"dkim=none" or DKIM not signing: how to turn on DKIM

What's happening: dkim=none means the message carried no DKIM signature at all. Most providers don't sign with your domain until you publish a key and switch signing on, so the DNS record alone isn't always enough.

How to fix it

  1. Google Workspace: Admin console → Apps → Google Workspace → Gmail → Authenticate email. Generate the record, add the google._domainkey TXT, wait for it to resolve, then click Start authentication.
  2. Microsoft 365: publish the selector1._domainkey and selector2._domainkey CNAMEs, then enable DKIM signing for the domain in the Defender portal.
  3. Zoho, SendGrid, Mailchimp, HubSpot and others: open the tool's domain authentication page and add the records it gives you exactly (DNS hosts often append your domain twice; enter only the part before your domain).
  4. Send a test and confirm dkim=pass header.d=yourdomain.com.

Not sure which record is wrong? Check your domain free: it shows which of SPF, DKIM and DMARC is failing, in 5 seconds, no signup.

Other fix guides