XiaTools

How to Fix 'DKIM Check Failed' Warnings in Apple Mail

Updated 10 Oct 2026

When Apple Mail displays a "DKIM check failed" warning or marks your incoming emails with suspicious banners, it usually means the cryptographic signature in your email headers does not match the public key published in your domain's DNS. This discrepancy triggers security protocols in Apple’s Mail app, often routing your legitimate messages straight to the spam folder or displaying authentication failures to your recipients. Fortunately, you can systematically diagnose and resolve these alignment and signing issues by verifying your DNS records, email headers, and sending infrastructure configurations.

To quickly verify whether your cryptographic signature is currently valid across public DNS servers, you can use the XiaTools DKim Checker to instantly inspect your public keys and identify syntax errors before Apple Mail flags them.

Understanding DKIM in Apple Mail

DomainKeys Identified Mail (DKIM) adds a cryptographic signature to the header of every outgoing email. When Apple Mail receives a message, it extracts the signature, looks up the public key in your domain's DNS records using the specified Selector, and uses that key to verify the signature. If the cryptographic math fails, or if the DNS record is missing, malformed, or timed out, Apple Mail flags the message as unverified.

Unlike other email clients that silently drop failing emails, Apple Mail is notoriously strict about cryptographic validation and SPF/DKIM alignment. If your sending platform rotates keys without updating DNS, or if your DNS provider appends your root domain name twice to your selector (creating a double-domain error), Apple Mail will immediately throw an authentication warning.

Step-by-Step Troubleshooting Guide

Fixing a failed verification warning requires tracing the email from your outbound server to the recipient's inbox. Follow this structured process to locate and resolve the root cause.

Step 1: Inspect the Raw Email Headers

Before modifying DNS, find out exactly why Apple Mail rejected the signature. Open the message in Apple Mail, go to the top menu, select View, then Message, and click Raw Source (or use the shortcut Option + Command + U). Look for the Authentication-Results header to see how Apple's mail engine evaluated your message.

Authentication-Results: mail.example.com;
	dkim=fail reason="signature verification failed"
	header.d=example.com
	header.s=selector1
	header.b=AbCdEfGh

If the result shows fail, note the header.d (domain) and header.s (selector) values. You will need these exact strings for your DNS lookup.

Step 2: Verify Your DNS Public Key Record

Once you have your selector, verify that the TXT record exists in your DNS zone. Your DKIM record must always be hosted at [selector]._domainkey.[yourdomain.com]. For example, if your selector is s1 and your domain is example.com, the DNS record name must be s1._domainkey.example.com.

Use your terminal to query the DNS record using dig:

dig TXT s1._domainkey.example.com +short

A correct response looks like this:

"v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0..."

If the query returns no output or a SERVFAIL error, your DNS provider does not have the record published correctly.

Step 3: Check for Syntax and Formatting Errors

Formatting errors in DNS TXT records are the most common reason for verification failures. Check your public key against common formatting mistakes:

  • String Length Limits: Many DNS providers require long public keys to be split into multiple quoted strings (e.g., ("v=DKIM1; k=rsa; p=..." "...")). If your provider doesn't handle this automatically, it can break the key.
  • Incorrect Tag Names: Ensure tags use lowercase letters (v=, k=, p=).
  • Extra Whitespace or Line Breaks: Accidental spaces inside the base64-encoded p= string will invalidate the cryptographic hash.

Step 4: Validate Your Email Sending Platform Configuration

If your DNS record is correct, the issue usually lies with your email service provider (ESP) or mail transfer agent (MTA) signing the message incorrectly. Ensure that:

  • Your ESP is configured to use the exact selector you published in DNS.
  • Your outgoing server is not modifying the body or standard headers (like Subject or From) after the DKIM signature has been applied, as any post-signing modification breaks the hash.
  • Your private key matches the public key published in DNS. If your ESP recently rotated your keys, you must update your DNS records with the new public key immediately.

Comparison: Correct vs. Incorrect DKIM Configurations

Configuration Aspect Correct Setup Incorrect Setup (Causes Failures)
DNS Record Name selector1._domainkey.example.com selector1.example.com (missing _domainkey)
Record Type TXT CNAME pointing to an invalid external target
Base64 Key Data Clean, uninterrupted string or valid chunks Trailing spaces, missing characters, or corrupted padding
Selector Matching Matches header s= tag exactly Mismatched selector between ESP config and DNS

Common Mistakes and How to Fix Them

  • Double-Domain Append: Many DNS management panels automatically append your root domain to the record name. If you enter selector1._domainkey.example.com into a dashboard that auto-appends, your final DNS query becomes selector1._domainkey.example.com.example.com, resulting in a lookup failure. Fix this by using a trailing dot (e.g., selector1._domainkey.example.com.) or omitting the apex domain if your provider handles it.
  • Caching Delays: If you just updated your DNS records, Apple Mail might still be checking an old cached version. Wait out the TTL (Time To Live) period, or flush your local DNS resolver cache.
  • Using Weak Keys: Modern mail servers deprecate 512-bit and 1024-bit RSA keys. If your provider generates an insecure key size, upgrade to a minimum of 2048-bit RSA or Ed25519.

Quick Checklist for Apple Mail DKIM Health

  • Raw headers confirm the correct domain (header.d) and selector (header.s).
  • DNS TXT record query returns a valid v=DKIM1 string.
  • Public key length is at least 2048 bits.
  • No trailing whitespaces or line break artifacts exist inside the p= tag value.
  • ESP signing configuration matches the active DNS public key.

By systematically verifying your DNS records, reviewing your email headers, and ensuring your ESP aligns its signing keys with your published records, you can permanently eliminate verification warnings and ensure your emails render securely in Apple Mail.

Frequently asked questions

Why does Apple Mail say DKIM check failed when other email clients pass it?

Apple Mail enforces strict cryptographic and alignment checks compared to webmail clients like Gmail or Outlook. If your signature has minor body hash mismatches, or if your domain alignment is loose, Apple's mail engine will flag the message while webmail clients might silently accept it.

How long does it take for DNS changes to fix a DKIM failure?

DNS propagation typically takes anywhere from a few minutes to 24 hours, depending on your DNS provider's TTL (Time To Live) settings. Once the global nameservers update with your correct public key, Apple Mail will successfully validate incoming messages.

Can I use the same DKIM selector for multiple email providers?

No, you should never share the same selector across different email service providers. Each provider requires its own unique selector and cryptographic key pair to sign mail independently without overwriting or invalidating each other's records.

What is the difference between a DKIM failure and an SPF failure?

SPF verifies whether the sending server's IP address is authorized to send email on behalf of your domain name. DKIM uses a cryptographic digital signature embedded in the email headers to prove the message was genuinely sent by the domain owner and was not altered in transit.

How do I find my current DKIM selector if I lost it?

You can find your active selector by examining the raw headers of an outbound test email sent from your server. Look for the `header.s=` tag within the Authentication-Results or DKIM-Signature header lines, or check the outgoing server configuration panel in your email service provider account.

Related articles

Free tools