Learning Hub · Intermediate · 15 minutes
How to Set Up DKIM Signing
Everything you need to cryptographically sign your mail so tampering and spoofing show — the steps, the gotcha, and the tip the support desk gives everyone.
The short answer
Goal: cryptographically sign your mail so tampering and spoofing show. Time needed: 15 minutes. Difficulty: intermediate.
The walkthrough below covers each step, the mistake most people make, and the shortcut worth knowing. On HostingAlly plans, several of the steps are handled for you — we note where.
Written by the HostingAlly team · Last revised 27 July 2026
Intermediate
Skill level
5
Steps to done
Free
Support included
Tested
On our platform
You don't need to be technical for this — the walkthrough is written for first-timers, tested against our own platform, and honest about which parts are genuinely fiddly versus merely unfamiliar.
One promise before starting: nothing in this guide is irreversible. Where a step could bite, we say so and give the undo.
What you'll do, at a glance
The whole job breaks into clear stages: enable dkim in the panel, publish the selector record, repeat per sending service, verify signatures end-to-end and leave keys stable.
Each stage is a few minutes of focused clicking — the elapsed time mostly depends on how familiar the control panel already feels. The detailed steps are listed further down this page; skim the whole route once before starting.
Where this goes wrong (and how to not)
Enabling DKIM in the panel while DNS lives elsewhere — the signature goes out referencing a public key the world can't fetch, and verification fails as 'key not found' until the record is published at the actual DNS host.
Forewarned is genuinely forearmed here — this exact mistake accounts for most of the frustration this topic produces, and it's entirely avoidable once named.
One habit that makes this easier forever
DKIM survives forwarding where SPF breaks — which is why both exist; the signature travels inside the message while SPF judges the delivering server.
It costs a minute now and repays it every time this task comes around again — which, like most hosting tasks, it will.
The parts you can skip on our hosting
Several steps in this guide exist because hosting historically made you do them — on our plans, SSL issues itself, backups run daily without being asked, and one-click installers replace manual setup entirely. What remains is the genuinely-yours part of the task.
And when a step misbehaves anyway, support answers around the clock — with the actual fix, not a knowledge-base link and a shrug. Half our best guides started as patterns in the tickets.

Why this is simpler on HostingAlly
Every walkthrough in our Learning Hub is tested on the platform we actually run — cPanel, LiteSpeed, NVMe, one-click installs — so instructions match your screen instead of gesturing at it.
Every plan includes free SSL that renews itself, so the padlock is never your job.
- Step-by-step, tested as written
- The gotcha flagged before you hit it
- Automation covers the boring steps
- 24/7 support if you get stuck
Why HostingAlly
Every plan includes this, whatever you pay
No jargon tax
Terms are explained in place or linked to the glossary — nothing assumes you already know.
Written from real tickets
Our guides come from the support desk — the gotchas are the ones people actually hit.
5 steps, no filler
Each stage is a few minutes of focused clicking, with the fiddly parts marked as fiddly.
Help on standby
Stuck at step three at midnight? Support answers around the clock, mid-guide included.
Works as written
Every step tested on our own platform — no 'your host may vary' hand-waving.
Automation where it belongs
SSL, backups and installs run themselves here — the guide covers only what's genuinely yours to do.
Getting Started
How to get going
- 1
Enable DKIM in the panel
cPanel's Email Deliverability screen generates the key pair and shows the exact DNS record — on our hosting, often one click to install.
- 2
Publish the selector record
The public key lives in a TXT record at selector._domainkey.yourdomain — the panel installs it automatically when DNS is hosted here.
- 3
Repeat per sending service
Newsletter and CRM platforms sign with their own keys — each provides its own selector records (often CNAMEs) to add alongside.
- 4
Verify signatures end-to-end
Send to a mail-tester service or inspect headers at Gmail — dkim=pass with your domain is the goal state.
- 5
Leave keys stable
DKIM keys aren't secrets to rotate nervously — change them when compromised or migrating, not on a schedule that breaks alignment.
Included
What's covered on our plans
- 99.9% uptime commitment, monitored around the clock
- Free WebP image optimisation built in
- 30-day money-back guarantee on hosting plans
- No setup fees, ever
- Webmail plus IMAP, POP and SMTP access
- Renewal prices that match signup prices
- SSH, Git and Composer access on developer-friendly plans
- Softaculous one-click app installer
- Staging environments for risk-free changes
- NVMe SSD storage as standard
FAQ
Your questions, answered
What visible difference does DKIM make?
None to readers, everything to filters — dkim=pass with domain alignment feeds sender reputation and enables DMARC enforcement. It's plumbing whose absence shows up as spam-folder placement.
Do I need DKIM for each service that sends as my domain?
Yes — each sender signs independently with its own selector. Multiple selectors coexist happily; the point is that every legitimate mail stream carries a verifiable signature.
Do you include email with hosting?
Yes — mailboxes on your own domain come with every hosting plan, with webmail, IMAP/POP/SMTP access and spam filtering. Standalone email hosting also exists for domains whose websites live elsewhere.
Where are your servers located?
Our hosting infrastructure runs from European datacentres with London at the core, behind server-level caching that keeps cached pages fast worldwide. For most sites, platform quality — NVMe storage, LiteSpeed, sensible server density — matters far more than the datacentre's postcode.
Is SSL really included at no cost?
On every plan, with no exceptions — certificates are issued automatically when your domain points to us and renew themselves before expiry. The encryption is identical to paid DV certificates; paid tiers exist only for wildcard convenience or organisation-level validation.
Can I choose my PHP version?
Yes — PHP versions are selectable per site from the control panel, so a legacy application and a current one can live side by side. Extensions and per-site settings are adjustable in the same place, no support ticket needed.
Do you support staging sites?
Yes — plans with staging let you clone the live site, test changes safely, and push to production when ready. It's the difference between 'I hope this update works' and knowing it does.
Planning to switch hosts? Grab the checklist here.
The steps that keep a site migration dull rather than dramatic: what to back up first, how to shift email across without losing a single message, when to touch DNS, and the two mistakes behind nearly every hour of downtime we come across.
Your site deserves better hosting.
From your first site to a fleet of servers, the upgrade path is an account change, not a migration.
View Reseller Hosting plans