# DKIM Signing — PostFrame — EternalEngine

DomainKeys Identified Mail cryptographically signs your emails so recipients can verify they came from you and weren't tampered with.

[Back to Domain Verification](https://eternalengineos.io/features/postframe/domain-verification/)DKIM

Domain Security

# DKIM Signing

PostFrame publishes three DKIM CNAME records for your domain, signs every message with a 2048-bit RSA key, and reads the signing status back from the provider so you know the moment DKIM is live.

[Start free](https://app.eternalengineos.io/signup?plan=free&interval=annual)[Domain verification overview](https://eternalengineos.io/features/postframe/domain-verification/)

## Cryptographic Email Signing

Three CNAME records

PostFrame registers your domain with the signing infrastructure and hands you three `<token>`._domainkey CNAMEs; the private key never leaves the signing side

Message integrity

The signature covers email headers and body — any modification in transit causes verification to fail

Rotation without downtime

The CNAMEs delegate to the provider's keys, so keys rotate on the signing side and your DNS never changes

Status read from the provider

Verification stays pending until all three CNAMEs resolve and the provider confirms; it is marked failed only when the provider rejects the DKIM setup

DKIM DNS Record

Record type

CNAME — three records

Host

`<token>`._domainkey.yourdomain.com

Key size

2048-bit RSA

Verification

Read live from the provider each time you press Check

## Keep exploring PostFrame

[### SPF record The one TXT record that names who may send for your domain. Open SPF record →](https://eternalengineos.io/features/postframe/domain-verification/spf/)[### DMARC policy What receivers do when SPF or DKIM fails, and where reports go. Open DMARC policy →](https://eternalengineos.io/features/postframe/domain-verification/dmarc/)[### Separate domains One workspace per domain, with its own DKIM tokens. Open Separate domains →](https://eternalengineos.io/features/postframe/multi-tenant/separate-domains/)

Questions

## Common questions, straight answers.

How many DNS records does DKIM need?

Three CNAME records, one per signing token, each pointing at the signing provider. The domain setup page lists them with a Copy button beside each value.

Why CNAME records instead of a TXT key?

A CNAME delegates to the provider's published key, so the key can rotate on the signing side without you touching DNS again. The signing key is 2048-bit RSA.

How long until DKIM shows as verified?

As soon as the three CNAMEs resolve and the provider confirms them — press Check on the domain page to re-run the lookup. The first time a domain becomes fully verified, PostFrame sends one in-app notification.

What does a "failed" status mean?

Only a provider rejection of the DKIM setup. A record that has not propagated yet stays "pending" with a per-record found / missing / mismatch verdict and a hint on what to change.

## Run your business from one place.

Five plans, seventeen launch apps, one dashboard. Set up in under 5 minutes — change tiers any time.

[Start free$0 forever &bull; No card &bull; Upgrade any time](https://app.eternalengineos.io/signup?plan=free&interval=annual)[Talk to Sales](https://eternalengineos.io/contact/)

From $0 · Basic $9.95/mo · Save 20% on annual billing · Upgrade or downgrade any time
