Back to all articles
Technical Guide

How to Configure DKIM for Zendesk Email

NT
The Network Tools TeamSecurity Research
Published
Read Time1 min

Configuring DKIM (DomainKeys Identified Mail) for your Zendesk email ensures that messages sent from support agents land in inboxes, not spam folders. Below is a step‑by‑step guide, peppered with real‑world examples and best‑practice tips, so you can get your Zendesk tickets authenticated in minutes.


Why DKIM Matters for Zendesk

  • Trust signal – DKIM adds a cryptographic signature to each outbound email, proving it really came from your domain.
  • Spam reduction – ISPs like Gmail and Outlook treat DKIM‑signed mail as more reputable, lowering the chance of tickets being filtered.
  • Brand consistency – Recipients see a consistent “from” address (e.g., [email protected]) rather than a generic Zendesk domain.

Think of DKIM as a wax seal on a letter: the recipient can verify the seal hasn’t been tampered with, confirming the sender’s identity.


Prerequisites

Item Reason
Access to your DNS provider You’ll need to add a TXT record.
Zendesk admin rights Only admins can edit email settings.
A custom support domain (e.g., [email protected]) DKIM works per domain, not per sub‑address.
Optional: A DNS diagnostic tool (e.g., The Network Tools) Quickly verify the TXT record propagation.

Step‑by‑Step Configuration

1. Locate Zendesk’s DKIM Public Key

  1. Log in to Zendesk Admin Center → Channels → Email → Outbound email.
  2. Click Add DKIM (or Generate DKIM if you haven’t created one yet).
  3. Zendesk will display a selector (e.g., zendesk) and a long string of characters – this is your public key.

Real‑world tip: If you manage multiple brands, use a distinct selector per brand (e.g., brandA, brandB). This keeps keys isolated and simplifies troubleshooting.

2. Create the DNS TXT Record

  1. Open your DNS management console (GoDaddy, Cloudflare, Route 53, etc.).
  2. Add a new TXT record with the following values:
Field Value
Host/Name zendesk._domainkey (replace zendesk with the selector you received)
TTL 3600 seconds (or default)
Value v=DKIM1; k=rsa; p=YOUR_PUBLIC_KEY (paste the key exactly as Zendesk gave it)

Analogy: Think of the TXT record as a public billboard that says, “This is the official signature for our emails.” The selector (zendesk) tells receiving servers which billboard to look at.

3. Verify DNS Propagation

Propagation can take anywhere from a few seconds to 48 hours, depending on your TTL settings. Use a DNS lookup tool to confirm the record exists:

dig TXT zendesk._domainkey.yourdomain.com +short

Or, for a more visual check, head to The Network Tools → DNS Lookup and enter the full selector record. The tool will instantly show whether the TXT value is visible worldwide.

4. Activate DKIM in Zendesk

  1. Return to Zendesk Admin Center → Email → Outbound email.
  2. Click Verify DKIM. Zendesk will query the DNS record you just added.
  3. If the verification succeeds, toggle the DKIM status to Enabled.

Pro tip: If verification fails, double‑check for stray spaces or line breaks in the TXT value. DNS is unforgiving—one extra character can break the signature.

5. Test Sending a Ticket

Send a test ticket from Zendesk to an external email (e.g., a personal Gmail account). Open the email headers (Gmail: “Show original”) and look for:

DKIM-Signature: ... d=yourdomain.com; s=zendesk; ...

If the signature line appears and the header shows “PASS” under Authentication‑Results, you’re good to go.


Common Pitfalls & How to Fix Them

Symptom Likely Cause Fix
DKIM verification times out DNS record not yet propagated Wait up to 24 hrs or lower TTL, then re‑verify.
“Invalid public key” error Extra whitespace or missing p= prefix Re‑paste the key exactly as Zendesk provides, no line breaks.
Multiple DKIM records for the same selector Previous migration left an old TXT record Delete the stale record; keep only the latest.
Emails still landing in spam DKIM alone isn’t enough Implement SPF and DMARC alongside DKIM for full authentication.

Best Practices for Ongoing DKIM Management

  • Rotate keys annually – Generate a new DKIM key in Zendesk and replace the TXT record. This limits exposure if a private key is ever compromised.
  • Use a dedicated selector per environment – e.g., prod_zendesk, staging_zendesk. It makes debugging easier and prevents cross‑environment contamination.
  • Monitor with DMARC reports – Set up a DMARC record (_dmarc.yourdomain.com) and aggregate reports to a mailbox. You’ll see real‑time DKIM pass/fail stats.
  • Document changes – Keep a simple spreadsheet: selector, key creation date, expiration, DNS host. Future admins will thank you.

Quick FAQ

Q: Do I need a separate DKIM record for each Zendesk sub‑domain?
A: No. One DKIM selector per domain is sufficient, even if you use multiple Zendesk sub‑domains (e.g., support.yourdomain.com, help.yourdomain.com). Just ensure the d= tag in the signature matches your root domain.

Q: Can I use a third‑party DKIM provider instead of Zendesk’s key?
A: Yes, but you must upload the private key to Zendesk (via the API) and manage the public key in DNS yourself. This is more complex and typically unnecessary for most support teams.

Q: What if my DNS provider doesn’t support long TXT records?
A: Split the key into multiple quoted strings. Most modern providers handle this automatically, but you can manually break the key into 255‑character chunks.


Wrap‑Up

Configuring DKIM for Zendesk email is a straightforward process that pays dividends in deliverability, brand trust, and compliance. By following the steps above—and using tools like The Network Tools to validate your DNS records—you’ll have a robust email authentication setup in under an hour.

Ready to tighten your support email security? Dive into your DNS console, paste that public key, and let Zendesk do the heavy lifting. Your customers (and inboxes) will thank you.

You might also need

Keep troubleshooting with these related free tools.