"dkim=none" or DKIM not signing: how to turn on DKIM
What's happening: dkim=none means the message carried no DKIM signature at all. Most providers don't sign with your domain until you publish a key and switch signing on, so the DNS record alone isn't always enough.
How to fix it
- Google Workspace: Admin console → Apps → Google Workspace → Gmail → Authenticate email. Generate the record, add the
google._domainkeyTXT, wait for it to resolve, then click Start authentication. - Microsoft 365: publish the
selector1._domainkeyandselector2._domainkeyCNAMEs, then enable DKIM signing for the domain in the Defender portal. - Zoho, SendGrid, Mailchimp, HubSpot and others: open the tool's domain authentication page and add the records it gives you exactly (DNS hosts often append your domain twice; enter only the part before your domain).
- Send a test and confirm
dkim=pass header.d=yourdomain.com.
Not sure which record is wrong? Check your domain free: it shows which of SPF, DKIM and DMARC is failing, in 5 seconds, no signup.