Your emails are landing in spam. You've checked everything else - your list quality looks fine, your copy isn't screaming "BUY NOW," your domain reputation tool says you're clean. So you run a test through a mail tester and see it: DKIM failed.

Now you're stuck. DKIM feels like infrastructure voodoo. You set it up months ago, maybe a year ago, and forgot about it. But here's the thing - DKIM not working isn't actually complicated once you know what to look for. It's usually one of maybe five specific problems, and I'm going to walk you through all of them.

First: Check If DKIM Is Actually Broken

Before you tear apart your DNS records, verify that DKIM is actually failing. The easiest way is to send a test email to yourself and check the full headers. In Gmail, click the three dots on an email, then "Show original." Look for the Authentication-Results line.

You're looking for something like this:

Authentication-Results: mx.google.com; dkim=pass [email protected]; spf=pass

If you see dkim=pass, you're fine - DKIM is working. If you see dkim=fail, then keep reading. If you see dkim=none, DKIM isn't set up at all yet.

You can also use MXToolbox's DKIM checker or similar free tools. Just input your domain and your selector (usually "default" or "selector1" depending on your email provider), and it'll tell you if the record exists and validates correctly.

Problem 1: Your DKIM Record Doesn't Exist in DNS

This is the most common one. You think you set DKIM up, but you never actually added the DNS record. Or you added it but to the wrong domain.

Log into your DNS provider (GoDaddy, Cloudflare, Route53, wherever you manage your domain). Search for DKIM records. You should see a TXT record that looks something like:

default._domainkey.yourdomain.com TXT v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3...

If that record doesn't exist, you haven't actually completed the DKIM setup. Go back to wherever you're sending from - Gmail, Outlook, AWS SES, lemlist, whatever - and get the exact DKIM record they're asking you to add. Then add it to DNS exactly as specified, selector and all. DNS changes can take up to 48 hours to propagate, but usually it's 15-30 minutes.

If you're using multiple domains, make sure you're checking the right one. A lot of people set DKIM for their primary domain but then send from a subdomain. Those need separate records.

Problem 2: Your DNS Record Is There, But It's Wrong

Sometimes the record exists but it got corrupted or truncated. This happens most often when you copy-paste from an email or document that has formatting issues.

Pull up your DKIM record in DNS and copy it into a text editor. Check that:

If something looks wrong, delete it and re-add it carefully. Copy directly from your email provider's setup page, not from an old email or screenshot.

Problem 3: You're Using the Wrong Selector

Your email provider generates DKIM records with a specific selector - usually something like "default," "selector1," or "s1." Your email software also needs to be configured to sign with that same selector.

For example, if you added a DKIM record for "selector1._domainkey.yourdomain.com" but your email provider is configured to sign with "default," the signatures won't match and DKIM will fail.

Check your email provider's settings. In Gmail, it's in the domain setup area. In Outlook/Microsoft 365, check the DKIM settings in the Microsoft 365 admin center. In lemlist or other cold email platforms, look in domain settings. Make sure the selector you're using to sign matches the selector in your DNS record exactly.

Problem 4: You Set Up DKIM But Never Actually Enabled It

This one catches people off guard. You added the DNS record, everything looks right, but your email software isn't actually signing messages with DKIM.

Check the toggle or checkbox in your email provider's DKIM settings. In Microsoft 365, DKIM sometimes defaults to off - you have to explicitly enable it. Same with some other platforms. If the setting says "Enable DKIM signing" and it's not turned on, turn it on and wait 24 hours for it to take effect.

Problem 5: Your Public Key Is Malformed

If your DKIM record exists, your selector is right, and DKIM signing is enabled but it's still failing, your public key might be corrupted. This can happen if you were using an old or improperly generated key.

The solution is to generate a new DKIM record. In most platforms, you can rotate or regenerate your DKIM keys - Gmail has a "Generate new record" button, Microsoft 365 lets you rotate keys, etc. Generate a fresh one, replace the old DNS record with the new public key, and test again.

The 60-Second Verification Process

Once you've made changes, here's how to verify DKIM is actually working:

If it still says fail or none after 24 hours, go back through the checklist above. 90% of the time it's either a missing record, a wrong selector, or DKIM signing disabled.

Getting DKIM working properly matters because it's one of three core authentication protocols that email providers use to decide if you're legitimate. If you're serious about cold email, you need all three - and that's what we cover in depth in our complete SPF, DKIM, DMARC setup guide.

When DIY Infrastructure Gets Messy

Knowing how to debug DKIM is valuable. But setting up authentication infrastructure correctly, keeping it maintained, monitoring it for breaks, and then managing all the other pieces of a cold email operation - domain rotation, IP warmup, list sourcing, copy testing, campaign management - is a lot of moving parts.

Most agencies and service businesses that run cold email at scale end up spending more time fixing infrastructure problems than actually sending emails. That's the gap BEC Growth closes - we handle all of this (infrastructure, domains, lists, copy, campaign execution, reply management) so you can focus on converting leads into clients. If you're running multiple cold email campaigns and infrastructure keeps pulling your attention away, that might be worth a conversation.

Related Guides