7 min read Diesen Artikel auf Deutsch lesen
GoDaddy DKIM Setup for Brevo Senders
The short answer
To set up GoDaddy DKIM for Brevo, open your domain's authentication screen in Brevo and copy the DKIM record exactly: type, host and value. Then add it in GoDaddy's DNS records view. Enter only the host part, such as the selector._domainkey label. GoDaddy appends your domain itself. Wait for the TTL to pass, check it with dig, then click verify in Brevo. This only works if GoDaddy hosts your nameservers.
In this article
- What does GoDaddy DKIM mean if you send through Brevo?
- How do I add the Brevo DKIM record in GoDaddy DNS?
- Why can't Brevo find my GoDaddy DKIM record?
- How do I check that my GoDaddy DKIM record is live?
- Do I need SPF and DMARC on GoDaddy as well as DKIM?
- How does GoDaddy DKIM fit into sending video email with EmailFlow OS?
- Questions people ask
What does GoDaddy DKIM mean if you send through Brevo?
GoDaddy doesn't sign your mail, even though a lot of people assume it does. DKIM (DomainKeys Identified Mail, RFC 6376) works like this: the sending server, in this case Brevo, signs each message with a private key. The receiving server then looks up the matching public key in DNS at selector._domainkey.yourdomain.com. When GoDaddy hosts your DNS, its only job is to publish that public key. So "GoDaddy DKIM" really means putting Brevo's DKIM record into GoDaddy's DNS zone. The record lives at GoDaddy, and the signing happens at Brevo. Once the record is published and Brevo has verified it, Brevo can sign with d=yourdomain.com. That's the domain DMARC compares against your visible From address. If you skip the record, Brevo can't sign as your domain, and the DKIM check DMARC relies on fails. One thing doesn't carry over: DKIM set up for GoDaddy's own mailbox product or for Microsoft 365 covers only mail sent through those services. Every sending service needs its own selector and key, so Brevo needs a separate record.
How do I add the Brevo DKIM record in GoDaddy DNS?
Start in Brevo, not GoDaddy. Brevo creates the key pair and shows you which records to publish. The record types and selector names can differ depending on when a domain was authenticated. Copy what your Brevo screen shows instead of using values from an old tutorial.
- In Brevo, open the senders and domains settings, pick your sending domain and open its authentication records. Leave that tab open.
- In GoDaddy, open your Domain Portfolio, select the domain and go to its DNS records.
- Click Add New Record and choose the exact type Brevo lists (TXT or CNAME).
- In Name/Host, enter only the part before your domain, for example the selector._domainkey label. Don't include yourdomain.com. GoDaddy adds it for you.
- Paste the value exactly as shown, with no extra spaces or quotes. Leave TTL at the default of 1 hour unless you have a reason to change it.
- Save, wait at least one TTL period, then return to Brevo and run the verification.
Why can't Brevo find my GoDaddy DKIM record?
When Brevo reports the DKIM record as missing or invalid, the cause is nearly always one of a few mistakes. You can check each one directly in DNS:
- Doubled domain: the full hostname went into GoDaddy's Host field, so the record got published at selector._domainkey.yourdomain.com.yourdomain.com.
- Wrong nameservers: the domain is registered at GoDaddy but uses nameservers somewhere else, such as a CDN or your web host. Edits in GoDaddy's DNS panel are then never served. The records have to go wherever the NS records point.
- Wrong record type: you entered a CNAME value as TXT, or the other way round, so the lookup returns nothing usable.
- Truncated key: a 2048-bit public key is longer than the 255-character limit per DNS string (RFC 1035). If the value got cut off while pasting, the key won't parse.
- Not propagated yet: resolvers still have the old answer cached until the TTL runs out. GoDaddy says DNS changes can take up to 48 hours.
How do I check that my GoDaddy DKIM record is live?
Look it up yourself before you click verify in Brevo. For a TXT-based key, run dig TXT selector._domainkey.yourdomain.com +short, using the selector Brevo gave you. The answer should begin with v=DKIM1 or at least contain k=rsa and p= followed by the key. For a CNAME-based setup, run dig CNAME selector._domainkey.yourdomain.com +short. It should return the target hostname Brevo listed. An empty answer means the record isn't live at that name, so check the Host field and your nameservers. Run dig NS yourdomain.com +short to find out who actually serves your zone. If the answer isn't domaincontrol.com (GoDaddy's nameservers), your GoDaddy DNS panel is the wrong place to make changes. Once DNS looks right, send a test message from Brevo to a mailbox you control and open the raw headers. Authentication-Results should show dkim=pass with header.d=yourdomain.com. If it shows the Brevo domain in d= instead of yours, the message wasn't signed with your key.
Do I need SPF and DMARC on GoDaddy as well as DKIM?
Yes. Gmail and Yahoo have required both since February 2024 for anyone sending more than 5,000 messages a day to their users. Under that volume, they still expect SPF or DKIM. There are two GoDaddy-specific traps. The first is SPF. A domain can publish only one v=spf1 TXT record. GoDaddy often creates one automatically for its own mail products, so if Brevo lists an SPF include, add it to the existing record instead of creating a second one. Two SPF records produce a permerror. SPF also has a limit of 10 DNS lookups (RFC 7208), and stacking includes can push you over it. The second trap is DMARC. Add a TXT record with host _dmarc and a value such as v=DMARC1; p=none; rua=mailto:reports@yourdomain.com. p=none only monitors, so read the aggregate reports before you move to quarantine or reject. Keep in mind that a record only authenticates mail. Receiving servers still weigh volume, complaints and history, which is why domain warm-up matters after DNS is done.
If you're pacing a new domain, our guide to email warm-up for Brevo senders goes through the ramp, and the article on cold email follow-up timing covers Gmail's bulk-sender thresholds and RFC 8058 one-click unsubscribe.
How does GoDaddy DKIM fit into sending video email with EmailFlow OS?
EmailFlow OS sends through your own Brevo account and your own sending domain, not through a shared platform address. That's why your GoDaddy DKIM record matters. You record one video and upload it to EmailFlow OS. Then you connect your Brevo account and sending domain and import your prospect list into EmailFlow OS. EmailFlow OS creates a personalised version of that recording for each recipient, not one per company, and sends each version from your inbox through Brevo. Every message therefore carries your domain in the From address. Once Brevo's DKIM record at GoDaddy is verified, Brevo can sign those messages with d=yourdomain.com, and that alignment is what DMARC checks. The sender reputation is yours: you own the domain, the DNS and the Brevo account. The downside is that a broken record at GoDaddy affects every send until you fix it. Finish the DNS setup and confirm dkim=pass before importing a list. The walkthrough on how to send video email with EmailFlow OS covers the connection steps that follow.
Questions people ask
- What do I put in the GoDaddy Host field for DKIM?
- Enter only the part in front of your domain, for example selector._domainkey, using whatever selector Brevo shows you. GoDaddy adds yourdomain.com automatically. If you type the full hostname, the record ends up at selector._domainkey.yourdomain.com.yourdomain.com, and Brevo's verification won't find it.
- How long does GoDaddy DKIM take to work?
- New records often resolve within the default TTL of 1 hour, and GoDaddy says changes can take up to 48 hours. If dig returns the record from domaincontrol.com nameservers but Brevo still can't verify it, a resolver probably has an older answer cached. Wait one TTL period and try again.
- Can I have more than one DKIM record on GoDaddy?
- Yes. DKIM records are keyed by selector, so selector1._domainkey for Microsoft 365 and a Brevo selector can exist side by side without conflict. SPF is different: a domain can publish only one v=spf1 record, so extra senders are added as includes within that single record.
- Does GoDaddy's own DKIM cover mail sent through Brevo?
- No. A DKIM key belongs to the service that holds the private key. GoDaddy's or Microsoft 365's DKIM signs only mail sent through those services. Brevo signs with its own key, so it needs its own record published in your GoDaddy zone.