Custom Email Domain missing DKIM records

I have set up a couple of domains for icloud's custom email for domain following instructions as found https://support.apple.com/en-gb/HT212524. This includes setting up a CNAME record for the domain to point at the canonical DKIM record controlled by Apple. eg. a custom domain of 'foobar.uk.' should have a CNAME record 'sig1._domainkey.foobar.uk.' pointing to 'sig1.dkim.foobar.uk.at.icloudmailadmin.com.'


From the support document for a domain 'example.com':

CNAME: 

host: sig1._domainkey

points to: sig1.dkim.[example.com].at.icloudmailadmin.com.

TTL: 3600


Unfortunately I cannot retrieve any records from the target (canonical) address: eg.


dig sig1.dkim.[example.com].at.icloudmailadmin.com. TXT

dig sig1.dkim.foobar.uk.at.icloudmailadmin.com. TXT


Clearly 'foobar.uk' is not my real domain, but I have 2 domains set up with Apple and neither has a valid DKIM record.


Anyone else?

Posted on Oct 6, 2021 2:32 AM

Reply
Question marked as Top-ranking reply

Posted on Mar 4, 2022 7:52 AM

I just sent a test email from Mac Mail app using my custom domain to a Gmail account.

The summary at the top of the "show original" now has this entry:


SPF:PASS with IP 17.58.63.177
DKIM: 'PASS' with domain mydomain.tld 


Where are few weeks ago, only the SPF line was there.


Additionally, there's also the "DKIM-Signature" line further down.

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mydomain.tld; s=sig1; t={redacted}; bh={redacted}; h=From:Content-Type:Mime-

This wasn't there a few weeks ago either.


When you send from an iCloud address, though, you get this:

SPF:PASS with IP 17.58.63.184 
DKIM:'PASS' with domain icloud.com
DMARC:'PASS'


So things are looking better for sure.

Similar questions

112 replies

Nov 11, 2021 4:20 AM in response to KevinD-B

Hi there. I have a support ticket open for the missing DKIM records with Apple since end of October. Not so much progress on the ticket and it was not easy to get the DKIM subject explained to support. Anyway I have had several contacts now and shared a lot of information and evidence with support and currently it sits with engineering.

Feb 7, 2022 11:06 AM in response to Nick_WGD

To be honest, I disabled my test domain now. Apple just can’t do modern email. Even when fixing DKIM, there is just so much more as the simple IMAP protocol doesn’t really do it anymore. Then there is still this insufficient protection of my identity, 2-factor auth is awful. Then they can’t do calendars either as meeting invitations will not be sent automatically to non-Apple accounts (a real bummer, it is 2022, Apple…)


I now made a decision for my GSuite domains just last week and moved all of them to Microsoft 365 Family (Outlook.com) and Cloudflare Email (forwarding/inbound). (Note, Outlook.com does not require godaddy to be your domain registrar, google the Reddit article for this, really easy).


Outlook.com is a great alternative for families and personal emails. It is actually reasonably priced, just paid 110€ for 30 month. Totally acceptable and I already love to be able to combine the calendar with my M365 business account.

Feb 24, 2022 1:28 PM in response to Nick_WGD

As I said above, I absolutely did give them the other ticket numbers and the link to this thread when I began the support chat. They seriously don't care. (I've had this happen many times with Apple Support). But I did insist they include it, because I know the engineering team will care.

I too work in IT (both engineer & support since 1995) and can not understand why the heck they seem to encourage duplicate tickets.

The last issue I had, I ended up with a very high level support person at Apple (shout out to Brenda!). She's the one who told me to encourage people here to report the issue via official Apple Support. She said it gets higher priority with the engineering team when more people report it. Having been both an engineer and support, this is very much true, even if you really don't want it to be. If your customers are freaking out about something, you're likely to prioritize it pretty high if there's no viable work around. Of course, how many people are freaking out, is all relative, but you know what I mean.

(Anecdotal I know, but my last issue actually did get fixed pretty quickly once I spoke with Brenda, then followed up for a couple of weeks. I know others were reporting it too. My BFF Brenda (LOL) told me so. It was a "portrait photos in Shared Albums" issue.)


That being said, they may not mind duplicate "Case IDs" as they call them. But internally they likely put all those Case IDs into one "issue ticket".

Mar 24, 2022 10:55 AM in response to l.fromgeneva

Ok this is interesting... I just tested from https://www.icloud.com/mail/

It did not work properly...


Also tried using learndmarc:


So what this tells me, since it all works fine from iPhone mail and Mac mail apps, my DNS records are set up properly.

iCloud.com/mail is not adding the DKIM signature headers. Which seems odd since I'm pretty sure they were being added on Mar 8 as I tested all 3 situations then (Mac Mail, iPhone mail, iCloud.com/Mail).

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Custom Email Domain missing DKIM records

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.