Verify DKIM DNS Record
Audience:
Low-code EngineersSkill Prerequisites:
Actions,Tokens,Conditions
Checks whether a domain publishes a DKIM record with the public key you expect. It saves True or False in a token.
DKIM (DomainKeys Identified Mail) lets a mail server sign outgoing email with a private key. Receiving servers check the signature against a public key that the domain owner publishes in DNS. The key lives in a TXT record at <selector>._domainkey.<domain>, for example mail2026._domainkey.example.com. A typical record looks like v=DKIM1; k=rsa; p=MIIBIjANBgkq..., where p= holds the public key.
This action only reads DNS. It doesn't sign email, and PAA doesn't sign email with DKIM itself. Signing is done by the SMTP server or email provider that sends your mail.
This action is part of the Security add-on (DnnSharp.Security). The add-on also provides Generate RSA Keys. If you don't see these two actions, the add-on isn't installed. The action doesn't check a license feature.
Typical Use Cases
- Confirm that a customer has published the DKIM record you gave them, before you enable email sending for their domain
- Build a setup wizard: generate a key pair, show the customer the TXT record, then check it until DNS is updated
- Check on a schedule that a domain's DKIM record hasn't been changed or removed
Don't use it to
- Sign or send email. Use Send Email, and set up DKIM signing on your SMTP server or email provider.
- Check SPF or DMARC records. The action only looks at the DKIM TXT record for one selector.
- Fully validate a DKIM record. The check is basic. See How the record is checked.
Related Actions
| Action Name | Description |
|---|---|
| Generate RSA Keys | Creates a key pair. Its PublicKey token is in the format this action expects. |
| Send Email | Sends email. DKIM signing happens on the SMTP server, not in PAA. |
| Add Connector | Creates a connector, such as an SMTP connector for sending email. |
| Test Connector | Checks that a connector, such as an SMTP connector, works. |
Input Parameter Reference
| Parameter | Description | Supports Tokens | Default | Required |
|---|---|---|---|---|
| Domain | The domain to check, for example example.com. Don't include the selector or _domainkey. | Yes | empty string | Yes |
| DKIM Selector | The DKIM selector, for example mail2026. The action looks up <selector>._domainkey.<domain>. | Yes | empty string | Yes |
| Rsa Public Key | The public key you expect in the record's p= tag. Use the Base64 key on one line, without -----BEGIN PUBLIC KEY----- headers or line breaks. The [<OutputToken>:PublicKey] token of Generate RSA Keys has this format. | Yes | empty string | Yes |
| Output Token | The name of the token that receives the result, for example DkimOk. If it's empty, the action does nothing. | No | empty string | Yes |
Output Parameters Reference
| Output | Description |
|---|---|
[<OutputToken>] | True if a matching DKIM record was found, otherwise False. The token is set to False first, so it's False if the domain or selector has no TXT record. |
How the record is checked
The action queries TXT records for <selector>._domainkey.<domain>. It uses the DNS servers configured on the web server. It uses the DnsClient library with its default timeout and retry settings.
Each TXT record is checked on its own. If a record is split into several strings, the strings are joined first. The record is split at ; into tags, and spaces around each tag are removed. Then:
- A tag that starts with
k=must be exactlyk=rsa. - A tag that starts with
p=must be exactlyp=followed by Rsa Public Key. - All other tags, such as
v=DKIM1,h=ort=, are ignored.
If at least one TXT record passes, the result is True.
Considerations
- The comparison is exact and case-sensitive.
k=RSA, spaces inside the key, or spaces around=(for examplep = MIIB...) make the check fail. Remove line breaks from the key before you compare it. - A record without a
p=tag passes. Any TXT record at the name that has nok=orp=tag counts as a match, for examplev=DKIM1alone. Don't rely on this action alone to prove that the right key is published. - An empty Rsa Public Key matches a revoked key. A record with an empty
p=tag (a revoked key) matches when Rsa Public Key is empty. Always pass a key. - Only RSA keys match. A record with
k=ed25519never passes. - DNS changes take time. A new or changed record may not be visible yet because of DNS caching. If you check right after the customer updates DNS, a
Falseresult may just mean "not yet". Let users retry later. - DNS errors fail the action. A missing record gives
False. If the DNS server can't be reached or times out, the action raises an error. Catch it with theOn Erroractions of Execute Actions if you need to. - The inputs aren't validated. Check that Domain and DKIM Selector aren't empty before you run the action. For example, use a condition. See Common Parameters.
- Keep the private key safe. You only need the public key here. Don't store or show the private key from Generate RSA Keys anywhere users can see it.
Examples
To understand how to use the below examples, please see Running Examples.
1. Check a customer's DKIM record
This action checks the record at [Selector]._domainkey.[Domain] against the public key saved for the customer. The result is saved in [DkimOk]. The condition skips the check if the domain is empty.
{
"Title": "Verify DKIM DNS Record",
"ActionType": "VerifyDkimDnsRecord",
"Description": "Check that the customer published the DKIM key",
"Condition": "[Domain] != \"\"",
"Parameters": {
"Domain": "[Domain]",
"DkimSelector": "[Selector]",
"RsaPublicKey": "[DkimPublicKey]",
"OutputToken": "DkimOk"
}
}
Use [DkimOk] in the conditions of the next actions, for example [DkimOk] == "True" to enable sending, or [DkimOk] == "False" to show a message that DNS isn't updated yet.
2. Check a key right after generating it
This action compares the record with a key created earlier by Generate RSA Keys with the Output Token Dkim. Until the customer adds the record to DNS, the result is False.
{
"Title": "Verify DKIM DNS Record",
"ActionType": "VerifyDkimDnsRecord",
"Description": "Compare DNS with the generated public key",
"Parameters": {
"Domain": "example.com",
"DkimSelector": "mail2026",
"RsaPublicKey": "[Dkim:PublicKey]",
"OutputToken": "DkimOk"
}
}
The customer's TXT record for this example is named mail2026._domainkey.example.com and has the value v=DKIM1; k=rsa; p=[Dkim:PublicKey].
Revised 09/27/2026