You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Custom Email Domain missing DKIM records

I have set up a couple of domains for icloud's custom email for domain following instructions as found https://support.apple.com/en-gb/HT212524. This includes setting up a CNAME record for the domain to point at the canonical DKIM record controlled by Apple. eg. a custom domain of 'foobar.uk.' should have a CNAME record 'sig1._domainkey.foobar.uk.' pointing to 'sig1.dkim.foobar.uk.at.icloudmailadmin.com.'


From the support document for a domain 'example.com':

CNAME: 

host: sig1._domainkey

points to: sig1.dkim.[example.com].at.icloudmailadmin.com.

TTL: 3600


Unfortunately I cannot retrieve any records from the target (canonical) address: eg.


dig sig1.dkim.[example.com].at.icloudmailadmin.com. TXT

dig sig1.dkim.foobar.uk.at.icloudmailadmin.com. TXT


Clearly 'foobar.uk' is not my real domain, but I have 2 domains set up with Apple and neither has a valid DKIM record.


Anyone else?

Posted on Oct 6, 2021 2:32 AM

Reply
Question marked as Top-ranking reply

Posted on Nov 11, 2021 4:20 AM

Hi there. I have a support ticket open for the missing DKIM records with Apple since end of October. Not so much progress on the ticket and it was not easy to get the DKIM subject explained to support. Anyway I have had several contacts now and shared a lot of information and evidence with support and currently it sits with engineering.

Similar questions

112 replies

Mar 8, 2022 8:29 AM in response to l.fromgeneva

Well, glad it got fixed for your custom domain.


In contrary to what some here report, my emails from my custom domain are not DKIM signed, ever. I've verified the DNS records. Used online check tools to retrieve the settings on my custom domain, they're all OK. But no matter if I send an email from macOS Mail, iOS Mail or iCloud.com's webmail interface, none of these emails gets a DKIM header.


For what its worth, I just reached out to Apple Support on Twitter to get their attention. No DKIM signage is a deal breaker for me. I've set up DKIM, SPF and DMARC a long time ago and never had issues with my email not getting delivered, or getting backscatter as a result some spammer abusing my domain to spam others.

Mar 8, 2022 10:09 AM in response to D43m0ns

I ran a test using https://www.learndmarc.com/ and it passed DKIM, SPF and DMARC checks but with this proviso:


"It looks like your domain currently does not have a DMARC policy. We will continue with the validations and show you what the DMARC result would be if you would enable DMARC with p=reject (simulated)."


Can we sort this out or do we need Apple's involvement?


I've also noticed that the number of mails in folders on Mac Mail don't match the folders as seen in iCloud.com Mail. I exported the mail from my old email host to .mbox files, re-imported them as Apple mail and copied them to iCloud. There are 6 folders in total. 4 tally, but for the other 2 there are 2 or 3 more mails in iCloud.com than on the Mac client. BTW, the mail totals on the Mac client are correct, but iCloud is getting a handful of additional mails from somewhere. No amount of sync attempts make a difference. It doesn't inspire confidence.

Mar 24, 2022 10:17 AM in response to th-m

Try learndmarc.com and see if it gives you any other explanation.

When I was setting mine up, it did take some time for the settings to propagate through the internet. And I know for sure the rua/ruf settings messed stuff up. One tool explained that the domain the rua/ruf email address is on would have to be "set up" to allow rua/ruf reports. I may be explaining that poorly, but that was the gist.


It sure seems like "the internet" can't see your CNAME record. If you recently added it, give it a few hours. If you didn't, maybe try deleting it and re-adding?

Mar 24, 2022 11:03 AM in response to th-m

Seems so. Which seems.... odd. My .xyz domain consistently works for me on my Mac (Mac mini M1, Monterey 12.3). I actually want to move a .com to iCloud (it's currently on Google Legacy) so when Google finally lets us all know what they're doing for us Legacy users, I may be able to test a .com and see if it works better/consistently in all situations.

Apr 7, 2022 12:56 AM in response to sverzijl

Been a while, but checking again now with https://www.learndmarc.com/ results in a PASS on DKIM now. (I made no changes in DKIM record myself, so guess Apple finally resolved it now)



SPF auth result is pass and SPF domain is in alignment. DMARC SPF result is pass.

DKIM auth result is pass and DKIM domain is in alignment. DMARC DKIM result is pass.


Because both the SPF and DKIM test passed and their domains are in alignment, the DMARC result is pass.

Apr 8, 2022 8:53 AM in response to th-m

I can confirm that I'm using a *.com domain and I'm getting DMARC passes based on both SPF and DKIM passes, as validated using https://www.learndmarc.com. I moved my domain email to iCloud about 3 weeks ago, followed their instructions - nothing 'off piste', and it worked first time. I host my domain with Google domains. I get the daily DMARC reports and they confirm both the DKIM and SPF passes.


Is it worth deleting your domain email hosting from iCloud and starting afresh? I ask because I didn't try to move my domain to iCloud until folk started reporting in this thread that they were finally having success and I've had no problems at all.

Custom Email Domain missing DKIM records

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.