← All installation guides Email authentication and DNS

Set up Plesk Email & DKIM for an Email Sender Seal

Enable DKIM signing in Plesk, publish the records in local or external DNS and identify the selector.

PL✉
Recommended methodEmail DNS and seal setup
Email authentication setup

Configure email DNS and find the selector

  1. 1

    Enable domain signing

    Open Websites & Domains, select the domain, open Mail and Mail Settings, then enable Use DKIM spam protection system to sign outgoing email messages and apply the change.

  2. 2

    Publish the DKIM records

    If Plesk hosts DNS, it adds the records to the zone. For external DNS, use the Plesk external-DNS instructions and copy every supplied record to the authoritative provider.

  3. 3

    Find the selector

    Plesk commonly publishes a record such as default._domainkey. The selector is default in that example. Use the exact label Plesk displays and confirm it from the s= header of a test message.

  4. 4

    Confirm SPF and DMARC

    Check the sender domain has one valid SPF record and a DMARC record at _dmarc. Make changes only in the DNS service named by the domain nameservers.

  5. 5

    Validate and add the seal

    Enter the confirmed selector in VerifySeal, complete the DNS check, then add the issued linked image through the active Plesk webmail program or another email client.

Open Plesk DKIM signing documentation ↗
Email Sender Verification Seal

Complete authentication before installing the seal

The sender domain must continue to publish a valid SPF record, the selected DKIM key and a DMARC policy. VerifySeal automatically rechecks these records according to the administrator schedule. For High Security messages, DKIM must cover the final Message-ID, VEM header and completed body.

  • SPF authorizes sending services
  • DKIM verifies the signed message domain
  • DMARC publishes the domain policy
Testing checklist

Confirm the installation is working

01

SPF

The sender domain has one valid SPF record containing every authorized sending service.

02

DKIM

A new external message reports DKIM pass and its matching signature contains the selector entered in VerifySeal.

03

DMARC

A DMARC record is published at _dmarc and its policy matches the organization’s approved rollout.

04

VerifySeal

The customer order reports SPF, DKIM and DMARC as verified before the Email Sender Seal is issued.

Platform notes
  • The server administrator must first enable DKIM support before the per-domain option can be used.