dkim PROTOCOLHost: AWS Route 53Standard: RFC 6376
How to Configure DomainKeys Identified Mail (DKIM) on AWS Route 53
Cryptographically signs outbound emails using public/private key pairs to prove message integrity and authenticate sender domain. Follow this verified implementation guide to deploy standard compliant DKIM DNS records in AWS Route 53.
Default DKIM Record Syntax
// Authoritative RFC Example
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQ...Configuration Steps in AWS Route 53
- 1Open the AWS Management Console and navigate to Route 53.
- 2Select "Hosted zones" and click on your domain zone.
- 3Filter records by the target subdomain name.
- 4Select the checkbox next to the orphaned record.
- 5Click "Delete record" and confirm the deletion dialog.
Verification Checklist (RFC 6376)
Query the DNS selector TXT/CNAME record at <selector>._domainkey.yourdomain.com.
Validate key length (minimum 2048-bit RSA recommended, 1024-bit deprecated).
Confirm public key matching against outbound SMTP signature headers.
Ensure CNAME delegation targets an active, valid ESP key repository.
Live Validation Engine
Run Free DNS ValidatorValidate Your AWS Route 53 DKIM Record
Verify propagation, check syntax formatting, and audit recursive lookups in 60 seconds with SubDomainWatch.