Fortinet black logo

Cookbook

Enabling DKIM checking for incoming email

Copy Link
Copy Doc ID 9538f879-a447-11ea-8b7d-00505692583a:248855
Download PDF

Enabling DKIM checking for incoming email

FortiMail can perform DKIM checking for the incoming mail by querying the DNS server that hosts the DNS record for the sender’s domain name to retrieve its public key to decrypt and verify the DKIM signature.

To enable DKIM checking:
  1. Go to Profile > Session > Session and click New, or edit an existing profile.

  2. Under Sender Validation, enable the DKIM checking option. DKIM signing options are also available.
To configure DKIM signing:

If you want to sign the outgoing mail with DKIM signatures so that the remote receiving server can verify the signatures, you can do so after you create the protected domains. Note that the DKIM signing settings only appear when configuring an existing protected domain.

  1. Go to Domain & User > Domain > Domain and click New, or edit an existing profile.
  2. Under Advanced Setting, click DKIM Setting.
  3. Click New.
  4. Enter a name in the New selector field.
  5. Set DKIM key to Auto Generation. The key pair will be automatically generated and the public key exported for publication on a DNS server.
  6. Click OK.
  7. The new selector will appear. Select the newly created selector and click Download to download the domain key DKIM file.
  8. Publish the public key by inserting the exported DNS record into the DNS zone file of the DNS server that resolves this domain name.
  9. From the DKIM Setting window in FortiMail, select the newly created selector and click Activate.
  10. Click Close, and click OK.

Enabling DKIM checking for incoming email

FortiMail can perform DKIM checking for the incoming mail by querying the DNS server that hosts the DNS record for the sender’s domain name to retrieve its public key to decrypt and verify the DKIM signature.

To enable DKIM checking:
  1. Go to Profile > Session > Session and click New, or edit an existing profile.

  2. Under Sender Validation, enable the DKIM checking option. DKIM signing options are also available.
To configure DKIM signing:

If you want to sign the outgoing mail with DKIM signatures so that the remote receiving server can verify the signatures, you can do so after you create the protected domains. Note that the DKIM signing settings only appear when configuring an existing protected domain.

  1. Go to Domain & User > Domain > Domain and click New, or edit an existing profile.
  2. Under Advanced Setting, click DKIM Setting.
  3. Click New.
  4. Enter a name in the New selector field.
  5. Set DKIM key to Auto Generation. The key pair will be automatically generated and the public key exported for publication on a DNS server.
  6. Click OK.
  7. The new selector will appear. Select the newly created selector and click Download to download the domain key DKIM file.
  8. Publish the public key by inserting the exported DNS record into the DNS zone file of the DNS server that resolves this domain name.
  9. From the DKIM Setting window in FortiMail, select the newly created selector and click Activate.
  10. Click Close, and click OK.