Skip to main content

DKIM Continuous Protection Report

How to access and use the DKIM Continuous Protection Report

The DKIM Continuous Protection Report is a comprehensive tool within Valimail's services that helps you monitor and maintain the health of your DKIM (DomainKeys Identified Mail) records. It gives you visibility into the status and effectiveness of your DKIM records, how actively each key is being used, the age of key rotation, and key length in bits.

By surfacing these critical factors in one place, the DKIM Continuous Protection Report helps you ensure the security and reliability of your email authentication and strengthen the integrity of your digital communications.

This article explains the main features and benefits of the report so you can make the most of it for your organization.

The DKIM Continuous Protection Report is available only in our Enforce Enterprise product. If you'd like access to this report, please reach out to your Valimail Account Manager.

Summary Section

summary

At the top of the report, the Summary section gives you an at-a-glance health check across your entire DKIM key inventory, broken down into three categories:

  • Bits: the percentage of keys at 2048+ bits (recommended), 1024 bits, 512 bits, and unknown key length. All keys should ideally have a key length of 2048 bits.

  • Usage: the percentage of keys that were last seen within the last 6 months, more than 6 months ago, or never seen at all. All keys should be removed if they haven't been used in 6 months.

  • Rotation: the percentage of active keys rotated within the last 6 months, more than 6 months ago, or more than 2 years ago. Active keys should be rotated at least every 6 months.

Each category is shown as a color-coded bar (green/orange/red) so you can quickly spot where your organization stands and prioritize cleanup or rotation work before drilling into individual records below.

Using the Filters

Above the report table, you can now filter your DKIM records using the following criteria:

  • Domains: filter by specific domain or subdomain.

  • DKIM Record: filter by whether a domain has DKIM pointed to Valimail or not.

  • Senders: filter by the sending service associated with the key.

  • Bits: filter by key length.

  • Usage: filter by First Seen / Last Seen activity.

  • Rotation: filter by how recently an active key was rotated.

  • Type: filter by record type (CNAME or Manual).

  • Sending Status: filter by whether a domain's sending status is Active.

These filters make it easier to narrow the report down to exactly the records you need to act on. For example, isolating domains that don't have DKIM pointed to Valimail, or domains that are actively sending but haven't rotated their keys recently.

Report Columns

The report contains all DKIM records uploaded to Valimail, with the following columns:

  1. Domain: the domain or subdomain on which the DKIM record is published.

  2. Sender: the sending service associated with the key (e.g., Postmark, Salesforce, Qualtrics).

  3. DKIM Selector: the DKIM selector name for the record.

  4. Bits: the key length. Keys shorter than 2048 bits are flagged with a warning icon, since all keys should ideally be 2048 bits.

  5. Usage: now shows both First Seen and Last Seen dates for the key. Keys that have never been seen are flagged with a red alert icon, and keys not seen in over 6 months are flagged with an orange warning icon. This threshold was extended from 3 months to 6 months to align with best practices and rotation timing keys should be removed if they haven't been used in 6 months.

  6. Rotation: previously the Upload Date column, this has been updated with new logic to track active key usage and flag keys that have been in active use for more than 6 months. Values include the time since the key was last rotated, or "Not Needed Yet" / "N/A" for keys that don't require rotation (e.g., keys that haven't been seen). Active keys should be rotated at least every 6 months; keys that haven't been used in over 6 months should be removed instead of rotated.

  7. Details: click View to see full metadata for the key, including Domain and Sender Owner.

  8. Actions: Add or edit details for a key, and an option to delete a DKIM key. Editing lets you update the Associated Service, Domain Owner, Sender Owner, or Comment.

Need help actually rotating a key? See Managing DKIM Configurations for Popular Email Sending Services for a breakdown of which sending services rotate keys automatically (CNAME-based) versus which ones require you to rotate manually (TXT-based), a service-by-service reference for 22 popular platforms, and a suggested rotation schedule.

Report Actions

report actions

From the top of the report, you can also:

  1. Download CSV: export the full report to a CSV file.

  2. Create Notification: set up an email alert for DKIM keys you'd like to be notified about.

  3. Create a DKIM Key: publish a new DKIM record directly from this button.

Create a Notification for the DKIM Continuous Protection Report

create alert

There are 3 types of email alerts built into the DKIM Continuous Protection Report:

  1. Add/Delete DKIM Keys

  2. DKIM Keys over 6 months

  3. DKIM Keys over 2 years

To configure an alert:

  1. Click Create Notification from the DKIM Continuous Protection Report.

  2. Click Add A Custom Alert.

  3. Enter your email address and select the alerts you want to configure.

  4. Click Add Custom Alert.

Did this answer your question?