Skip to main content
Version: 1.28 (Current)

Verify DKIM DNS Record

Audience: Low-code Engineers

Skill Prerequisites: Actions, Tokens, Conditions

Checks whether a domain publishes a DKIM record with the public key you expect. It saves True or False in a token.

DKIM (DomainKeys Identified Mail) lets a mail server sign outgoing email with a private key. Receiving servers check the signature against a public key that the domain owner publishes in DNS. The key lives in a TXT record at <selector>._domainkey.<domain>, for example mail2026._domainkey.example.com. A typical record looks like v=DKIM1; k=rsa; p=MIIBIjANBgkq..., where p= holds the public key.

This action only reads DNS. It doesn't sign email, and PAA doesn't sign email with DKIM itself. Signing is done by the SMTP server or email provider that sends your mail.

note

This action is part of the Security add-on (DnnSharp.Security). The add-on also provides Generate RSA Keys. If you don't see these two actions, the add-on isn't installed. The action doesn't check a license feature.

Typical Use Cases​

  • Confirm that a customer has published the DKIM record you gave them, before you enable email sending for their domain
  • Build a setup wizard: generate a key pair, show the customer the TXT record, then check it until DNS is updated
  • Check on a schedule that a domain's DKIM record hasn't been changed or removed

Don't use it to​

  • Sign or send email. Use Send Email, and set up DKIM signing on your SMTP server or email provider.
  • Check SPF or DMARC records. The action only looks at the DKIM TXT record for one selector.
  • Fully validate a DKIM record. The check is basic. See How the record is checked.
Action NameDescription
Generate RSA KeysCreates a key pair. Its PublicKey token is in the format this action expects.
Send EmailSends email. DKIM signing happens on the SMTP server, not in PAA.
Add ConnectorCreates a connector, such as an SMTP connector for sending email.
Test ConnectorChecks that a connector, such as an SMTP connector, works.

Input Parameter Reference​

ParameterDescriptionSupports TokensDefaultRequired
DomainThe domain to check, for example example.com. Don't include the selector or _domainkey.Yesempty stringYes
DKIM SelectorThe DKIM selector, for example mail2026. The action looks up <selector>._domainkey.<domain>.Yesempty stringYes
Rsa Public KeyThe public key you expect in the record's p= tag. Use the Base64 key on one line, without -----BEGIN PUBLIC KEY----- headers or line breaks. The [<OutputToken>:PublicKey] token of Generate RSA Keys has this format.Yesempty stringYes
Output TokenThe name of the token that receives the result, for example DkimOk. If it's empty, the action does nothing.Noempty stringYes

Output Parameters Reference​

OutputDescription
[<OutputToken>]True if a matching DKIM record was found, otherwise False. The token is set to False first, so it's False if the domain or selector has no TXT record.

How the record is checked​

The action queries TXT records for <selector>._domainkey.<domain>. It uses the DNS servers configured on the web server. It uses the DnsClient library with its default timeout and retry settings.

Each TXT record is checked on its own. If a record is split into several strings, the strings are joined first. The record is split at ; into tags, and spaces around each tag are removed. Then:

  • A tag that starts with k= must be exactly k=rsa.
  • A tag that starts with p= must be exactly p= followed by Rsa Public Key.
  • All other tags, such as v=DKIM1, h= or t=, are ignored.

If at least one TXT record passes, the result is True.

Considerations​

  • The comparison is exact and case-sensitive. k=RSA, spaces inside the key, or spaces around = (for example p = MIIB...) make the check fail. Remove line breaks from the key before you compare it.
  • A record without a p= tag passes. Any TXT record at the name that has no k= or p= tag counts as a match, for example v=DKIM1 alone. Don't rely on this action alone to prove that the right key is published.
  • An empty Rsa Public Key matches a revoked key. A record with an empty p= tag (a revoked key) matches when Rsa Public Key is empty. Always pass a key.
  • Only RSA keys match. A record with k=ed25519 never passes.
  • DNS changes take time. A new or changed record may not be visible yet because of DNS caching. If you check right after the customer updates DNS, a False result may just mean "not yet". Let users retry later.
  • DNS errors fail the action. A missing record gives False. If the DNS server can't be reached or times out, the action raises an error. Catch it with the On Error actions of Execute Actions if you need to.
  • The inputs aren't validated. Check that Domain and DKIM Selector aren't empty before you run the action. For example, use a condition. See Common Parameters.
  • Keep the private key safe. You only need the public key here. Don't store or show the private key from Generate RSA Keys anywhere users can see it.

Examples​

tip

To understand how to use the below examples, please see Running Examples.

1. Check a customer's DKIM record​

This action checks the record at [Selector]._domainkey.[Domain] against the public key saved for the customer. The result is saved in [DkimOk]. The condition skips the check if the domain is empty.

{
"Title": "Verify DKIM DNS Record",
"ActionType": "VerifyDkimDnsRecord",
"Description": "Check that the customer published the DKIM key",
"Condition": "[Domain] != \"\"",
"Parameters": {
"Domain": "[Domain]",
"DkimSelector": "[Selector]",
"RsaPublicKey": "[DkimPublicKey]",
"OutputToken": "DkimOk"
}
}

Use [DkimOk] in the conditions of the next actions, for example [DkimOk] == "True" to enable sending, or [DkimOk] == "False" to show a message that DNS isn't updated yet.

2. Check a key right after generating it​

This action compares the record with a key created earlier by Generate RSA Keys with the Output Token Dkim. Until the customer adds the record to DNS, the result is False.

{
"Title": "Verify DKIM DNS Record",
"ActionType": "VerifyDkimDnsRecord",
"Description": "Compare DNS with the generated public key",
"Parameters": {
"Domain": "example.com",
"DkimSelector": "mail2026",
"RsaPublicKey": "[Dkim:PublicKey]",
"OutputToken": "DkimOk"
}
}

The customer's TXT record for this example is named mail2026._domainkey.example.com and has the value v=DKIM1; k=rsa; p=[Dkim:PublicKey].

Revised 09/27/2026