Set up DKIM validation:
To enable DKIM validation, navigate to Email Security > Spam & Malware Protection > Email Authentication in the Control Panel. Then, under Sender Authentication, select the checkbox Enable DKIM validation for incoming emails.
Set up DKIM signing:
To enable our DKIM signature for outgoing emails, you must first add our CNAME records to the DNS zone of your domain.
It is important to note that we require different DNS values for Hornetsecurity customers and Proofpoint customers. Due to DNS caching, it can take up to 72 hours for the change to take effect.
You can then enable the DKIM signature in the Control Panel under Email Security > Spam & Malware Protection > Email Authentication. The DKIM signature is only enabled for domains that have valid DKIM settings.
How to find out whether you need to add the Hornetsecurity or Proofpoint CNAMEs:
You can find out which CNAME records are required by navigating to Email Security > Spam & Malware Protection > Settings in the Control Panel and viewing the recommended MX settings. If you see Hornetsecurity or Vade MX records there, use the CNAME records for Hornetsecurity. You can recognize these because they contain either "hornetsecurity" or "vade".
If you see Proofpoint MX records, use the CNAME records for Proofpoint. These can be identified by the "pp-tp" in the record.
Add CNAME records:
Add the following two CNAME records to the DNS zone of your domain if you are a Hornetsecurity customer:
hse1._domainkey.DOMAIN.TLD CNAME hse1._domainkey.hornetsecurity.comhse2._domainkey.DOMAIN.TLD CNAME hse2._domainkey.hornetsecurity.comReplace DOMAIN.TLD with your own domain.
Add the following two CNAME records to the DNS zone of your domain if you are a Proofpoint customer:
pp-tp1._domainkey.DOMAIN.TLD CNAME pp-tp1._domainkey.pp-tp.com
pp-tp2._domainkey.DOMAIN.TLD CNAME pp-tp2._domainkey.pp-tp.com
Replace DOMAIN.TLD with your own domain.
Note: DNS changes can take up to 72 hours to take effect.