Updated: 28 September 2026 · Applies to: OpenDKIM 2.11 with Postfix 3.8 (Ubuntu 24.04) and 3.10 (Ubuntu 26.04)
DKIM adds a cryptographic signature to every message you send. Receivers check it with a public key that you publish in DNS. This guide installs OpenDKIM, creates a key for each of your sending domains and connects it to Postfix. The signature also covers the unsubscribe headers, which mailbox providers require for marketing mail (How to add a working unsubscribe link and one-click unsubscribe headers to your emails?).
Before you start
- Postfix works (How to install and configure Postfix for sending on Ubuntu?).
- You can edit the DNS of the sending domain.
- Ubuntu 24.04 or 26.04: the packages
opendkimandopendkim-toolsare available on both.
1. Install
sudo apt update sudo apt install -y opendkim opendkim-tools
2. Create a key for each domain
Use a selector that includes the year, for example s2026, so that you can rotate keys later.
sudo mkdir -p /etc/opendkim/keys/example.com sudo opendkim-genkey -b 2048 -d example.com -D /etc/opendkim/keys/example.com -s s2026 sudo chown -R opendkim:opendkim /etc/opendkim sudo chmod 600 /etc/opendkim/keys/example.com/s2026.private sudo cat /etc/opendkim/keys/example.com/s2026.txt
The last command shows the DNS record. Repeat the steps for every other sending domain (change the domain name in the folder and the -d option).
3. Publish the public key
Create a TXT record named s2026._domainkey.example.com. The value is the text inside the parentheses of the .txt file: it begins with v=DKIM1; h=sha256; k=rsa; p= followed by a long key. Join the parts into one value without the quotes. If your DNS panel limits the length, ask its support or use a 1024-bit key with -b 1024 (2048 is preferred).
4. Tell OpenDKIM which key to use
Edit /etc/opendkim.conf and set (keep other lines as they are):
Syslog yes UMask 007 Canonicalization relaxed/simple Mode s Socket inet:8891@localhost KeyTable /etc/opendkim/key.table SigningTable refile:/etc/opendkim/signing.table InternalHosts /etc/opendkim/trusted.hosts SignHeaders From,Reply-To,Subject,Date,To,Cc,Resent-Date,Resent-From,Resent-To,Resent-Cc,In-Reply-To,References,MIME-Version,Message-ID,List-Id,List-Help,List-Unsubscribe,List-Unsubscribe-Post,List-Subscribe,List-Post,List-Owner,List-Archive OversignHeaders From
Mode s means signing only. The SignHeaders line makes sure List-Unsubscribe-Post is signed; the DKIM standard lists List-Unsubscribe as a header to sign, but the one-click header is not in the default list, and RFC 8058 asks for both to be covered.
Create the three files:
sudo tee /etc/opendkim/key.table >/dev/null <<'EOF' s2026._domainkey.example.com example.com:s2026:/etc/opendkim/keys/example.com/s2026.private EOF sudo tee /etc/opendkim/signing.table >/dev/null <<'EOF' *@example.com s2026._domainkey.example.com EOF sudo tee /etc/opendkim/trusted.hosts >/dev/null <<'EOF' 127.0.0.1 localhost EOF
Add one line to key.table and one to signing.table for each further domain.
5. Check the key, then start
sudo opendkim-testkey -d example.com -s s2026 -vvv sudo systemctl restart opendkim sudo systemctl enable opendkim sudo systemctl status opendkim
opendkim-testkey must say key OK. If it says the key was not found, the DNS record is not published yet.
6. Connect Postfix
sudo postconf -e "milter_default_action = tempfail" sudo postconf -e "milter_protocol = 6" sudo postconf -e "smtpd_milters = inet:localhost:8891" sudo postconf -e "non_smtpd_milters = \$smtpd_milters" sudo systemctl restart postfix
tempfail means that if OpenDKIM is down, Postfix keeps the mail queued and tries again later, instead of sending it unsigned.
7. Test
Send a message (How to install and configure Postfix for sending on Ubuntu?, step 4) to a Gmail address, open it, choose "Show original" and look for DKIM: 'PASS' with domain example.com. The message source must contain a DKIM-Signature header whose h= list includes the List-Unsubscribe headers when your messages carry them.
Common problems
- No DKIM-Signature header: the From address domain is missing in
signing.table, or the milter is not connected (sudo postconf smtpd_milters non_smtpd_milters). - DKIM fails at the receiver: the DNS record is wrong or cut off, or a program changes the message after signing.
- Permission errors in the log: the key file must belong to
opendkimand be readable only by it.
Rotate keys
Create a new key with a new selector (for example s2027), publish it, switch the tables to it, and remove the old DNS record after some weeks.
Frequently asked questions
Do I need a key for each IP address?
No. DKIM belongs to the domain, not to the IP address. All your addresses can sign with the same key.
Can I use rspamd instead?
Yes. rspamd can also sign mail; OpenDKIM is shown here because it is small and simple.
Source: Postfix Milter support and the OpenDKIM manual pages.
Need a dedicated server, more IP addresses, or a hand with the setup?
- Unmanaged dedicated servers: full root access and IPv4 subnets from /29 up to /24, ordered with the server or added later.
- Managed dedicated servers: our team looks after the operating system, updates, security and monitoring.
- Dedicated server locations: choose the country and data centre when you order.
Prefer a hand with the setup? Our engineers can do it for you: Hire an Expert, or use our on-demand server management.
