Reseller playbook · Intermediate · 15 minutes
How to set up DKIM signing — DKIM Across a Reseller Account, Selector by Selector
Every cPanel you create signs its own mail, which means every client you take on is one more key whose whole lifecycle is now yours.
Straight answer first
Treat DKIM as an account-creation default rather than a task: enable it as the package builds so every cPanel you hand over signs from its first message, and the only recurring per-client work is chasing selector records out of third-party platforms.
Fifteen minutes covers one domain by hand. The decisions worth making once are the selector name, who holds the private key the day a client leaves you, and whether your clients ever see the Email Deliverability screen at all.
Written by the Hosting Seller staff · Checked 24 August 2026
Intermediate
Skill assumed
5
Stages per account
Free
Support for you and them
Tested
Tested on the reseller stack
Written for the reseller rather than the mailbox owner. It assumes you create accounts in WHM, that some of your clients have their own marketing agencies, and that anything you do forty times needs to be a default rather than a habit.
The awkward part of DKIM in a reseller estate is not cryptography. It is administration: keys you own on domains you do not, and records that live in zones other people can edit.
What the client sees, and what they should not
In a client-facing cPanel, Email Deliverability is a green tick or a red warning with a suggested DNS record printed beside it. That screen is one of the most common routes by which a client discovers the hostname of the machine their site actually sits on, because the record and the server's own name are shown together.
If your handover model gives clients cPanel access, decide deliberately whether that icon stays in the feature list you assign. Removing it means you own every DKIM question that ever arises; leaving it means the more curious clients will read a hostname off the screen. Either is defensible. Choosing by accident is not.
Doing it once, in the package
Switch signing on as the account is created rather than when a client complains. The key pair exists before the first message leaves, the record is already in the zone if your nameservers answer for the domain, and a recurring support task quietly becomes a property of the package instead.
Where DNS lives elsewhere — a client whose agency runs their zone on a third-party service, typically — the key is generated here and published there. Put that case in the onboarding script, because it is the one path where creating the account does not finish the job.
Third-party senders are the recurring cost
Each platform a client sends through signs with its own key and hands over its own selector record, frequently as a CNAME rather than a TXT. Selectors coexist happily, so the work is administrative: chasing the client's agency for a value and getting it into the right zone before anyone notices.
Absorb that cost or charge for it, but count it. Three platforms per client across forty accounts is a hundred and twenty records you are now responsible for, and every one of them is something a tidy-minded stranger can delete from a DNS panel on a Friday afternoon.
Keys, migrations and the day a client leaves
DKIM keys are not passwords and do not want a rotation schedule. Rotate on compromise or on a genuine provider migration, because every needless rotation opens a window in which mail already in flight fails alignment for no benefit to anybody.
When a client moves away, the private key stays on your server and the new host issues its own. Say that in the offboarding note, in writing. A client whose mail starts failing a week after leaving will ring you first regardless of where the fault actually sits.

Why this is shorter on a reseller account here
The guides on this shelf are written against the reseller platform we sell: WHM for you, a cPanel of their own for every client, private nameservers under your brand and packages you name yourself.
Mailboxes on the client's own domain are part of the account, with webmail, IMAP, POP and SMTP, so mail is never an upsell you have to explain.
- Account-creation defaults over per-ticket fixes
- The client's view of the panel, called out
- The administrative cost counted per account
- Real people answering for you and for them
Why Hosting Seller
On every plan, as standard
A default, not a chore
Puts signing into the package build so no account you hand over ever ships unsigned.
The client's screen, described
Says exactly what a client sees in Email Deliverability and what that screen gives away.
Selector naming, decided once
Weighs a branded selector against a portable one, from the point of view of the migration that follows.
Key ownership in writing
Names who holds the private key at offboarding, so the argument happens before it matters.
The third-party tax, counted
Multiplies the per-client record chasing by your account list, so the cost is visible before it is a surprise.
Answers for two audiences
Support here fields questions from you and from your clients, at any hour of the day.
First Steps
From choosing to live
- 1
Leave it enabled in the package, not in the ticket queue
Account creation in WHM can leave DKIM on by default. Every cPanel you build then signs from its first message, and you never field the question 'why is my mail unsigned' about an account you set up yourself.
- 2
Pick a selector you can live with for years
The panel's default selector is portable and boring, which is the point. A selector named after your brand looks tidy until a client migrates and asks their new host to reproduce it verbatim.
- 3
Publish the record where the domain is actually answered
If your nameservers hold the zone, the panel writes it. If the client's agency holds it, export the value and send it with a screenshot of the destination field — a key truncated on the way is the standard failure on that path.
- 4
Gather the third-party selectors during onboarding
Newsletter platforms, CRMs and helpdesks each hand over their own record. Collect them while the client still has the logins to hand, not during an incident when nobody can remember who set the platform up.
- 5
Verify against an outside mailbox, then log it
Send to a mail-testing service, or read the headers on a message delivered to a mainstream provider: you want dkim=pass showing the client's domain, not yours. Note every live selector in the client file.
In the Box
Packed with every plan
- A cPanel of their own for every client, WHM for you
- Private nameservers answering under your own brand
- Packages you build and name yourself
- Mailboxes on the client's own domain, webmail included
- Spam and virus filtering fitted to every mailbox
- Daily backups running across every client account
- Free SSL on every client site, reissued before it lapses
- Softaculous in every account you create
- Upgrades applied to the account in place, no plan move
- One-click installs for WordPress and 400+ other applications
Across the Counter
Things people ask us all the time
Should my clients be able to see the Email Deliverability screen at all?
That is a feature-list decision, and worth taking on purpose. Leaving it visible pushes simple DNS questions back to the client but also shows them the server hostname beside the suggested record. Removing it keeps the account looking entirely like yours and moves every mail question onto your desk.
When a client leaves, whose DKIM key is it?
The private half stays on the server it was generated on, which is yours, and the receiving host issues a fresh pair with its own selector. Write that into the offboarding note so the client understands their new provider has to redo the record rather than inherit it.
How much of this can carry my own branding rather than a supplier's?
The parts clients touch. Nameservers run privately under your own domain, the packages carry the names and limits you choose, and the accounts you create are yours to present as your product. What sits underneath stays a commercial detail between us.
Do client accounts include mailboxes, or is mail sold separately?
Mailboxes on the client's own domain come with the hosting, with webmail plus IMAP, POP and SMTP, and spam filtering fitted as standard. There is also standalone email hosting for a client whose website is parked somewhere you do not control.
Read next
Domain Names
Register and transfer client names in one place — year one free with annual hosting.
WordPress Hosting
WordPress hosting for the client sites you look after — LiteSpeed, staging and daily backups.
Moving your site to another host? Start with this checklist.
A step-by-step order of work for a move your visitors never spot: which files to copy first, how to carry email across without losing one message, the right moment to repoint DNS, and the two mistakes behind nearly every hour of downtime people ring us about.
Sell hosting under your own name.
Overselling on from day one, packages you name yourself, and a seven-day window to test the whole thing.
See Domain Names plans