Zoho Mail email configuration guide
Zoho Mail: DKIM record not verifying
Zoho cannot verify the selector record for the custom domain, or signing has not been enabled after DNS verification.
A provider setup symptom may look like:
DKIM record not verifying after a provider DNS change.
What this usually means
The DKIM record does not match the selector generated for this Zoho organization and domain, or Zoho has verified the DNS record but has not begun using it.
Fix it
- In the correct Zoho Mail Admin Console and data center, select the exact custom domain and create or view its DKIM selector.
- Copy the full record name, type, and value from Zoho.
- Publish it in the authoritative DNS zone without a duplicated domain suffix, truncated key, or CNAME/TXT type change.
- Return to Zoho, verify the selector, and enable or make it active as the console requires.
- Send a new external message and confirm that its
d=domain ands=selector resolve and producedkim=pass.
Common mistake
A selector created in another Zoho organization, domain, or regional data center is not interchangeable. DNS verification and active message signing are separate states.
What MailFixIt can check
MailFixIt can inspect public DKIM data for a supplied selector. It cannot enter the Zoho organization or activate signing.
Related troubleshooting
Use the related DKIM guide for a missing owner name or invalid public key.
Frequently asked questions
What does MailFixIt check for Zoho Mail?
It can query the public selector and detect a missing or malformed record. Zoho must confirm verification and active signing.
Should I replace every existing DNS record with the provider values?
No. Confirm the exact record type and owner, preserve unrelated legitimate services, and change only the provider-controlled record required for the intended mail route.
Related email diagnostics
Primary sources: Zoho Mail official setup guidance.