Custom Email Domain missing DKIM records

I have set up a couple of domains for icloud's custom email for domain following instructions as found https://support.apple.com/en-gb/HT212524. This includes setting up a CNAME record for the domain to point at the canonical DKIM record controlled by Apple. eg. a custom domain of 'foobar.uk.' should have a CNAME record 'sig1._domainkey.foobar.uk.' pointing to 'sig1.dkim.foobar.uk.at.icloudmailadmin.com.'


From the support document for a domain 'example.com':

CNAME: 

host: sig1._domainkey

points to: sig1.dkim.[example.com].at.icloudmailadmin.com.

TTL: 3600


Unfortunately I cannot retrieve any records from the target (canonical) address: eg.


dig sig1.dkim.[example.com].at.icloudmailadmin.com. TXT

dig sig1.dkim.foobar.uk.at.icloudmailadmin.com. TXT


Clearly 'foobar.uk' is not my real domain, but I have 2 domains set up with Apple and neither has a valid DKIM record.


Anyone else?

Posted on Oct 6, 2021 2:32 AM

Reply
Question marked as Top-ranking reply

Posted on Mar 4, 2022 7:52 AM

I just sent a test email from Mac Mail app using my custom domain to a Gmail account.

The summary at the top of the "show original" now has this entry:


SPF:PASS with IP 17.58.63.177
DKIM: 'PASS' with domain mydomain.tld 


Where are few weeks ago, only the SPF line was there.


Additionally, there's also the "DKIM-Signature" line further down.

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mydomain.tld; s=sig1; t={redacted}; bh={redacted}; h=From:Content-Type:Mime-

This wasn't there a few weeks ago either.


When you send from an iCloud address, though, you get this:

SPF:PASS with IP 17.58.63.184 
DKIM:'PASS' with domain icloud.com
DMARC:'PASS'


So things are looking better for sure.

Similar questions

112 replies

Feb 24, 2022 1:10 PM in response to l.fromgeneva

Hahaha! That’s good entertainment - thanks for spending the time. I run a software development business, have done for 25 years. Defects are triaged and and assigned a priority that determines how quickly they’re fixed - there are many factors that determine priority. Duplicate issues are the bane of develop teams because they occupy more development resource than consolidated issues.


Give them the link to this thread. It contains not only the link to the case that’s been raised, but most of the interested parties and details of all follow up comment.


As for IT advice, I’m good for now, thanks.

Mar 4, 2022 1:13 AM in response to Seezar

I've been keeping an eye on my CNAME record for DKIM and today there is a DKIM key at sig1.dkim.[domain].uk.at.icloudmailadmin.com! However, when sending from icloud.com, the message is not signed at all (previously it was signed by icloud.com). But this is definitely progress and it would seem that Apple are going to have this sorted pretty soon.

Mar 4, 2022 7:26 AM in response to Jee Are

Hi guys - I'm holding off transferring my domain to iCloud until the DKIM issue has been resolved in entirety. Looking at the posts today it seems like there has been progress in terms of the DKIM record being created but messages aren't being signed correctly yet - is that a fair representation of where we're at?


As I say I don't have first hand experience of switching to iCloud yet and as such nothing to check on my side.

Mar 7, 2022 10:58 AM in response to Nick_WGD

Hi guys - an observation to share.


I've been considering moving my Apple ID email domain to Apple to have things more consolidated, but there's a shortcoming. There used to be the option to specify a 'Notification Email Address' that's used notify you when there's a login from an unknown browser / device. Apple have done away with this and those notification emails can only be sent to your Apple ID email address. This means that if you moved your Apple ID email account to iCloud and your Apple ID got hacked then the notification of the suspicious login would be sent to your iCloud account and the hacker could potentially delete the email before you had a chance to see it.


FYI.

Mar 8, 2022 8:29 AM in response to l.fromgeneva

Well, glad it got fixed for your custom domain.


In contrary to what some here report, my emails from my custom domain are not DKIM signed, ever. I've verified the DNS records. Used online check tools to retrieve the settings on my custom domain, they're all OK. But no matter if I send an email from macOS Mail, iOS Mail or iCloud.com's webmail interface, none of these emails gets a DKIM header.


For what its worth, I just reached out to Apple Support on Twitter to get their attention. No DKIM signage is a deal breaker for me. I've set up DKIM, SPF and DMARC a long time ago and never had issues with my email not getting delivered, or getting backscatter as a result some spammer abusing my domain to spam others.

Mar 8, 2022 10:09 AM in response to D43m0ns

I ran a test using https://www.learndmarc.com/ and it passed DKIM, SPF and DMARC checks but with this proviso:


"It looks like your domain currently does not have a DMARC policy. We will continue with the validations and show you what the DMARC result would be if you would enable DMARC with p=reject (simulated)."


Can we sort this out or do we need Apple's involvement?


I've also noticed that the number of mails in folders on Mac Mail don't match the folders as seen in iCloud.com Mail. I exported the mail from my old email host to .mbox files, re-imported them as Apple mail and copied them to iCloud. There are 6 folders in total. 4 tally, but for the other 2 there are 2 or 3 more mails in iCloud.com than on the Mac client. BTW, the mail totals on the Mac client are correct, but iCloud is getting a handful of additional mails from somewhere. No amount of sync attempts make a difference. It doesn't inspire confidence.

Mar 24, 2022 11:40 AM in response to th-m

Interestingly I tested my .com, which is hosted at Name.com with MX records pointing to Google (I'm a Google Suites Legacy user), and sending from my main admin account pretty much failed. Both sending from mail.google.com and the Gmail app on my iPhone:


However using my iCloud.com account worked fine both in Mail app and at iCloud.com/mail:


So I'm not so sure GSuite is really any better.

Apr 8, 2022 10:07 AM in response to Nick_WGD

I just retested mine. I sent from my .xyz domain and it fully passes spf/dkim/dmarc from the Mail app on my Mac and from my iPhone.


However, when I use https://www.icloud.com/mail/ the DKIM signature is not included, but the DMARC still passes because the SPF passed.


I do not have Private Relay enabled, but I do have Hide My Email enabled (though not using it for this test - I chose my XXXX@mydomain.xyz as the "send from" on each test).

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Custom Email Domain missing DKIM records

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.