What is DKIM?
DKIM (DomainKeys Identified Mail) adds a digital signature to every e-mail sent from your domain. Receiving mail servers use this signature to check that the e-mail really comes from your domain and has not been altered in transit. Without DKIM, your e-mail is much more likely to end up in the spam folder or be rejected by Gmail, Outlook and Microsoft 365.
Requirements
- An active hosting account with Kyzoe with access to cp.vcloudhosting.eu
- An e-mail service that is active for the domain
- Access to the DNS management of the domain (at Kyzoe or at an external registrar/DNS provider)
Step 1 — Log in
- Go to https://cp.vcloudhosting.eu
- Log in with your e-mail address and password.
- In the left-hand menu, click Websites and select the website/domain for which you want to enable DKIM.
Step 2 — Go to the e-mail settings
- In the menu of the selected website, click Email.
- Open the Settings tab (or Instellingen).
- Here you will see the domain’s e-mail configuration, including the DKIM section.
Step 3 — Enable DKIM
- Set the Enable DKIM switch to on.
- Enhance generates a key pair automatically and displays the corresponding DNS record.
- Click Save / Opslaan.
Step 4 — Add the DNS record
Enhance now displays a TXT record with the following structure:
- Type: TXT
- Name / Host:
default._domainkey(or the selector shown by Enhance, e.g.x._domainkey) - Value:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A...(long key) - TTL: 3600 (or default)
Situation A — DNS is managed within the control panel
If your domain’s DNS zone runs at Kyzoe/Enhance, the record is in most cases created automatically. Check this via Websites → your domain → DNS and look for the _domainkey record. If it is not there, add it manually using the details above.
Situation B — DNS is managed externally (e.g. Cloudflare or registrar)
Copy the full value from the control panel and create the TXT record manually at your DNS provider.
Please note:
- Copy the full key, without adding spaces or line breaks.
- Some DNS panels require you to enter only
default._domainkey, others the fulldefault._domainkey.uwdomein.be. Do not add the domain twice. - With Cloudflare, the record must be set to DNS only (grey cloud) — proxying does not apply to TXT records.
Step 5 — Verify
DNS changes can take up to 24 hours to propagate worldwide, although in practice it usually takes 5 to 30 minutes.
Then check:
- Via the command line:
dig TXT default._domainkey.uwdomein.be +short
- Or via an online tool such as mxtoolbox.com/dkim.aspx (enter the domain and selector
default). - Send a test e-mail to a Gmail address, open the e-mail and click the three dots → Show original. Next to DKIM, it should say
PASS.
Recommended: combine with SPF and DMARC
DKIM alone is not enough. For good deliverability, we recommend setting up all three records correctly:
- SPF (TXT on
@):v=spf1 include:spf.uwmailserver.be ~all - DKIM (TXT on
default._domainkey): as above - DMARC (TXT on
_dmarc):v=DMARC1; p=none; rua=mailto:dmarc@uwdomein.be
Start with DMARC set to p=none to collect reports, and tighten the policy later to quarantine or reject.
Common problems
- DKIM keeps showing “fail”
The DNS record has not propagated (correctly), or there is an old key in the zone. Remove outdated_domainkeyrecords and check for typos. - The key is truncated or too long
Some DNS panels truncate long TXT values. In that case, split the value into parts of no more than 255 characters, each between quotation marks, or use a DNS provider that handles this automatically (such as Cloudflare). - DKIM works for the website, but not for e-mail from an external platform
If you send e-mail via an external service (Amazon SES, Mailchimp, a CRM …), that service has its own DKIM selector and its own record. Add it separately — multiple DKIM records side by side are perfectly fine as long as the selectors differ. - E-mail still ends up in spam
Check that your IP address or domain is not on a blocklist. You can test this via mxtoolbox.com/blacklists.aspx.
Need help?
Contact Kyzoe support at support@kyzoe.be. Please include the domain and, if possible, the full headers of a test e-mail.