Setting up DKIM when DNS is hosted on an external server
DKIM
Digital signatures are becoming increasingly important in the world of email, especially with growing concerns about email authenticity and security. DKIM, which stands for DomainKeys Identified Mail, is one of the technologies used to address these issues. But what happens if you want to send mail via Server A while your DNS is on Server B? Let's look at how DKIM works in this situation and how to implement it for more secure email traffic.
What is DKIM?
DKIM is a method for verifying the authenticity of email messages. It works by adding a digital signature to every outgoing message. This signature is generated using a private key stored on the sender's server. The public key, which is needed to verify the signature, is published in the DNS records of the sender's domain.
How DKIM works when DNS is not hosted on the same server the mail is sent from
In a typical configuration, the mail servers and the DNS servers are in the same place. This makes DKIM easy to implement, as both servers have access to the same keys and configuration files.
But what if the mail servers and the DNS servers are in different places, for example when you want to send mail via Server A while your DNS is on Server B? In this situation, a few extra steps are needed to make DKIM work correctly.
Implementing DKIM on the external DNS server
To make DKIM work with separate servers, follow these steps:
1. *Generate the DKIM keys on Server A:* The private key for DKIM must be generated on Server A, where the emails are sent from.
2. *Publish the DKIM record in DNS on Server B:* Once the DKIM keys have been generated, the corresponding public key must be published in the domain's DNS records on Server B.
3. *Configure the mail server on Server A:* The mail server on Server A must be configured to add DKIM signatures to outgoing emails using the private key generated there.
With this configuration, emails can be sent via Server A while the DKIM signature is validated using the DNS records on Server B.
