Updated: 28 September 2026 · Applies to: OpenDKIM 2.11 with Postfix 3.8 (Ubuntu 24.04) and 3.10 (Ubuntu 26.04)

DKIM adds a cryptographic signature to every message you send. Receivers check it with a public key that you publish in DNS. This guide installs OpenDKIM, creates a key for each of your sending domains and connects it to Postfix. The signature also covers the unsubscribe headers, which mailbox providers require for marketing mail (How to add a working unsubscribe link and one-click unsubscribe headers to your emails?).

Before you start

1. Install

sudo apt update
sudo apt install -y opendkim opendkim-tools

2. Create a key for each domain

Use a selector that includes the year, for example s2026, so that you can rotate keys later.

sudo mkdir -p /etc/opendkim/keys/example.com
sudo opendkim-genkey -b 2048 -d example.com -D /etc/opendkim/keys/example.com -s s2026
sudo chown -R opendkim:opendkim /etc/opendkim
sudo chmod 600 /etc/opendkim/keys/example.com/s2026.private
sudo cat /etc/opendkim/keys/example.com/s2026.txt

The last command shows the DNS record. Repeat the steps for every other sending domain (change the domain name in the folder and the -d option).

3. Publish the public key

Create a TXT record named s2026._domainkey.example.com. The value is the text inside the parentheses of the .txt file: it begins with v=DKIM1; h=sha256; k=rsa; p= followed by a long key. Join the parts into one value without the quotes. If your DNS panel limits the length, ask its support or use a 1024-bit key with -b 1024 (2048 is preferred).

4. Tell OpenDKIM which key to use

Edit /etc/opendkim.conf and set (keep other lines as they are):

Syslog                  yes
UMask                   007
Canonicalization        relaxed/simple
Mode                    s
Socket                  inet:8891@localhost
KeyTable                /etc/opendkim/key.table
SigningTable            refile:/etc/opendkim/signing.table
InternalHosts           /etc/opendkim/trusted.hosts
SignHeaders             From,Reply-To,Subject,Date,To,Cc,Resent-Date,Resent-From,Resent-To,Resent-Cc,In-Reply-To,References,MIME-Version,Message-ID,List-Id,List-Help,List-Unsubscribe,List-Unsubscribe-Post,List-Subscribe,List-Post,List-Owner,List-Archive
OversignHeaders         From

Mode s means signing only. The SignHeaders line makes sure List-Unsubscribe-Post is signed; the DKIM standard lists List-Unsubscribe as a header to sign, but the one-click header is not in the default list, and RFC 8058 asks for both to be covered.

Create the three files:

sudo tee /etc/opendkim/key.table >/dev/null <<'EOF'
s2026._domainkey.example.com example.com:s2026:/etc/opendkim/keys/example.com/s2026.private
EOF
sudo tee /etc/opendkim/signing.table >/dev/null <<'EOF'
*@example.com s2026._domainkey.example.com
EOF
sudo tee /etc/opendkim/trusted.hosts >/dev/null <<'EOF'
127.0.0.1
localhost
EOF

Add one line to key.table and one to signing.table for each further domain.

5. Check the key, then start

sudo opendkim-testkey -d example.com -s s2026 -vvv
sudo systemctl restart opendkim
sudo systemctl enable opendkim
sudo systemctl status opendkim

opendkim-testkey must say key OK. If it says the key was not found, the DNS record is not published yet.

6. Connect Postfix

sudo postconf -e "milter_default_action = tempfail"
sudo postconf -e "milter_protocol = 6"
sudo postconf -e "smtpd_milters = inet:localhost:8891"
sudo postconf -e "non_smtpd_milters = \$smtpd_milters"
sudo systemctl restart postfix

tempfail means that if OpenDKIM is down, Postfix keeps the mail queued and tries again later, instead of sending it unsigned.

7. Test

Send a message (How to install and configure Postfix for sending on Ubuntu?, step 4) to a Gmail address, open it, choose "Show original" and look for DKIM: 'PASS' with domain example.com. The message source must contain a DKIM-Signature header whose h= list includes the List-Unsubscribe headers when your messages carry them.

Common problems

  • No DKIM-Signature header: the From address domain is missing in signing.table, or the milter is not connected (sudo postconf smtpd_milters non_smtpd_milters).
  • DKIM fails at the receiver: the DNS record is wrong or cut off, or a program changes the message after signing.
  • Permission errors in the log: the key file must belong to opendkim and be readable only by it.

Rotate keys

Create a new key with a new selector (for example s2027), publish it, switch the tables to it, and remove the old DNS record after some weeks.

Frequently asked questions

Do I need a key for each IP address?
No. DKIM belongs to the domain, not to the IP address. All your addresses can sign with the same key.

Can I use rspamd instead?
Yes. rspamd can also sign mail; OpenDKIM is shown here because it is small and simple.

Source: Postfix Milter support and the OpenDKIM manual pages.

Need a dedicated server, more IP addresses, or a hand with the setup?

Prefer a hand with the setup? Our engineers can do it for you: Hire an Expert, or use our on-demand server management.

Was this answer helpful? 0 Users Found This Useful (0 Votes)