How To Generate And Configure A DKIM Record For MailEnable On AccuWeb Hosting

How To Generate And Configure A DKIM Record For MailEnable On AccuWeb Hosting

How to set up DKIM and SPF records

DomainKeys Identified Mail (DKIM) is a critical email authentication protocol that adds a cryptographic signature to outgoing messages, allowing receiving servers to verify that the email was not tampered with during transit. To successfully implement this on MailEnable hosted via AccuWeb, administrators must generate the public-private key pair within the MailEnable management console, publish the public component to their DNS records, and ensure the local signing service is enabled for the specific domain.


Pre-Deployment Infrastructure and Technical Prerequisites

Before initiating the DKIM generation process, ensure that your mail server environment meets the structural requirements for successful cryptographic handshakes. Attempting to deploy DKIM without these foundations often results in delivery failure or authentication bypass errors.



  • Essential Software Requirements: Access to the MailEnable Administration console (Standard, Professional, or Enterprise edition) with administrative privileges. Ensure your server is running a version of MailEnable that supports DomainKeys (generally 7.0 or higher).
  • Administrative Access: You must have the ability to modify DNS records for your domain through your AccuWeb Hosting control panel (SolidCP or Plesk) or your third-party DNS provider.
  • Prerequisite Knowledge: Basic familiarity with DNS resource records (specifically TXT records), selector terminology, and the impact of TTL (Time to Live) settings.
  • Time Allocation: The generation process takes approximately 10 minutes, while DNS propagation for the new TXT record may take between 1 and 24 hours depending on global recursive resolver caching.
  • Security Standard: Ensure your server clock is synchronized via NTP (Network Time Protocol) to prevent signature validation failures caused by time drift.

Procedural Workflow for DKIM Signature Implementation

Generating a DKIM signature involves a two-part handshake: the generation of the cryptographic key pair on the server and the publication of the public key to the public Internet through your DNS host.



Step 1: Initialize DomainKeys in MailEnable

Log in to your server via Remote Desktop and launch the MailEnable Administration console. Navigate to the Messaging Manager, expand the Servers node, and then expand the local server node. Locate the Connectors icon, expand it, and select the SMTP connector. Right-click the SMTP connector and select Properties, then navigate to the DomainKeys tab. Here, check the option to enable DomainKeys.

Pro-Tip: Always select the strongest possible key length if your version of MailEnable allows it. A 2048-bit key is currently the industry standard, though 1024-bit is the minimum required to ensure compatibility with older receiving gateways.



Step 2: Generate the Key Pair

Within the DomainKeys tab of the SMTP properties, you will see a button to create or generate a key. Input your domain name and a selector. A selector is a unique identifier used to distinguish between multiple DKIM keys for the same domain. It is common practice to use a date-based selector or a generic term like mail1. Clicking generate will create the public and private key files in the configuration directory of your MailEnable installation.



Step 3: Extract the Public Key for DNS

Once generated, the system will display the public key string. This is a long alphanumeric sequence that acts as the public half of your cryptographic pair. Copy this entire string exactly as it appears. Do not include spaces, line breaks, or special characters that are not part of the provided string, as any modification will cause the authentication to fail during the verification stage.



Step 4: Publish the TXT Record to DNS

Log in to your AccuWeb Hosting control panel and locate the DNS Zone Editor. Create a new TXT record. The host field for this record should follow the format selector._domainkey.yourdomain.com. Paste the public key string into the TXT value field. Set the TTL to a standard value such as 3600 seconds to ensure the record propagates efficiently.

Warning: Ensure there are no hidden quotes or extra characters in the TXT value field. Many DNS managers automatically wrap entries in quotes, which may invalidate the signature if double-quoted.


How to create a DKIM record for your domains? - Salesmate

How to create a DKIM record for your domains? - Salesmate

Cryptographic and Configuration Parameters for MailEnable

When deploying DKIM, accuracy in string formatting is non-negotiable. The following table outlines the expected configuration parameters to ensure your implementation adheres to current RFC 6376 standards.



Parameter Recommended Specification Notes
Key Length 2048 bits Provides optimal balance between security and compatibility.
Record Type TXT Must be published as a TXT, not a CNAME.
Selector Unique Identifier Can be alphanumeric; e.g., mail2023.
TTL 3600 Seconds Allows for rapid updates if the key must be rotated.
Canonicalization Simple/Simple The default for most MailEnable setups; ensures header stability.

Troubleshooting Common Authentication Failures

Even with perfect configuration, environment-specific issues can disrupt email deliverability. Use these troubleshooting steps to diagnose failure points.



  • DNS Propagation Delay: If your email headers show "dkim=neutral" or "dkim=none," the DNS record may not have propagated. Use an external DNS lookup tool to verify that the TXT record is visible to the public. If it is not visible, wait an additional four hours.
  • Signature Mismatch: If the receiving server reports "dkim=fail," the private key on the server no longer matches the public key published in DNS. This typically happens if the keys were regenerated without updating the DNS record. Actionable Fix: Regenerate the key in MailEnable, copy the new string, and overwrite the existing TXT record in your DNS manager.
  • Record Truncation: Some older DNS control panels have character limits for TXT records. If your 2048-bit key is truncated, the signature will be invalid. Actionable Fix: Confirm with your DNS host that they support 2048-bit records. If they do not, you may be forced to use a 1024-bit key, which is less secure but more likely to be accepted by legacy DNS providers.

Frequently Asked Questions



Why does my email still land in spam after adding DKIM?

DKIM is only one piece of the authentication puzzle. Ensure that your Sender Policy Framework (SPF) and DMARC records are also correctly configured, as email filters evaluate all three protocols in combination to determine sender reputation.



How often should I rotate my DKIM keys?

Industry best practices recommend rotating DKIM keys at least once every 12 months, or immediately if you suspect that your mail server’s private key has been compromised or if your server has been migrated to new hardware.



Can I use the same DKIM key for multiple domains?

While technically possible by publishing the same TXT record, it is considered a security risk. Best practice dictates generating a unique key pair for every individual domain to prevent a breach of one domain from affecting the reputation of the others.



Does DKIM affect email encryption or privacy?

No, DKIM does not encrypt the body of the email. It is strictly an authentication mechanism designed to prevent sender spoofing; for actual content privacy, you should use TLS or S/MIME.

Implement DKIM today to fortify your sender reputation and ensure your legitimate communications reach the inbox reliably. If you require advanced assistance with server-side authentication headers, contact your AccuWeb technical support team to verify your DNS integration.


How to Easily Set Up a DKIM Record - Step-by-Step Guide

How to Easily Set Up a DKIM Record - Step-by-Step Guide

Read also: oasis coffee: The 2026 Supply Chain Shock and Market Realignment