How to Detect and Fix Expired DKIM Public Keys in 2026
Find and fix expired DKIM public keys causing email verification failures. Use real-time checks, bulk verification, and inbox placement tests to prevent.
Why are expired DKIM keys breaking email verification?
You send a campaign. Your list looks clean. Yet some emails bounce. You check the logs — the error says “DKIM signature verification failed.” You’re baffled. The addresses are valid. The domain looks fine. But the email didn’t land.
This happens when a domain’s DKIM public key expires without replacement. The signature still checks, but the server refuses it because the key is outdated. Even real, active addresses fail verification under this breakage. It’s like showing an expired passport at a border — technically correct, but no longer valid.
MailTester’s 98.9% accuracy catches this. It checks DNS records in real time and flags addresses tied to missing or expired DKIM keys before you send. This prevents bounces, protects sender reputation, and stops your deliverability from degrading silently.
Key takeaways
- Expired DKIM public keys cause verification failures even for valid email addresses, leading to unnecessary bounces.
- MailTester detects expired or missing keys by checking DNS records in real time during verification.
- Fixing expired keys before sending preserves sender reputation and improves inbox placement.
How DKIM works with email verification — and where it breaks
When you send an email, the receiving server checks the DKIM signature against the public key published in the sender’s DNS records. If that key is missing, expired, or malformed, the signature fails — even if the email address itself is valid. This creates false negatives in your list, where real addresses are flagged as invalid. MailTester’s verification API doesn’t just check the address; it also validates the DNS-level DKIM status, so you catch these issues before sending.
Digital signatures and DNS records: what’s really being checked
DKIM signs each email with a cryptographic key tied to your domain. The receiving server retrieves the public key from DNS and uses it to verify the signature. It’s like checking a notarized document — if the notary’s public key isn’t available or has expired, the document is rejected, even if the content is sound.
Common issues include expired keys, outdated key rotations, or misconfigured TXT records. A key might still be active, but if the record is incorrectly formatted, the server can’t read it — and the email fails validation. According to the RFC 6376, DKIM relies entirely on DNS lookup for key retrieval, making DNS accuracy non-negotiable.
Why this breaks email verification — and how to fix it
Most email verification tools only check if the address format is correct and if the mailbox exists. They don’t probe DNS records for DKIM validity. So a valid address with an expired or broken DKIM key still shows as “valid” — until you actually send and fail.
When you send to a list full of such addresses, your sender reputation drops fast. ISPs like Gmail, Yahoo, and Outlook flag your domain as inconsistent. They’ll either reject your emails or send them to spam — even if the content is clean.
Let’s be clear: a single expired DKIM key isn’t a dealbreaker for the sender, but it’s a red flag to the receiver. Your domain’s reputation ties directly to alignment between sending practices and DNS records.
With MailTester’s real-time verification API, you can check both address validity and DKIM DNS status in one step. The tool surfaces expired or malformed DKIM records before you send, so you can either update your keys or remove those addresses from your list.
It’s not about perfection — it’s about catching problems before they hurt deliverability. Every valid address with a broken signature is a missed opportunity. Fixing these early keeps your IP and domain reputation intact, which directly improves inbox placement.
How to detect expired DKIM keys in your email list
You can detect expired DKIM keys in your email list by running a bulk verification using MailTester’s email validation tool. It checks the DNS records of each recipient’s domain for the DKIM selector and evaluates whether the public key has expired. Keys that are invalid or past their validity period return a clear Dkim Expired or Dkim Invalid status—distinct from generic Invalid or Catch-all results—so you know immediately which addresses are failing due to cryptographic issues, not deliverability rules.
Scan your list for DKIM-related failures with MailTester
- Upload your entire email list to MailTester’s bulk email verification tool to check all addresses at once.
- The system queries the domain’s DNS records to locate the DKIM public key using the published selector, just as receiving mail servers do.
- It evaluates the key’s validity period by checking the
expirestimestamp in the DKIM DNS record, consistent with the standards defined in RFC 6376. - If the key has expired or is malformed, MailTester flags it with a
Dkim ExpiredorDkim Invalidverdict, giving you precise insight into why verification failed. - These failures aren’t just bounce risks—they can signal broader authentication breakdowns that affect sender reputation and inbox placement.
Act before sending to avoid delivery issues
- Use the verification report to filter out addresses with
Dkim Expiredstatus before launching campaigns. - These addresses are not necessarily invalid—but they represent a risk because the sender’s authentication mechanism has failed.
- Some ISPs (like Gmail and Outlook) treat expired DKIM signatures as a red flag, often treating the email as suspicious or dropping it into spam.
- Fixing DKIM involves updating the key in DNS—MailTester doesn’t change DNS, but it identifies the problem so you can act.
- Regular verification, even monthly, helps catch expired keys before they impact deliverability, especially for high-volume senders.
Expired DKIM keys don’t just cause bounces—they undermine trust. If your authentication fails, even valid emails may never reach the inbox.
Fixing expired DKIM keys: a real-time process
You can detect and fix expired DKIM keys by first identifying affected domains using MailTester’s bulk verification report, then checking your DNS provider for the DKIM TXT record’s exp tag. If the key has expired, regenerate it in your email platform (like SendGrid or Mailchimp), publish the new public key under the same selector, wait for DNS propagation, and reverify addresses with MailTester’s real-time API to confirm delivery readiness. This process keeps your sender reputation intact and prevents hard bounces.
Step-by-step: Identify and resolve expired DKIM keys
- Run your email list through MailTester’s bulk verification report. Look for domains flagged with DKIM-related failures or verification issues — these often stem from expired keys.
- Log in to your DNS provider (like Cloudflare, AWS Route 53, or GoDaddy). Navigate to the DNS records for the domain and locate the DKIM TXT record using the same selector (e.g.,
default._domainkey). - Check the record’s
exporexpirestag. If it’s set to a past date, the key is expired. This means your messages may be rejected or marked as untrusted by receiving servers. - Go to your sending platform (SendGrid, Mailchimp, HubSpot, etc.) and generate a new DKIM key pair. This creates a new private key (kept secure) and a new public key (which you publish).
- Update the existing DKIM TXT record in DNS with the new public key, keeping the same selector. This ensures continuity in email signature validation.
- Wait for DNS propagation. Most changes resolve within 1–5 minutes, but can take up to 24 hours if your TTL is high. Use tools like MXToolbox to verify the new record is live.
- Reverify affected domains using the MailTester real-time API. This confirms that DKIM now passes and the addresses are deliverable. This step is crucial — it’s your proof the fix worked.
Why this matters: Reputation and delivery stay intact
Misconfigured or expired DKIM keys break email authentication, leading to increased hard bounces and poor inbox placement. According to RFC 6376 (DKIM specification), the exp tag is used to signal expiration, and receiving servers are expected to respect it. Ignoring expired keys damages sender reputation and can lead to IP or domain blacklisting. Regular verification with a tool like MailTester ensures you catch these issues before they impact your deliverability.
Why you can’t rely on your ESP’s dashboard alone
You can’t trust your ESP’s dashboard to catch expired DKIM public keys because it only shows the current configuration, not whether the key has expired. Most ESPs won’t flag an expired key until it’s used in a send—by then, you’ve already sent to invalid addresses and risk damaging your sender reputation. The real fix comes from verifying DNS records independently before sending.
ESP dashboards don’t test key validity over time
Just because your ESP shows a DKIM record in place doesn’t mean it’s still valid. Keys expire, domains change, and configurations drift—especially in large-scale or automated environments. Your ESP tracks active settings at a moment in time, but not their ongoing usability. A failed authentication attempt only surfaces during send time, not during setup.
Let’s say you set up DKIM in 2022 and never revisited it. The key may have expired by 2024. Your ESP won’t detect this until you attempt to send an email authenticated with that key. At that point, the message fails auth, and your IP starts accruing negative signals—even if you’ve done nothing wrong. This kind of failure doesn’t just impact one send; it weakens your long-term sender reputation, especially if repeated.
Independent DNS checks catch expired keys early
That’s where tools like MailTester come in. Instead of waiting for a send, MailTester verifies DKIM and SPF records directly in DNS—checking for expiration, alignment, and correctness—before any email ever leaves your system. It’s not part of your ESP’s workflow; it’s a pre-send verification layer.
You can run bulk checks on your mailing list using MailTester’s bulk verification to catch expired keys across thousands of domains. For real-time validation in integrations like HubSpot or SendGrid, the real-time API can validate email addresses with full DNS analysis on demand. This includes checking if a DKIM key has actually expired, not just if it exists.
Independent verification matters. Sending to addresses with expired DKIM keys looks like a weak authentication attempt to recipient servers, and that triggers scrutiny. According to RFC 6376, DKIM verification failures should be treated as hard failures unless specifically allowed. Avoiding them is a baseline of good email hygiene.
By catching expired keys before sending, you prevent unnecessary authentication failures that degrade deliverability. This isn’t about perfection—it’s about removing preventable issues that can silently eat into inbox placement over time.
How MailTester's inbox placement tests detect DKIM failures
MailTester’s inbox placement tests simulate real email delivery to Gmail, Outlook, and AppleMail by sending messages through actual infrastructure. Each test checks DKIM validation status during transit—when a signature fails, the message is flagged, which can push it into a spam or junk folder. If a domain with verified addresses consistently lands below 85% in inbox placement, a DNS-level issue like an expired DKIM key is a likely cause.
Why DKIM failures show up in inbox tests but not in basic checks
Standard email validation tools check syntax, domain existence, and basic MX records—they don’t simulate the full delivery path. MailTester goes deeper by mimicking real-world delivery, running tests across multiple provider environments where DKIM verification happens in real time. If the DKIM signature fails during delivery, even a technically valid email will not reach the inbox.
Many tools miss this because they rely on static checks or don’t validate the full delivery chain. A valid address might still fail to deliver if the DKIM key has expired, been revoked, or is misconfigured. This is why your bounce rate might be low—but your open rates are still poor.
How to use inbox placement results to catch expired DKIM keys
Run a placement test with a small, representative sample of your valid addresses. If the inbox delivery rate is under 85% across multiple providers—especially Gmail or Outlook—it’s a red flag. Check your DNS records with tools like MXToolbox or public-dns.info to verify your DKIM TXT record is present and correctly formatted.
DKIM keys are time-bound. If you haven’t rotated them in over two years, they may have expired. Use a real-time inbox placement test to confirm whether DKIM issues are affecting delivery before sending to larger lists.
Fixing expired keys requires updating the public key in your DNS and re-signing outgoing mail with the new private key. Once done, re-run the inbox placement test to validate the fix. This step is often overlooked in automated checks but is critical for consistent deliverability.
How to prevent future DKIM key expiration
You can prevent expired DKIM keys by setting automated alerts for key expiry dates, rotating keys every 6–12 months, storing them securely with clear expiry records, and running quarterly full list checks using a reliable verification tool like MailTester. This proactive approach stops deliverability issues before they impact your sending.
Set alerts and track rotation
- Use your ESP or DNS provider’s built-in key management features to schedule expiry notifications. Most modern platforms support reminders for upcoming key rotations.
- Establish a standard key rotation policy—rotate DKIM keys every 6 to 12 months. This limits exposure if a key is compromised and aligns with industry best practices for cryptographic hygiene.
- Record each key’s creation and expiry date in your internal documentation. Include the key selector, domain, and the corresponding private key location (e.g., secure vault, encrypted file).
Validate and monitor at scale
- Run full list verification every quarter using a tool that checks both syntax and infrastructure signals like DKIM, SPF, and MX records. MailTester’s bulk verification service identifies expired or misconfigured keys across thousands of addresses.
- Monitor domain-level deliverability using inbox placement testing. If your DMARC policy is strict (p=reject), even one expired DKIM key can trigger a failure and reduce inbox placement. DMARC.org outlines how alignment and authentication are enforced.
- Integrate your email verification workflow into your onboarding or campaign setup. Use the MailTester API to validate domains in real time during list acquisition or during automated campaigns.
Automated systems aren’t foolproof—human oversight is still required. Let’s make key rotation part of your compliance rhythm. When every email is sent from a verified, up-to-date domain, deliverability becomes predictable, not fragile.
DKIM vs SPF vs DMARC: their roles in delivery
SPF, DKIM, and DMARC work together to verify your emails’ authenticity. SPF checks if the sending server’s IP is authorized. DKIM cryptographically signs the message using a private key, and the public key in DNS confirms the signature. DMARC enforces policies based on SPF and DKIM results—telling receivers what to do with failed messages. An expired DKIM key breaks verification completely, even if SPF and DMARC are correct.
How each layer protects email delivery
SPF acts as a gatekeeper: it lists which IP addresses are allowed to send email on behalf of your domain. If a message arrives from an unlisted IP, SPF fails. This stops spoofing at the source level.
DKIM adds accountability. When your server sends an email, it signs the headers and body with a private key. The recipient’s server fetches your public key from DNS and verifies the signature. If the key is expired, the signature fails, and the message may be rejected—even if SPF passes.
DMARC is the policy engine. It tells receivers what to do when SPF or DKIM fails: quarantine, reject, or just report. It also specifies where to send failure reports. Without DMARC, even a correct SPF or DKIM can go unenforced.
Why an expired DKIM key can derail delivery
Many email providers treat a failed DKIM signature as a strong signal of forgery or misconfiguration. Even if SPF is valid and DMARC is set to allow delivery, a failed DKIM verification often results in the message being marked as suspicious or outright blocked.
That’s why you can’t rely on SPF alone. One expired DKIM key can cause delivery failures across hundreds of legitimate messages. This is especially common after security audits, key rotations, or when using third-party senders who forget to update DNS records.
Let’s be clear: these systems are not optional. They’re fundamental to being trusted by modern inbox providers. Industry standards like those from RFC 7052 and the DMARC working group define these protocols as a baseline for email security.
If you’re checking for issues like this, verify your public keys before deploying new campaigns. Regularly test your DNS records for validity using tools like MXToolbox or dmarcian to catch expired keys early.
MailTester’s email checker and bulk verification tools help detect invalid or suspicious email setups—including misconfigured or expired DKIM keys—before you send. You don’t have to guess. You can test, confirm, and fix.
What happens if you ignore expired DKIM keys?
If you ignore expired DKIM keys, your emails fail authentication during delivery, leading to bounces, spam folder placement, and reputational damage. Reputation penalties from major providers like Gmail compound over time, hurt inbox placement, and can trigger blocklist signals. Recovery takes weeks, even months, and requires resetting sender reputation — prevention via regular key checks is far more efficient than remediation.
Here’s what specifically goes wrong when DKIM keys expire:
- Receiving servers check DKIM signatures during delivery — if the public key is expired or no longer valid, the signature fails verification, and the email is treated as unauthenticated.
- Gmail, Outlook, and other reputable providers use authentication results to determine inbox placement. Failed DKIM scores reduce your sender reputation, which directly affects whether your messages land in the inbox or the spam folder.
- Frequent authentication failures — even if only a few messages a day — can trigger alerts in systems like Sender Score or Spamhaus, which monitor sending behavior and reputation over time.
- Once your domain reputation is degraded, you may see reduced delivery rates, higher bounce rates, and increased spam complaints — even if your content is clean and your lists are valid.
- Rebuilding trust after a reputation hit requires sustained, clean sending patterns over weeks, and in extreme cases, may require changing infrastructure or even domains.
How to stop this from happening
Let’s be clear: detecting and fixing expired DKIM keys isn’t optional. It’s part of maintaining basic deliverability hygiene. One missed key doesn’t break your entire domain — but repeated failures do.
Use automated tools that monitor your domain’s DMARC, SPF, and DKIM alignment regularly. Real-time tools like MailTester’s API Email Checker can verify how your domain handles authentication for specific messages before sending. This catches issues early, before they impact your entire mailing list.
For teams managing large volumes, bulk list verification identifies not just invalid addresses, but also patterns of misconfigured DNS records tied to authentication. You can use this to audit your list before sending, catching expired keys in bulk. Many tools miss this — it’s a gap MailTester fills.
For deeper insight into how authentication failures impact delivery, refer to standards like RFC 6376 (DKIM) and the widely referenced DMARC reports from industry sources — these show how real-world providers apply failure penalties over time.
Bottom line: expired DKIM keys aren’t a minor glitch. They are a direct path to failed deliveries, penalized domains, and slow recovery. Catching them early avoids the need for fire drills later. Prevention, not repair, is the only scalable strategy.
MailTester’s real-time verification API detects expired keys
MailTester’s real-time verification API checks DKIM key validity during every email verification by querying DNS for the public key and its expiry status. It returns structured results—dkim_valid, dkim_expired, or dkim_missing—so you know exactly when a domain’s DKIM setup is failing. This catches issues before they impact deliverability, giving you real-time insight into why verification might fail.
How it works: DNS checks, not guesses
When you run a check, MailTester doesn’t rely on historical data or assumptions. It performs an up-to-the-moment DNS lookup for the domain’s DKIM record and parses the expires field. If the expiry date is in the past, the API flags it as dkim_expired. This ensures you’re not depending on outdated information—even if a key was valid last month, it’s useless today.
Let’s say you’re onboarding users and validating their email addresses. A single expired DKIM key from a domain like company.com can cause the entire setup to fail, even if the address is otherwise valid. Without real-time checking, you might send to a user whose domain has no functional DKIM, leading to rejected emails and damaged sender reputation. MailTester surfaces this risk instantly.
Integrate early, fix fast
Integrate the API into your sign-up flow, campaign prep, or list hygiene routine. You’ll catch expired keys before they cause a delivery failure. For example, sending a welcome email to a user at example.org with a missing or expired DKIM key results in low inbox placement or outright rejection by providers like Gmail or Microsoft.
DKIM is part of a broader email authentication stack. According to RFC 6376, the DKIM signature must be valid and not expired at the time of receipt. MailTester ensures compliance with that standard. It doesn’t replace your need to maintain your own DKIM keys—but it tells you when your setup breaks automatically.
Start with the free tier: 100 verifications included, no expiry date on credits. Test high-risk domains or critical user signups without cost. If you’re managing a large list, use the API to validate addresses before campaigns. No need to wait until bounces or blocklists arrive.
Check if your domain’s DKIM is still active—try a real-time email address validation right now. Use the API to automate detection in your workflows. Keep your deliverability secure by validating the entire email stack, including DKIM status, before every send.
Conclusion: Treat DKIM as a delivery critical control, not an afterthought
Expired DKIM keys don’t trigger bounces. They cause silent authentication failures, dropping emails into spam or outright rejection without notification.
Use MailTester’s bulk verification and inbox-placement testing to proactively detect expired keys and other infrastructure issues before they impact deliverability.
With 98.9% accuracy and 100 free verifications that never expire, you can audit your list and sender setup with no risk. Regular checks reduce bounce rates, protect sender reputation, and ensure consistent inbox placement.
Sources
- The number of top domains at DMARC enforcement grew from 233,249 in 2023 to 411,935 in 2026 — a 77% increase driven largely by mailbox-provider sender mandates. — EasyDMARC 2026 DMARC Adoption & Enforcement Report (2026)
- Since May 5, 2025, Microsoft Outlook requires SPF, DKIM, and DMARC from domains sending 5,000+ emails per day, rejecting non-compliant mail outright at the SMTP level with error 550 5.7.515. — Microsoft Outlook requirements (via MailOver bulk-sender requirements guide) (2025)
Keep reading
- Email authentication: SPF, DKIM, DMARC, BIMI and MTA-STS (complete guide)
- Coordinated DKIM Key Rotation Across Clusters in Multi-Tenant Email Infrastructure
- Reducing Email Delivery Latency Caused by DNS-Based DKIM Key Lookup
- Can Incorrect DKIM Signature Field Ordering Cause Email Rejection?
- Why Is My Tracking Pixel Not Loading Due to TLS Handshake Failure?
Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.
Frequently asked questions
How do I know if my DKIM key has expired?
Check the TXT record in DNS for the 'exp' tag. If it's in the past, the key has expired. MailTester detects this during verification.
Can a valid email address fail verification because of DKIM?
Yes. If the DKIM key is expired or missing, the address may appear invalid even if it’s correct and deliverable.
Does MailTester detect all types of DKIM issues?
Yes. It checks DNS for key presence, expiration, and correct formatting. It flags 'expired' and 'missing' keys.
Do I need to reconfigure DKIM after renewal?
Yes — replace the old public key in DNS with the new one, using the same selector. Wait for DNS propagation.
How often should I rotate DKIM keys?
Every 6 to 12 months is standard. Rotate keys before expiration to avoid delivery disruptions.
Can expired DKIM keys cause spam filtering?
Not directly. But repeated authentication failures reduce sender reputation, which can trigger spam filters.
What’s the best way to test DKIM after update?
Use MailTester’s inbox placement test or real-time API to verify that new keys are recognized and valid.
Why does MailTester have 98.9% accuracy?
It uses multiple validation layers, including real-time DNS checks, protocol-level testing, and machine learning to distinguish authentic issues.
Can I use MailTester with SendGrid or Mailchimp?
Yes. The tool integrates with SendGrid, Mailchimp, HubSpot, and Klaviyo. Use it to verify lists before importing or sending.
Do unused verification credits expire?
No. Any purchased credits never expire — you can use them when you're ready.
How do DKIM, SPF, and DMARC work together?
SPF checks the sending IP. DKIM checks the message signature. DMARC uses both to enforce policies and report failures.
What’s the impact of ignoring DKIM expiration?
Increased bounces, reduced inbox placement, and long-term damage to sender reputation.