Overview
This article explains the procedure for configuring the DKIM feature for administrators who use the DKIM feature in Email DLP.
Notes
- The content of this article is based on product specifications as of October 2026 and is subject to change without notice.
-
For information on how to access the Email DLP Management Console, please refer to the following article.
Accessing Method to Email DLP Management Console -
For an overview of DKIM and frequently asked questions, please refer to the following article.
[Email DLP] About DKIM -
DKIM can only be configured for custom Domains (Domains owned by customers) already registered with HENNGE One.
For information on how to check registered Domains, please refer to the following article.
[Customer Portal] Managing Domains
Table of Contents
Procedure
Activating DKIM
-
Access the Email DLP Management Console [Tenant Settings]-[DKIM Setup].
-
Click [+ Add new selector].
※ Since only one Selector can be activated, add only one common Selector even when configuring multiple Domains. -
When the [Create DKIM Selector] window is displayed, enter the following information.
-
[Selector Name]: Enter a Selector Name using any value that meets the following conditions.
※ Available characters: Alphanumeric characters a-z and 0-9, periods (.), and hyphens (-)
※ Maximum number of characters: 63 characters
※ Other condition: Must begin with a lowercase letter. -
[Key Length]: Select either [1024 bits] or [2048 bits].
To improve security, we recommend issuing a key with a key length of 2048 bits.
If you cannot configure a key length of 2048 bits due to restrictions such as the DNS string length limit, issue a key with a key length of 1024 bits.
-
[Selector Name]: Enter a Selector Name using any value that meets the following conditions.
-
The generated record will be displayed. Add it to the DNS TXT record.
※ By default, the TXT record value includes the "t=y;" (Test Mode) tag. Clear the check box for [Include Test Mode tag (t=y;)] at the bottom before copying.
※ If you want to enable DKIM records for multiple Domains, including subdomains (E.g., sub.example.com), you must add this TXT record to the DNS for each Target Domain.
※ The method for adding TXT records on a DNS server differs depending on the server.
Please check with your DNS server provider for Details. -
Open Command Prompt (Windows) or Terminal (macOS), run the command, and confirm that the configured TXT record value is displayed.
<For Windows> ※ Use Command Prompt.
nslookup -type=TXT <セレクタ名>._domainkey.<追加ドメイン> 8.8.8.8
Display example
C:\Windows\system32>nslookup -type=TXT <セレクタ名>._domainkey.<追加ドメイン> 8.8.8.8 サーバー: dns.google Address: 8.8.8.8 権限のない回答: <セレクタ名>._domainkey.<追加ドメイン>. text = "v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3<中略>dPx4QIDAQAB"
<For macOS> ※ Use Terminal.
dig +short @8.8.8.8 <セレクタ名>._domainkey.<追加ドメイン> txt
Display example
dig +short @8.8.8.8 <セレクタ名>._domainkey.<追加ドメイン> txt "v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3<中略>dPx4QIDAQAB"
-
After registering the TXT record in DNS, click [Activate].
-
Enter the Domain to register for DKIM in [domain name] and click [Activate].
To register multiple Domains, enter them separated by line breaks.
※ For information on how to add a Domain to an existing Selector, refer to the following article.
[Email DLP] Add new domain to existing DKIM
Checking DKIM Activation Status
Complete the following procedure for All Domains where DKIM has been activated.
-
In the Email DLP Management Console, access [Tenant Settings]-[DMARC Apply Status].
-
Click the Domain for which DKIM has been activated to open its Details.
-
Confirm that the Status of [DKIM] is set to “enable.”
DKIM Verification
When newly registering DKIM, perform disabling Test Mode and functionality testing using the following Procedure.
※ When newly deploying Email DLP, perform disabling Test Mode and functionality testing after the Email DLP connection has been completed.
Disabling Test Mode
Check the TXT record configured on the DNS server. If the DKIM value contains “t=y;”, delete it.
※ No action is required in Email DLP. (The TXT record displayed in Email DLP is a sample record.)
After deleting the record, check the Status again in Checking DKIM Activation Status.
Functionality Test
- [Email DLP] Operation Test (Microsoft 365) - [Confirm Email DLP DKIM Setup]
- [Email DLP] Functionality Test (Google Workspace) - [Confirm Email DLP DKIM Setup]
Translation Disclaimer
This article has been automatically translated from the original Japanese version for your convenience.
While we strive to ensure accuracy, we cannot guarantee its reliability or completeness.
In the event of any discrepancies or questions regarding the content, the official Japanese version shall prevail.