administers the name.
A receiving server reads the header, works out the record name from d= and s=, queries your zone, fetches the public key and checks the signature. Everything after the sending host is a DNS operation, which is why DKIM problems are almost always zone problems wearing a mail costume.
The record has to sit where the delegation points
cPanel's Email Deliverability screen will generate the key pair and show you the exact record required, and where the domain is delegated to our nameservers it will write that record itself. Where the domain answers from somewhere else — a CDN, a previous provider, a registrar's own DNS — the panel can generate the key but has no way to publish it.
That mismatch is the commonest failure by a distance. Signing is switched on, mail goes out with a perfectly valid DKIM-Signature header, and every verifier reports the key as not found because the record was created in a zone nobody queries. Check the delegation before you check anything else.
Selectors stack, one per sending service
The selector is just a label you choose, and a name can carry as many as it needs. Hosting mail signs under one, the newsletter platform under another, the CRM under a third, and they coexist without any relationship to each other. Nothing is overwritten and nothing competes.
Third-party services usually hand you a CNAME rather than a TXT record, pointing selector._domainkey.yourdomain at a hostname on their own domain. That indirection is deliberate: it lets them rotate the underlying key for years without ever asking you to open a zone editor again.
Why a 2048-bit key gets rejected by some zone editors
A single character string in a TXT record is limited to 255 characters, and a 2048-bit public key comfortably exceeds that. The record is therefore published as several quoted strings which the resolver concatenates, and a good zone editor does the splitting for you without saying so.
Editors that do not will simply refuse the value, or truncate it and leave you with a record that looks present and verifies as broken. If the panel rejects the key, split it into quoted chunks yourself rather than reaching for a shorter key length.
What a nameserver change breaks, and what a registrar transfer does not. Moving the domain to a new registrar changes who bills you and who holds the administrative record. It leaves the zone alone as long as the delegation is unchanged, so DKIM carries on signing and verifying exactly as before.
Moving the nameservers is the operation with teeth. Every selector record has to be recreated at the new DNS provider before the delegation changes, or there is a window in which mail is still signed and no longer verifiable. Rebuild the zone first, switch delegation second.

Where the account does this part for you
Guides written against a hypothetical registrar age badly. These were written at the same zone editor, client area and deliverability screen your own account opens on.
Mailboxes on the name you hold are part of the plan, not a line quietly added at the checkout.
- Every instruction checked at the panel as published
- The failure mode named before you meet it
- The stages the account already handles, marked as such
- People reachable whenever the job stalls
Why Hosting & Domains
Standard on every plan
Registry, registrar, host — kept apart
Each term is defined where it first appears, or linked to the jargon buster. Nothing here uses the four words as though they meant one thing.
Written out of the ticket queue
These pages exist because the same questions kept arriving. Every warning on them is one somebody has genuinely needed.
Stages, not padding
Each stage is a few minutes of careful clicking, and the parts that genuinely need care are marked as such.
Help on your clock, not ours
Stuck at the zone editor at midnight? The desk answers at any hour, mid-walkthrough included.
Checked at the panel, not imagined
Every instruction was carried out on the platform we run, against a name delegated to our own nameservers. No 'your provider may differ' hedging.
The parts the account already handles
Certificates, daily copies and application installs look after themselves, so the page only covers what is genuinely yours to decide.
Quick Start
Order placed to site online
- 1
Generate the key pair at the mail host
cPanel's Email Deliverability screen creates the pair and displays the record required. On our hosting this is often a single Install button, and the private half never needs to be seen or handled.
- 2
Read the selector out of the record it hands you
The record name is selector._domainkey.yourdomain, and the selector is whatever label the host chose. Write it down: it is what appears as s= in the signature header and what verifiers use to find the key.
- 3
Publish the public half in the delegated zone
Where DNS answers from here, the panel writes it. Where it answers elsewhere, create the record there by hand, and watch for the 255-character string limit if the editor will not accept the value whole.
- 4
Add each other sender's selector alongside
Newsletter platforms and CRMs issue their own selectors, usually as CNAMEs pointing at their infrastructure. Add each one next to the others; they never conflict, and a name signing under four selectors is entirely normal.
- 5
Confirm dkim=pass on your own domain, then leave the keys alone
Send to an outside mailbox and read Authentication-Results: you want dkim=pass with d= naming your domain rather than somebody else's. After that, replace keys on a compromise or a provider move, not on a calendar.
Built In
Fitted to every plan
- SSH, Git and Composer on the developer plans
- Softaculous bundled, for one-click application installs
- 30 days back on hosting plans, 7 on reseller
- No set-up charge at any point, and no joining fee
- Webmail in the browser, plus IMAP, POP and SMTP for any client
- 99.9% uptime as the target, watched around the clock
- A renewal figure identical to the one you registered at
- Plan upgrades applied in place, with no migration and no new server to point at
- WordPress and 400+ other applications in one click
- Your existing site brought across by our engineers at no charge
Frequently Asked
Questions we field again and again
Why does my DNS editor refuse the DKIM record?
Almost always the 255-character limit on a single string inside a TXT record. A 2048-bit public key runs past it, so the value has to be published as several quoted strings that the resolver joins back together. Better editors do this silently; the ones that do not either reject the value outright or truncate it into something that looks published and fails every check.
If I change nameservers, does DKIM keep working?
Only if you rebuild the selector records at the new provider before the delegation moves. The signing host carries on stamping messages regardless, so the gap shows up as verification failures rather than as anything visibly broken. Copy the whole zone across first, confirm it answers, then change the delegation at the registrar.
Which panel will I be working in, and can I have a different one?
cPanel, which the industry standardised on years ago — so every tutorial you find matches your screen and a backup restores onto any other cPanel host. Plesk and DirectAdmin are available on particular plans if you would rather use either of those instead.
Where does the platform physically run from?
A London datacentre with redundant power, cooling and several upstream carriers, with server-level caching in front of it. For most sites how the platform is built — NVMe disks, LiteSpeed, restrained account density per machine — matters considerably more than where the racks happen to stand.
Keep reading
Domain Names
Search, register and transfer names — the first year included with an annual plan.
WordPress Hosting
WordPress looked after for you: LiteSpeed caching, staging copies and a daily backup.
Changing provider? Work through this checklist beforehand.
A straightforward running order for a migration your visitors never spot: which files travel first, how to bring the mail across without dropping a single message, the right moment to repoint DNS, and the two errors that sit behind almost every outage we get called in to fix.
Register the name, then build on it.
Registration, DNS, mailboxes and a certificate on one account — and a desk that answers when a record refuses to resolve.
View Domain Names plans