Suped

What issues occur when adding DKIM record to DNS via CName with Cloudflare?

Summary

When adding a DKIM record as a CNAME in Cloudflare, users frequently encounter issues primarily related to Cloudflare's proxying feature (the 'orange cloud'). This proxy, while beneficial for web traffic, can interfere with DNS records like DKIM, preventing proper validation and email authentication. Many problems stem from failing to set the CNAME record to 'DNS only' mode. Misconfigurations, such as incorrect CNAME values, underscores, or a lack of understanding regarding the final activation steps, also contribute to these authentication failures. Effective troubleshooting requires careful verification of DNS settings and sometimes, collaboration with third-party DNS vendors.

Suped DMARC monitor
Free forever, no credit card required
Get started for free
Trusted by teams securing millions of inboxes
Company logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logo

What email marketers say

Email marketers often face practical challenges when configuring DKIM CNAMEs through Cloudflare, frequently encountering issues that block proper authentication. A recurring theme is the confusion surrounding Cloudflare's proxy settings, which are often overlooked for DNS records critical to email deliverability. The reliance on third parties for DNS management can further complicate troubleshooting, leading to delays and frustration in getting DKIM verified. Understanding the fundamental requirement for 'DNS only' mode and the final activation steps within the email sending platform is crucial for marketers.

Marketer view

Email marketer from Email Geeks asks if anyone has encountered issues when adding DKIM records to DNS via CNAME with Cloudflare, indicating a common problem.

08 Aug 2024 - Email Geeks

Marketer view

Email marketer from Proton.me advises selecting DNS management for the domain and adding SPF and DKIM records, emphasizing the importance of correct record creation within Cloudflare.

15 Mar 2024 - Proton

What the experts say

Experts consistently identify Cloudflare's proxying of DKIM CNAME records as the primary cause of authentication issues. They emphasize that such records must be configured in 'DNS only' mode. Furthermore, experts highlight the critical step of verifying DNS propagation using tools like dig to ensure records are visible globally. A frequently overlooked aspect, according to experts, is the 'activation piece' within the email service provider's platform, which completes the DKIM setup process. They advise a holistic approach to configuration and troubleshooting.

Expert view

Expert from Email Geeks advises making sure that Cloudflare's proxying (the orange cloud) is turned off for the DKIM CNAME record to allow proper DNS resolution for email authentication.

08 Aug 2024 - Email Geeks

Expert view

Expert from SpamResource emphasizes the importance of verifying correct DNS record propagation across the internet, noting that caching can sometimes delay visibility.

18 Jan 2024 - SpamResource

What the documentation says

Official documentation from various email service providers and DNS hosts consistently advises against proxying DKIM CNAME records through services like Cloudflare. Many guides explicitly state that such records must be configured in 'DNS only' mode to ensure proper authentication. Documentation often details the exact CNAME values to use, including the necessary underscores, and outlines the step-by-step process for adding these records and subsequently activating them within the respective email sending platform. Some advanced documentation may also mention automated DKIM generation or the importance of validating SVG and certificate files for BIMI (Brand Indicators for Message Identification).

Technical article

Documentation from Customer.io highlights that some hosts do not support underscores (_) in DNS records, and adding a DKIM record can cause an error, even though the underscore is required.

05 May 2023 - Customer.io

Technical article

Documentation from Email Marketing Self Help clearly states that if Cloudflare is used, CNAME records for DKIM cannot be proxied; they must be DNS only for correct functionality.

10 Apr 2023 - Email Marketing Self Help

6 resources

Start improving your email deliverability today

Get started