dkim PROTOCOLHost: Cloudflare DNSStandard: RFC 6376
How to Configure DomainKeys Identified Mail (DKIM) on Cloudflare DNS
Cryptographically signs outbound emails using public/private key pairs to prove message integrity and authenticate sender domain. Follow this verified implementation guide to deploy standard compliant DKIM DNS records in Cloudflare DNS.
Default DKIM Record Syntax
// Authoritative RFC Example
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQ...Configuration Steps in Cloudflare DNS
- 1Log in to the Cloudflare Dashboard and select your domain.
- 2Navigate to the "DNS" -> "Records" management panel.
- 3Locate the dangling CNAME/record for the orphaned subdomain.
- 4Click "Edit" and either update the target to an active resource or click "Delete" to remove it.
- 5Verify that Cloudflare Proxy (Orange Cloud) is enabled if HTTP proxying is required.
Verification Checklist (RFC 6376)
Query the DNS selector TXT/CNAME record at <selector>._domainkey.yourdomain.com.
Validate key length (minimum 2048-bit RSA recommended, 1024-bit deprecated).
Confirm public key matching against outbound SMTP signature headers.
Ensure CNAME delegation targets an active, valid ESP key repository.
Live Validation Engine
Run Free DNS ValidatorValidate Your Cloudflare DNS DKIM Record
Verify propagation, check syntax formatting, and audit recursive lookups in 60 seconds with SubDomainWatch.