How to Add a DKIM Record in Namecheap

VigilDog Team · October 4, 2026 · 6 min read

DKIM is the signature that tells receiving mail servers your email really came from you, and it lives in a DNS TXT (or CNAME) record. If your domain's DNS is at Namecheap, adding that record takes a few minutes once you know exactly what goes in each field. Here is the whole process, including the two gotchas that trip most people up.

What a DKIM record actually holds

DKIM works with a key pair. Your email provider holds the private key and uses it to sign every outgoing message. The matching public key sits in your DNS so any receiver can verify the signature. That public key is what you publish in Namecheap.

Every DKIM record lives at a subdomain called a selector, in the form selector._domainkey.yourdomain.com. The selector lets you run more than one key at once (useful during rotation) and lets each provider have its own key. The record's value looks like v=DKIM1; k=rsa; p=MIGfMA0... where the long p= string is the actual public key.

DKIM rarely acts alone. It is one of the three checks DMARC relies on, alongside SPF, and DMARC is what turns those checks into a real policy. If you want the full picture of how they interlock, see fix SPF, DKIM and DMARC.

Senderyour domainSPFauthorised IP?DKIMsignature valid?AlignmentFrom matches?DMARC policynone / quarantine / rejectInbox
How SPF, DKIM and DMARC verify an email

Get the key from your email provider first

You never invent a DKIM record; your sending provider generates it. Grab the exact host and value from wherever you send mail before you touch Namecheap.

One important fork in the road: some providers hand you a TXT record, others hand you a CNAME. Google Workspace gives you a single TXT record at the google selector (generate the 2048-bit key under Admin console > Apps > Google Workspace > Gmail > Authenticate email). Microsoft 365 instead gives you two CNAME records, selector1._domainkey and selector2._domainkey, that point at your onmicrosoft.com domain so Microsoft can rotate keys for you. ESPs like SendGrid, Mailchimp, and Postmark also tend to use CNAMEs for the same reason. Copy whatever type they specify exactly.

Add the record in Namecheap Advanced DNS

In your Namecheap dashboard, go to Domain List, click Manage next to the domain, then open the Advanced DNS tab. Under Host Records, click Add New Record.

  • For a TXT-style key (e.g. Google Workspace): set Type to TXT Record, Host to your selector plus _domainkey, for example google._domainkey, and paste the full v=DKIM1; k=rsa; p=... string into Value.
  • For a CNAME-style key (e.g. Microsoft 365, SendGrid): set Type to CNAME Record, Host to the selector your provider gave you (like selector1._domainkey), and Target to the exact target hostname they specified.
  • Leave TTL on Automatic. It only affects how quickly changes propagate.
  • Do NOT append your domain to the Host field. Namecheap adds it for you, so typing google._domainkey.yourdomain.com would create a broken double-domain record.
  • Click the green checkmark to save each record.

Verify it and fix the common breakages

DNS changes at Namecheap usually appear within minutes but can take up to an hour or two. Confirm the record is live with a direct lookup rather than trusting the UI: run dig TXT google._domainkey.yourdomain.com +short (or nslookup -type=TXT google._domainkey.yourdomain.com on Windows). You should see your v=DKIM1 value returned.

If it does not resolve, check these first. A trailing-domain mistake in the Host field is the most frequent culprit. A DKIM public key for a 2048-bit key is longer than a single DNS string can hold (255 characters), so it gets split into multiple quoted chunks; Namecheap's editor handles this splitting automatically, but if you pasted the key with line breaks or stray quotes, remove them and paste it as one continuous string. And if you copied a CNAME target into a TXT record's value (or vice versa), the record type will not match what your provider expects.

Once DNS resolves, send yourself a test message and check the headers for dkim=pass, or run your domain through the free DMARC checker to confirm alignment across SPF, DKIM, and DMARC together.

Keep it signing after you walk away

DKIM records break quietly. A provider rotates keys and the old selector goes stale, someone edits DNS during an unrelated change, or a domain migration drops the record entirely. Nothing bounces immediately, but your deliverability erodes and you often only notice when a client complains that emails are landing in spam.

That is exactly the kind of slow drift worth watching automatically. VigilDog's domain and email monitoring tracks your SPF, DKIM, and DMARC records and alerts you when one changes or disappears, so a broken signature becomes a notification instead of a mystery weeks later.

Questions

Frequently asked

Should I use a TXT or CNAME record for DKIM in Namecheap?

Use whatever your email provider specifies. Google Workspace uses a TXT record; Microsoft 365 and many ESPs use CNAME records so they can rotate keys on their side. Match the type exactly.

Why does my DKIM record fail to verify even though I added it?

The usual causes are appending your domain to the Host field (Namecheap adds it automatically), pasting the key with line breaks or extra quotes, or using the wrong record type. Confirm with a dig TXT lookup on the selector.

How long does a DKIM record take to work at Namecheap?

Usually a few minutes, but allow up to an hour or two for full DNS propagation before you conclude something is wrong.

Never lose a DKIM record again

VigilDog watches your SPF, DKIM, and DMARC records and pings you the moment one changes or breaks. Set it once, stop guessing about deliverability.

Your first domain is free forever