Zoho Mail email configuration guide

Zoho Mail: DKIM record not verifying

Zoho cannot verify the selector record for the custom domain, or signing has not been enabled after DNS verification.

Problem description

A provider setup symptom may look like:

DKIM record not verifying after a provider DNS change.

Check the sending domain

What this usually means

The DKIM record does not match the selector generated for this Zoho organization and domain, or Zoho has verified the DNS record but has not begun using it.

Fix it

  1. In the correct Zoho Mail Admin Console and data center, select the exact custom domain and create or view its DKIM selector.
  2. Copy the full record name, type, and value from Zoho.
  3. Publish it in the authoritative DNS zone without a duplicated domain suffix, truncated key, or CNAME/TXT type change.
  4. Return to Zoho, verify the selector, and enable or make it active as the console requires.
  5. Send a new external message and confirm that its d= domain and s= selector resolve and produce dkim=pass.

Common mistake

A selector created in another Zoho organization, domain, or regional data center is not interchangeable. DNS verification and active message signing are separate states.

What MailFixIt can check

MailFixIt can inspect public DKIM data for a supplied selector. It cannot enter the Zoho organization or activate signing.

Use the related DKIM guide for a missing owner name or invalid public key.

Frequently asked questions

What does MailFixIt check for Zoho Mail?

It can query the public selector and detect a missing or malformed record. Zoho must confirm verification and active signing.

Should I replace every existing DNS record with the provider values?

No. Confirm the exact record type and owner, preserve unrelated legitimate services, and change only the provider-controlled record required for the intended mail route.

Related email diagnostics

Primary sources: Zoho Mail official setup guidance.