How to rotate a DKIM key without breaking mail

How-to Email dkimrotationdnssigning

Use the three-step flow: prepare a new key, wait for DNS to propagate, confirm the switch, then retire the old record.

DKIM signing is automatic. Rotate the key when it may have leaked, or as routine. Doing it in three steps keeps mail already in flight verifiable.

Steps

  1. In the mail domain's DKIM section, choose Prepare. The panel creates a new key under a new selector and publishes its DNS record, but keeps signing with the old key.
  2. Wait for DNS to propagate. A TTL of an hour means waiting at least that long; check the new record resolves from outside.
  3. Choose Confirm. Signing switches to the new key. The old record stays published, because mail already queued was signed with it.
  4. After a few days, choose Retire to delete the old record and its private key.

If the zone is elsewhere

When this node does not serve the zone, the key is generated anyway and you get the public record to publish where your DNS lives.

Notes

  • DKIM signs authenticated submission (ports 587/465) with the domain of the envelope sender. Mail sent with PHP mail() is not DKIM-signed; use authenticated SMTP from your application when you need signed mail.

Last updated: 2026-10-10