DKIM Signing
PostFrame publishes three DKIM CNAME records for your domain, signs every message with a 2048-bit RSA key, and reads the signing status back from the provider so you know the moment DKIM is live.
Cryptographic Email Signing
<token>._domainkey CNAMEs; the private key never leaves the signing side<token>._domainkey.yourdomain.comCommon questions, straight answers.
How many DNS records does DKIM need?
Three CNAME records, one per signing token, each pointing at the signing provider. The domain setup page lists them with a Copy button beside each value.
Why CNAME records instead of a TXT key?
A CNAME delegates to the provider's published key, so the key can rotate on the signing side without you touching DNS again. The signing key is 2048-bit RSA.
How long until DKIM shows as verified?
As soon as the three CNAMEs resolve and the provider confirms them — press Check on the domain page to re-run the lookup. The first time a domain becomes fully verified, PostFrame sends one in-app notification.
What does a "failed" status mean?
Only a provider rejection of the DKIM setup. A record that has not propagated yet stays "pending" with a per-record found / missing / mismatch verdict and a hint on what to change.
Run your business from one place.
Five plans, seventeen launch apps, one dashboard. Set up in under 5 minutes — change tiers any time.
From $0 · Basic $9.95/mo · Save 20% on annual billing · Upgrade or downgrade any time
