---
title: CNAME DKIM Signing Feature
description: The easiest way to brand your email messages with your own DKIM signature is with the “Use a CNAME record” signing option.
---

[Skip to content](https://help.socketlabs.com/docs/custom-dkim-signing-feature#main-content)

English

Show submenu for translations

[Contact us](https://help.socketlabs.com/docs/kb-tickets/new?hsLang=en)

[![SocketLabs logo](https://help.socketlabs.com/hs-fs/hubfs/Logos/SocketLabs%20logo.png?width=243&height=70&name=SocketLabs%20logo.png)](https://www.socketlabs.com/)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- [Contact us](https://help.socketlabs.com/docs/kb-tickets/new)

 SocketLabs is here to help!

- There are no suggestions because the search field is empty.

1. [Help Center](https://help.socketlabs.com/docs?hsLang=en)
2. [DNS Authentication](https://help.socketlabs.com/docs/dns-authentication?hsLang=en)
3. [DKIM](https://help.socketlabs.com/docs/dns-authentication?hsLang=en#dkim)

# CNAME DKIM Signing Feature

## The easiest way to brand your email messages with your own DKIM signature is with the “Use a CNAME record” signing option.

#### What are the benefits of using the "Use a CNAME record" DKIM Signing Feature?

The benefits of using this method of DKIM signing is that it allows SocketLabs to remain in control of both the private and public DKIM keys. This allows you to get the benefit of custom DKIM signatures without the hassle of managing and rotating custom DKIM keys yourself.

For email experts looking for more refined control on the DKIM signatures of their messages, please see our [Advanced DKIM Signing Feature](https://help.socketlabs.com/docs/advanced-dkim-signing-feature?hsLang=en)

#### What does "Use a CNAME record" DKIM Signing require?

The “Use a CNAME record” option requires only the establishment of a single CNAME record in the DNS of your domain. The SocketLabs On-Demand Control Panel will perform a verification of your CNAME record before allowing for this feature to be enabled.

#### What is needed in my DNS settings?

Creating a CNAME record is a process that is handled by the provider that manages your domain’s DNS settings. This could be your website hosting provider, your domain registrar, or a third party service like Amazon’s Route 53.

SocketLabs does not provide technical support for managing your DNS settings. You will need to contact your DNS provider for assistance with establishing a CNAME record.

#### The CNAME entry that should be created is as follows:

```
dkim._domainkey.yourdomain.com CNAME IN dkim._domainkey.email-od.com
```

So if your domain were example.com, you would create the following record:

```
dkim._domainkey.example.com CNAME IN dkim._domainkey.email-od.com
```

Depending on the TTL settings of your DNS records, it could take 24 to 48 hours before SocketLabs will be able to verify your CNAME entries. If we are unable to verify your DNS entry, it is likely that mailbox providers will also be unable to verify your entry. 

#### What if my DNS provider does not support the underscore "\_" character?

Some providers do not support the underscore character “\_” in CNAME entries. If your DNS provider does not support this, you will be required to use the [Advanced DKIM signing feature](https://help.socketlabs.com/docs/advanced-dkim-signing-feature?hsLang=en).

Custom DKIM signatures will only be applied to messages that have a Purported Responsible Address (PRA) at the domain in which a custom signing option has been established. In most cases the PRA is the From Address, or the Sender Address.

#### Related Information

For more information about DKIM authentication technology, please see: [DomainKeys Identified Mail (DKIM) Authentication](https://help.socketlabs.com/docs/dkim-authentication?hsLang=en)

For more information about SPF authentication, please see our related article: [Sender Policy Framework (SPF)](https://help.socketlabs.com/docs/sender-policy-framework?hsLang=en)

 

- [Fundamentals](https://help.socketlabs.com/docs/fundamentals?hsLang=en#main-content)

    - [StreamScore](https://help.socketlabs.com/docs/fundamentals?hsLang=en#streamscore)
    - [Reports](https://help.socketlabs.com/docs/fundamentals?hsLang=en#reports)
    - [Frequently Asked Questions](https://help.socketlabs.com/docs/fundamentals?hsLang=en#frequently-asked-questions)
- [Advanced](https://help.socketlabs.com/docs/advanced?hsLang=en#main-content)

    - [Security](https://help.socketlabs.com/docs/advanced?hsLang=en#security)
- [DNS Authentication](https://help.socketlabs.com/docs/dns-authentication?hsLang=en#main-content)

    - [DKIM](https://help.socketlabs.com/docs/dns-authentication?hsLang=en#dkim)
    - [SPF and Custom Bounce Domain](https://help.socketlabs.com/docs/dns-authentication?hsLang=en#spf-and-custom-bounce-domain)
- [Deliverability](https://help.socketlabs.com/docs/deliverability?hsLang=en)
- [For Developers](https://help.socketlabs.com/docs/for-developers?hsLang=en#main-content)

    - [Event Webhooks](https://help.socketlabs.com/docs/for-developers?hsLang=en#event-webhooks)
- [Integrations](https://help.socketlabs.com/docs/integrations?hsLang=en#main-content)

    - [Languages and Frameworks](https://help.socketlabs.com/docs/integrations?hsLang=en#languages-and-frameworks)
    - [Mail Servers](https://help.socketlabs.com/docs/integrations?hsLang=en#mail-servers)
    - [Web Clients and Plug-ins](https://help.socketlabs.com/docs/integrations?hsLang=en#web-clients-and-plug-ins)
    - [Mail Clients](https://help.socketlabs.com/docs/integrations?hsLang=en#mail-clients)
- [Marketing Tools](https://help.socketlabs.com/docs/marketing-tools?hsLang=en#main-content)

    - [Tips and Tricks](https://help.socketlabs.com/docs/marketing-tools?hsLang=en#tips-and-tricks)
- [Troubleshooting](https://help.socketlabs.com/docs/troubleshooting?hsLang=en#main-content)

    - [SocketLabs Inbound SMTP Gateway Errors](https://help.socketlabs.com/docs/troubleshooting?hsLang=en#socketlabs-inbound-smtp-gateway-errors)
    - [SocketLabs Outbound SMTP Errors](https://help.socketlabs.com/docs/troubleshooting?hsLang=en#socketlabs-outbound-smtp-errors)
- [Spotlight Email Analytics](https://help.socketlabs.com/docs/spotlight-email-analytics?hsLang=en)
- [Hurricane MTA](https://help.socketlabs.com/docs/hurricane-mta?hsLang=en#main-content)

    - [Advanced Hurricane Usage](https://help.socketlabs.com/docs/hurricane-mta?hsLang=en#advanced-hurricane-usage)
    - [Upgrading Hurricane](https://help.socketlabs.com/docs/hurricane-mta?hsLang=en#upgrading-hurricane)
    - [Troubleshooting](https://help.socketlabs.com/docs/hurricane-mta?hsLang=en#troubleshooting)
    - [Hurricane Maintenance](https://help.socketlabs.com/docs/hurricane-mta?hsLang=en#hurricane-maintenance)
    - [Getting Started with Hurricane](https://help.socketlabs.com/docs/hurricane-mta?hsLang=en#getting-started-with-hurricane)
    - [Basic Hurricane Usage](https://help.socketlabs.com/docs/hurricane-mta?hsLang=en#basic-hurricane-usage)
- [Complex Sender](https://help.socketlabs.com/docs/complex-sender?hsLang=en)

[![Chill listening crop-3](https://help.socketlabs.com/hs-fs/hubfs/Logos/Logo_Favicon%20-%20large%20-%20cropped.png?width=24&height=24&name=Logo_Favicon%20-%20large%20-%20cropped.png "Chill listening crop-3")](https://www.socketlabs.com)

<https://www.facebook.com/socketlabs/> <https://twitter.com/socketlabs> <https://www.linkedin.com/company/socketlabs-inc./>

Copyright © 2026, SocketLabs LLC