These cookies provide us with information on how our websites are being used, to help us improve the quality and relevance of content we place on them. Additionally, they also allow us to show you embedded videos and remember your preferences and actions, so that the websites do not bother you with the same request repeatedly (e.g. filling a form to download a PDF file and provide feedback about such actions to our affiliated entities).
You are viewing our older product's guide. Click here for the documentation of GoodData Cloud, our latest and most advanced product.
Configure DKIM for Outgoing Email
You can use DomainKeys Identified Mail (DKIM) to authenticate your outgoing white-labeled email.
The email is marked trusted, and receiving mail exchangers can verify that it is coming from an authorized source. For more information, see http://www.dkim.org/.
GoodData uses OpenDKIM. For more information, see http://www.opendkim.org/.
DKIM must be configured on two sides, yours and GoodData’s.
There are two possible scenarios of setting up DKIM:
Using a specific private key to sign emails
You send your private key to the person managing the white-labeling process with GoodData Support.
We strongly recommend that you encrypt the private key. The private key contains sensitive information, which an unauthorized person can use to impersonate the server identity. To encrypt, you can use the GoodData PGP key or another encryption method available on your side. For the guidelines on how to encrypt a document using PGP, see GNU Privacy Handbook.
As an alternative, we can generate a unique private key for you.
You provide information which DKIM selector on which domain you use, so that the public key can be verified.
We add your private key to the configuration of our email servers.
You can set up a separate key for each domain or mailbox that you use for sending email.
Once all the steps are completed, your outgoing emails are signed. If you use Gmail, you will see a “signed-by: your_domain.com
” message in your email.
Using a GoodData shared key to sign emails
You contact GoodData Support with a request for a DNS record with a public key.
We provide you with a DNS record with a public key.
You add the key to the DNS records of your domain.
(Optional) Add
include:relays.gooddata.com
into your Sender Policy Framework (SPF) record to ensure that GoodData mail relays are authorized to send emails. To get email relay addresses, use the followingdig
commands:
Once all the steps are completed, your outgoing emails are signed. If you use Gmail, you will see a “signed-by: your_domain.com
” message in your email.