Proofpoint Essentials setup

Proofpoint Essentials: DKIM is not verified for outbound mail

The selector record may be missing, incorrect, or not yet verified in the Proofpoint organization.

Problem description

The visible symptom is:

Proofpoint Essentials reports that the DKIM key is not verified.

Check the sending domain

Fix DKIM verification

  1. Open the domain or Connection Details area in your Proofpoint Essentials organization.
  2. Create or select the DKIM key for the exact sending domain.
  3. Copy its selector, DNS name, and value without changing them.
  4. Publish the record at your authoritative DNS provider.
  5. Verify the key in Proofpoint Essentials.
  6. Enable the outbound connector only after SPF and DKIM are ready.
  7. Send a new message and confirm dkim=pass with the expected d= domain.

Common causes

The key was published under the wrong domain, the DNS panel appended the domain twice, an old selector remains active, or the connector was enabled before verification finished.

What the check proves

MailFixIt can validate the public selector and key. Proofpoint must confirm the key is attached to the correct organization and outbound route.

Frequently asked questions

Can I enable the Proofpoint outbound connector before DKIM is verified?

Proofpoint’s Microsoft 365 deployment guide says to update SPF and create and verify a DKIM key before enabling the outbound connector.

Does a correct DNS record prove the provider is using it?

No. The provider must also activate the matching route or signing policy. Confirm the result in its console and in a new message.

Related email diagnostics

Primary sources: Proofpoint Essentials: Microsoft 365 Direct MX integration.