How DKIM Affects Email Sent from Joomla
Understand where DKIM normally sits in the Joomla mail path
DomainKeys Identified Mail adds a cryptographic signature that lets a receiver verify that a signing domain took responsibility for the message and that signed content was not improperly altered. In many Joomla deployments the SMTP or transactional mail provider performs DKIM signing after Joomla submits the message, so DKIM configuration usually belongs at the mail provider and DNS layer.
Know what the DKIM signature identifies
A DKIM-Signature header includes a signing domain in the d= tag and a selector in the s= tag. The receiver uses those values to find the public key in DNS and validate the signature. A valid DKIM signature authenticates the signing domain; it does not by itself prove that the visible From address belongs to that domain.
Publish the provider's DKIM key correctly
Enable DKIM in the mail provider and publish the DNS record or records it specifies. RFC 6376 places DKIM keys below the _domainkey namespace, using the selector to identify the key. Copy the provider's host name and value exactly, allow for DNS propagation, and use its verification tool before assuming signing is active.
Check DMARC alignment as well as DKIM validity
For DKIM to satisfy DMARC, a valid DKIM signing domain must align with the message's Author/From domain under the domain's selected alignment mode. A third-party provider can produce dkim=pass using its own unrelated domain while DMARC still fails. Configure a custom signing domain when the provider supports it.
Avoid modifications that break a signature
DKIM signs selected headers and the message body using canonicalization rules. Systems that materially modify signed content after signing can invalidate the signature. If Joomla submits mail to a provider that signs at the final outbound stage, this is less likely; if another relay modifies the message afterward, inspect the authentication results and mail path.
Inspect Authentication-Results on a received message
Send a fresh Joomla test message and view its original headers. Look for dkim=pass or dkim=fail, the signing d= domain, selector, and DMARC result. If DKIM fails, verify the DNS key, selector, provider signing status, and whether the message changed in transit. Do not diagnose DKIM only from the existence of a DNS record.
Rotate and monitor keys through the signing provider
DKIM selectors allow providers to introduce new keys without immediately removing the old one. Follow the provider's supported key-rotation procedure and remove retired DNS records only when they are no longer needed. Recheck delivered headers after migrations, provider changes, or DNS changes so Joomla mail continues to carry a valid aligned signature.
Need More Help with Joomla?
Still having trouble? Open a support ticket with QuantaCade Support and we'll be happy to help where we can.
Support priority is given to QuantaCade products, services, and customers. However, we're also happy to assist fellow Joomla users with general Joomla questions and troubleshooting when possible.
QuantaCade is an independent Joomla extension developer and is not official Joomla support. Some issues involving third-party extensions, hosting environments, server configurations, or other systems outside our development control may be beyond what we're able to resolve.