You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Custom Email Domain missing DKIM records

I have set up a couple of domains for icloud's custom email for domain following instructions as found https://support.apple.com/en-gb/HT212524. This includes setting up a CNAME record for the domain to point at the canonical DKIM record controlled by Apple. eg. a custom domain of 'foobar.uk.' should have a CNAME record 'sig1._domainkey.foobar.uk.' pointing to 'sig1.dkim.foobar.uk.at.icloudmailadmin.com.'


From the support document for a domain 'example.com':

CNAME: 

host: sig1._domainkey

points to: sig1.dkim.[example.com].at.icloudmailadmin.com.

TTL: 3600


Unfortunately I cannot retrieve any records from the target (canonical) address: eg.


dig sig1.dkim.[example.com].at.icloudmailadmin.com. TXT

dig sig1.dkim.foobar.uk.at.icloudmailadmin.com. TXT


Clearly 'foobar.uk' is not my real domain, but I have 2 domains set up with Apple and neither has a valid DKIM record.


Anyone else?

Posted on Oct 6, 2021 2:32 AM

Reply
Question marked as Top-ranking reply

Posted on Nov 11, 2021 4:20 AM

Hi there. I have a support ticket open for the missing DKIM records with Apple since end of October. Not so much progress on the ticket and it was not easy to get the DKIM subject explained to support. Anyway I have had several contacts now and shared a lot of information and evidence with support and currently it sits with engineering.

Similar questions

112 replies
Question marked as Top-ranking reply

Nov 11, 2021 4:20 AM in response to KevinD-B

Hi there. I have a support ticket open for the missing DKIM records with Apple since end of October. Not so much progress on the ticket and it was not easy to get the DKIM subject explained to support. Anyway I have had several contacts now and shared a lot of information and evidence with support and currently it sits with engineering.

Feb 24, 2022 11:36 AM in response to l.fromgeneva

A little more help if you report...

Like I said, they're gonna make you answer a bunch of irrelevant questions.

Start off by stating something simple like:


Hi! I just wanted it documented that I too am one of many experiencing the problem where my Custom Domain isn't sending a DKIM signature when sending via Mail app (either on Mac or iOS). The DKIM signature *is* there, however, when utilizing iCloud Mail on iCloud.com.
There are at least 2 Case IDs reporting the same issue: 101638785504 and 101560160207
Here is the Apple forum with a bunch of others with the same issue:
Custom Email Domain missing DKIM records - Apple Community

They won't simply let you give a Case ID and ask for an update. They just don't work that way. You have to log it as "I'm having this problem too" officially (not just here on this thread).


I then ended up sending them screenshots of the source on an email sent from Mail app and iCloud.com so they could see the difference. I also sent a screenshot of my registrar's DNS records properly set. That really should have been enough, but she continued to ask multiple other questions like VPN, ISP, Wifi or Ethernet, email addresses of the custom domains (even though it happens on the entire custom domain), serial number, software version, etc, etc.

Once we got to questions like ISP, I kind of stopped it because it was taking a really long time. Supposedly she logged it, we'll see....

Mar 8, 2022 3:33 PM in response to Sebby*

Hi Sebby - I found this:


Postmaster information for iCloud Mail – Apple Support (UK)


Of specific interest here: "All iCloud Mail domains also have a DMARC ("p=quarantine") policy*, which indicates to a mail provider that an email from an iCloud email address that fails SPF and DKIM email authentication should go to the recipient's Junk folder. *The policy took effect on 2 July 2018."


This was published in July 2020 which would suggest that it hasn't been implemented for custom domains yet, but would be in future, perhaps.


If the users are supposed to setup the DMARC policy then why do Apple make no mention of it in the custom domain setup instructions?


In terms of setting it up I found this page:


https://dmarcadvisor.com/dmarc-record-wizard/?gclid=Cj0KCQiAmpyRBhC-ARIsABs2EAobZk7kVbb5PMBcNlStTuyPOVm72N5y6BoKegWjVO7P-He-0oRruGgaAnEKEALw_wcB


And inputting some sensible settings I'm looking at:


DNS:

Hostname: _dmarc

Resource Type: TXT

Value: v=DMARC1; p=quarantine; rua=mailto:me@example.com; ruf=mailto:me@example.com; fo=1;


Does that look about right?


If Apple subsequently implement their DMARC policy for custom domains will that take precedence over my DNS settings, do you think?

Mar 24, 2022 10:55 AM in response to l.fromgeneva

Ok this is interesting... I just tested from https://www.icloud.com/mail/

It did not work properly...


Also tried using learndmarc:


So what this tells me, since it all works fine from iPhone mail and Mac mail apps, my DNS records are set up properly.

iCloud.com/mail is not adding the DKIM signature headers. Which seems odd since I'm pretty sure they were being added on Mar 8 as I tested all 3 situations then (Mac Mail, iPhone mail, iCloud.com/Mail).

Jan 3, 2022 3:35 PM in response to KevinD-B

Looks like I'm a little late to the party. Just verified that there still remain 2 problems when setting up iCloud+ custom domains:

  • DKIM signature header is still missing when sending from the iOS Mail App.
  • The DKIM Signing Domain and the From Domain are not aligned when sending from a browser.


Has anyone with tickets seen updates to these? I'm going to create my own ticket tomorrow and will update if I get any new information.


C'mon Apple.... Be better than this.

Mar 24, 2022 11:40 AM in response to th-m

Interestingly I tested my .com, which is hosted at Name.com with MX records pointing to Google (I'm a Google Suites Legacy user), and sending from my main admin account pretty much failed. Both sending from mail.google.com and the Gmail app on my iPhone:


However using my iCloud.com account worked fine both in Mail app and at iCloud.com/mail:


So I'm not so sure GSuite is really any better.

Apr 8, 2022 10:07 AM in response to Nick_WGD

I just retested mine. I sent from my .xyz domain and it fully passes spf/dkim/dmarc from the Mail app on my Mac and from my iPhone.


However, when I use https://www.icloud.com/mail/ the DKIM signature is not included, but the DMARC still passes because the SPF passed.


I do not have Private Relay enabled, but I do have Hide My Email enabled (though not using it for this test - I chose my XXXX@mydomain.xyz as the "send from" on each test).

Dec 10, 2021 8:31 AM in response to Jee Are

Ok thanks for the update. If/when they finally fix it I’d be thrilled if you updated us all here.


I think I am going to trust apple to get it corrected and go with icloud for the hosting (for now). Once the DKIM records issue is corrected would you feel good about using icloud to host a very small business email? I understand the limitations with users/family sharing but I am most concerned about messages being delivered properly and spam filtering…


Anyone else care to chime in?

Custom Email Domain missing DKIM records

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.