To setup DKIM for Mimecast you will need to sign in to your Mimecast account and generate a public key and private key. To do this you will have to create an Outbound Signing Definition and an outbound Policy to apply DKIM to your outbound emails. Below are the steps to setup DKIM.
ADD A DKIM KEY IN MIMECAST/msdyn_blobfile/$value)
/msdyn_blobfile/$value)
/msdyn_blobfile/$value)
/msdyn_blobfile/$value)
/msdyn_blobfile/$value)
/msdyn_blobfile/$value)
TEST AND CONFIRM DKIM SIGNING
To confirm that DKIM is working correctly:
ADD A DKIM KEY IN MIMECAST
- Login to your Mimecast account.
- Navigate to Administration dropdown menu, and on the menu, select Gateway > Policies.
- In the Polices page, click on Definitions, and from the dropdown menu select DNS Authentication - Outbound.
- Now you will create a new DKIM policy where you will need to fill in the description box, select the domain from the lookup list, and name your DKIM selector.
- In the DKIM length category, you can select either 1024 bits or 2048 bits if you want more secure encryption. Then click Generate.
- Mimecast will then display a DNS record. Enter this DNS records with your DNS host provider.
- Once the TXT record has been added in your DNS return back to Mimecast and validate the DNS record.
- In the Mimecast Portal, go to Administration > Gateway > Policies
- Click New Policy and select DKIM signing.
- Configure the policy as follows:
- Policy Narrative: Provide a name, for example, "DKIM for example.com"
- Emails from: Your sending domain. You are given the option of typing your domain.
- Email To: Make sure the Applies To is set to External Addresses. Specify to apply to all external recipients.
- Validity: Make sure this is set to Enable. Set policy to Always On. Everything else in this section can be left blank.
TEST AND CONFIRM DKIM SIGNING
To confirm that DKIM is working correctly:
- Send a test message to an external user or you may use a tool like mail-tester.com.
- Verify that the DKIM signature is included in the headers and that it passes.
After following all the steps above, DKIM should now be fully set up and signing your outbound messages as expected through Mimecast.