Guide per DNS host

Set up DKIM at IONOS

DKIM signs outgoing mail with a key whose public part lives in DNS. At IONOS the key is generated in the control panel; if the name servers are at IONOS too, the DNS record is usually set automatically. This guide shows both steps and the mistakes that invalidate the signature.

Enable DKIM at IONOS

In the IONOS account open "Email" and enable DKIM signing for the domain; with IONOS name servers the DNS records are created automatically.

If the name servers are elsewhere, create the CNAME records shown there.

IONOS shows the exact include value in the email settings; US accounts use _spf-us.ionos.com.

IONOS shows the exact include value in the email settings; US accounts use _spf-us.ionos.com.

IONOS shows the exact include value in the email settings; US accounts use _spf-us.ionos.com.

IONOS shows the exact include value in the email settings; US accounts use _spf-us.ionos.com.

Other senders sign separately

Every service sending on behalf of the domain needs its own DKIM key with its own selector: the newsletter tool, the CRM, Microsoft 365. The records do not interfere because each lives under a different selector. DMARC then covers all of them.

How to add the DKIM record at IONOS

The way to the IONOS DNS editor:

  • Sign in to the IONOS account and open "Domains & SSL".
  • Click the gear icon next to the domain and choose "DNS".
  • Choose "Add record", pick the type (TXT, MX, CNAME) and host name, paste the value, save.
  • Type and name as shown by the mail provider: usually CNAME or TXT under selector._domainkey. The selector name goes before _domainkey, the host appends the rest of the domain.
  • Changes usually apply within minutes; the default TTL is one hour.
  • Use "@" as the host name for the apex domain; IONOS shows it as the domain name.

Typical mistakes at IONOS

  • Selector missing or misspelled in the name, so the receiver finds no key.
  • TXT value truncated for long keys or split into several records.
  • CNAME next to other records on the same name.
  • DKIM enabled in the control panel but the name servers are elsewhere and the record is missing there.

Verify and keep an eye on it

After saving, the change at IONOS usually applies within minutes. The checker below queries the authoritative name servers and shows right away whether the DKIM record is read correctly. DomainWarn keeps checking the record afterwards and alerts you when it changes or disappears, for example after a migration or one click too many in the DNS editor.

Frequently asked questions

Why does the checker find no DKIM record after enabling it at IONOS?
Either the name servers are not at IONOS and the record is missing there, or the selector differs from the common ones. Enter the selector name from the IONOS control panel in the DKIM checker.
Which key length is right?
2048 bits. 1024 bits is considered too short, longer keys do not fit every DNS editor.
Check now

Free DKIM record check and lookup: selector, key type, key length, syntax and revoked keys. Leave the selector empty to try common selectors automatically.

DomainWarn checks SPF, DKIM, DMARC, DNS and certificates of all client domains regularly and reports changes before mail lands in spam.

Monitor this domain continuously14-day free trial, no credit card.

The same guide for other hosts