dkim PROTOCOLHost: Azure DNSStandard: RFC 6376
How to Configure DomainKeys Identified Mail (DKIM) on Azure DNS
Cryptographically signs outbound emails using public/private key pairs to prove message integrity and authenticate sender domain. Follow this verified implementation guide to deploy standard compliant DKIM DNS records in Azure DNS.
Default DKIM Record Syntax
// Authoritative RFC Example
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQ...Configuration Steps in Azure DNS
- 1Navigate to the Azure Portal and select "DNS zones".
- 2Select your authoritative domain zone.
- 3Find the record set corresponding to the dangling subdomain.
- 4Click "Delete" from the top command toolbar.
- 5Confirm deletion to release the DNS binding.
Verification Checklist (RFC 6376)
Query the DNS selector TXT/CNAME record at <selector>._domainkey.yourdomain.com.
Validate key length (minimum 2048-bit RSA recommended, 1024-bit deprecated).
Confirm public key matching against outbound SMTP signature headers.
Ensure CNAME delegation targets an active, valid ESP key repository.
Live Validation Engine
Run Free DNS ValidatorValidate Your Azure DNS DKIM Record
Verify propagation, check syntax formatting, and audit recursive lookups in 60 seconds with SubDomainWatch.