DKIM (DomainKeys Identified Mail) is an email authentication method that helps verify that an email message was indeed sent by the domain it claims to be from and ensures the message has not been altered in transit. Along with SPF and DMARC, DKIM helps prevent domain spoofing and phishing attacks.
INKY uses DKIM as part of its sender authentication checks to validate emails. Properly authenticated mail with valid DKIM signatures is automatically trusted by INKY, reducing false spoofing alerts. If third-party services send mail on your behalf and are properly configured with DKIM (along with SPF and DMARC), INKY will honor that authentication without additional configuration.
If third-party senders are NOT properly authenticated with DKIM/SPF/DMARC, you can configure them as trusted third-party senders in INKY to prevent false alerts by mapping their sending domains (not your own domain) Trusted Third-Party Senders.
Also, for allow list entries or bypass lists, enabling DMARC authentication (which includes DKIM validation) helps ensure only legitimately authenticated emails are allowed or bypassed, protecting against spoofing Allow List Overview, Bypass INKY in Google Workspace.
In summary, DKIM is a key authentication mechanism INKY relies upon for accurate sender verification and threat detection.
To set up DKIM with INKY, follow these guidelines:
-
DKIM Signing Is Managed by Your Mail Provider
INKY does not require or provide its own DKIM DNS records. Instead, you must enable and configure DKIM signing for your domain using your mail provider (e.g., Microsoft 365 or Google Workspace).- For Microsoft 365: Enable DKIM in the Microsoft 365 Security & Compliance Center or via PowerShell for your custom domains.
- For Google Workspace: Enable DKIM in the Google Admin Console for your domain.
-
DNS Configuration
- Publish the DKIM public key as a TXT record in your domain’s DNS, as instructed by your mail provider.
- INKY does not require you to add any INKY-specific DKIM records to your DNS. Maintain your provider’s DKIM configuration.
-
INKY Compatibility
- INKY operates inline and does not break or alter DKIM signatures. It analyzes emails after they are signed by your mail system, so as long as your DKIM is set up and working, INKY will respect and verify those signatures during scanning.
- There is no need to publish or enable DKIM signing directly through INKY. INKY does not add or replace DKIM signatures; it relies on your existing mail flow and authentication setup.
-
Testing and Troubleshooting
- After setup, send test emails and verify that DKIM signatures pass using tools like MXToolbox or your mail provider’s reporting.
- If you experience DKIM failures, ensure that your mail flow and DNS settings are correct and that INKY is properly authorized in your SPF record.
Summary:
- Set up DKIM through your mail provider (Microsoft 365 or Google Workspace).
- Publish the DKIM public key in your DNS as instructed by your provider.
- No INKY-specific DKIM records are needed.
- INKY will honor and verify your existing DKIM signatures as part of its scanning process.
If you use third-party senders, ensure they are also configured with DKIM aligned to your domain, or use INKY’s Trusted Third-Party Senders configuration if DKIM cannot be set up for those services.
For setting up DKIM with INKY for both Microsoft 365 and Google Workspace:
Microsoft 365
-
Enable DKIM Signing in Microsoft 365:
- Go to the Microsoft 365 Security & Compliance Center.
- Navigate to Threat management > Policy > DKIM.
- Select your domain and enable DKIM signing.
- If prompted, publish the two CNAME records provided by Microsoft 365 in your DNS. These typically look like:
- selector1._domainkey.yourdomain.com CNAME selector1-yourdomain-com._domainkey.<yourtenant>.onmicrosoft.com
- selector2._domainkey.yourdomain.com CNAME selector2-yourdomain-com._domainkey.<yourtenant>.onmicrosoft.com
- Wait for DNS propagation, then confirm DKIM is enabled for your domain.
-
INKY Compatibility:
- INKY operates inline and does not break DKIM signing. No INKY-specific DKIM records are needed.
- Ensure your SPF record includes INKY’s mechanisms (see INKY’s SPF update guidance).
- After setup, send test emails to verify DKIM signatures pass and INKY banners appear correctly.
-
Mail Flow:
- Make sure mail flow rules and connectors are configured per the INKY Platform Setup Guide for Microsoft 365 to avoid disrupting DKIM or other authentication protocols [please refer to https://kaseya.zendesk.com/agent/tickets/7023720 for more info] [please refer to https://kaseya.zendesk.com/agent/tickets/7072526 for more info] [please refer to https://kaseya.zendesk.com/agent/tickets/6862106 for more info] [please refer to https://kaseya.zendesk.com/agent/tickets/6955548 for more info] [please refer to data_source_html/kaseya/zendesk_tickets_v2_kaseya/https://kaseya.zendesk.com/agent/tickets/6931122 for more info].
Google Workspace
-
Enable DKIM Signing in Google Workspace:
- Log in to the Google Admin Console (https://admin.google.com).
- Go to Apps > Google Workspace > Gmail > Authenticate email.
- Select your domain and click Generate new record.
- Add the provided TXT record to your DNS.
- After DNS propagation, return to the Admin Console and click Start authentication.
-
INKY Compatibility:
- INKY does not require or provide its own DKIM records. Use the DKIM keys generated by Google Workspace.
- Make sure your SPF record includes INKY’s mechanism for Google Workspace:
- v=spf1 include:_spf.google.com exists:%{i}._spf.inkyphishfence.com ~all
- After setup, send test emails and verify DKIM signatures pass.
-
Mail Flow:
- Ensure your mail routing is set up to route emails through INKY for scanning and sending.
- If you experience DKIM failures, check that INKY is properly authorized in your SPF record and that mail flow is not bypassing INKY [please refer to https://kaseya.zendesk.com/agent/tickets/7037919 for more info] [please refer to https://feedback.inky.com/en/help/articles/5496065-google-workspace for more info] [please refer to https://kaseya.zendesk.com/agent/tickets/7072526 for more info] [please refer to https://kaseya.zendesk.com/agent/tickets/6955548 for more info] [please refer to data_source_html/kaseya/zendesk_tickets_v2_kaseya/https://kaseya.zendesk.com/agent/tickets/6931122 for more info].
General Notes:
- Only one system should sign DKIM for a given domain at a time—do not mix INKY and Microsoft/Google DKIM selectors for the same domain.
- Allow up to 48 hours for DNS changes to propagate.
- For third-party senders, ensure they are DKIM-authenticated or use INKY’s Trusted Third-Party Senders configuration if needed.