Skip to main content
dkim PROTOCOLHost: Azure DNSStandard: RFC 6376

How to Configure DomainKeys Identified Mail (DKIM) on Azure DNS

Cryptographically signs outbound emails using public/private key pairs to prove message integrity and authenticate sender domain. Follow this verified implementation guide to deploy standard compliant DKIM DNS records in Azure DNS.

Default DKIM Record Syntax

// Authoritative RFC Example
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQ...

Configuration Steps in Azure DNS

  1. 1Navigate to the Azure Portal and select "DNS zones".
  2. 2Select your authoritative domain zone.
  3. 3Find the record set corresponding to the dangling subdomain.
  4. 4Click "Delete" from the top command toolbar.
  5. 5Confirm deletion to release the DNS binding.

Verification Checklist (RFC 6376)

Query the DNS selector TXT/CNAME record at <selector>._domainkey.yourdomain.com.
Validate key length (minimum 2048-bit RSA recommended, 1024-bit deprecated).
Confirm public key matching against outbound SMTP signature headers.
Ensure CNAME delegation targets an active, valid ESP key repository.
Live Validation Engine

Validate Your Azure DNS DKIM Record

Verify propagation, check syntax formatting, and audit recursive lookups in 60 seconds with SubDomainWatch.

Run Free DNS Validator