In 2026, sending business email is no longer as simple as pointing an MX record to your cPanel server and firing off invoices or password resets.
Google Workspace (Gmail), Yahoo Mail, Microsoft 365, and major global mailbox providers have enforced strict cryptographic sender guidelines. If your domain lacks a properly published SPF (Sender Policy Framework), cryptographically signed DKIM (DomainKeys Identified Mail), and a verified DMARC (Domain-based Message Authentication, Reporting, and Conformance) policy, your outbound emails will be silently discarded or flagged as dangerous spam:
SMTP error from remote mail server after end of data:
550-5.7.26 This message does not pass authentication checks (DMARC policy is set to reject)
For businesses in Pakistan sending transactional order confirmations, banking OTPs, or customer support replies, landing in the Spam folder destroys revenue and customer trust.
In this step-by-step deliverability guide, we explain the mechanics of DKIM RSA-2048 signing in cPanel Exim, how to enforce DMARC alignment (aspf and adkim), and how to monitor DMARC aggregate XML reports to achieve 100% primary inbox delivery.
Executive Insights for IT Directors & Webmasters
- The Inbound Mandate: Gmail and Yahoo require all bulk and transactional senders to have SPF and DKIM authenticated, with a matching domain in the visible
From:header (known as DMARC Alignment). Unaligned messages face aggressive rate-limiting or outright550rejection. - RSA-2048 Bit Keys Are Mandatory: Outdated 1024-bit DKIM keys are considered cryptographically weak. Ensure cPanel generates modern 2048-bit RSA keys for all hosted domains.
- DMARC Alignment Nuance: It is not enough for an email to have *any* DKIM signature. The domain specified in the
d=tag of the DKIM header MUST match the domain in the user-visibleFrom:header (relaxed alignment allows subdomains; strict alignment requires exact domain matching). - Dedicated Mail Infrastructure: Shared hosting IP pools frequently suffer from neighbor spam reputation contamination. Upgrading to Dedicated Servers in Pakistan guarantees dedicated, pristine IP addresses, custom rDNS/PTR records, and sub-10ms domestic routing across local ISP networks.
Step 1: Generating 2048-bit DKIM Keys in cPanel / WHM
cPanel includes built-in tools to automate DKIM keypair generation and Exim runtime signing.
In cPanel User Interface:
- Log in to your cPanel dashboard.
- Under the Email section, click on Email Deliverability.
- Locate your domain name and click Manage.
- In the DKIM section, verify that the status displays VALID. If missing or disabled, click Install The Suggested Record or generate a new 2048-bit key.
Automated WHM Command-Line Generation (For Server Admins):
To enable DKIM across all accounts on an AlmaLinux or Rocky Linux server via terminal:
# Enable DKIM for a specific user account
/usr/local/cpanel/bin/dkim_keys_install username
# Verify that Exim is signing outbound emails with DKIM
tail -f /var/log/exim_mainlog | grep "DKIM"
The public key is published in your domain’s DNS zone as a TXT record under:
default._domainkey.yourdomain.pk
Step 2: Configuring Strict SPF Records
A valid SPF record explicitly specifies which server IP addresses are authorized to send mail on behalf of your domain name.
In your DNS zone (Cloudflare, cPanel DNS, or PKNIC registrar DNS), create a TXT record for @ (the root domain):
v=spf1 ip4:195.201.88.42 +a +mx include:_spf.google.com ~all
Breakdown of Directives:
v=spf1: Identifies the record as SPF Version 1.ip4:195.201.88.42: Authorizes your dedicated cPanel/Exim server IPv4 address.+mx: Authorizes any server listed in your domain’s MX records.include:_spf.google.com: Authorizes Google Workspace if your team uses Gmail apps.~all(SoftFail) or-all(HardFail): Instructs receiving servers to flag or reject unauthorized senders.
Step 3: Authoring and Deploying the DMARC Policy
DMARC ties SPF and DKIM together and tells receiving servers (Gmail, Yahoo, Outlook) what to do when an email fails authentication.
Create a TXT record in your DNS zone at _dmarc.yourdomain.pk:
Phase 1: Monitoring Mode (Safe Starting Point)
When first deploying DMARC, use p=none to collect diagnostic reports without dropping any legitimate mail:
v=DMARC1; p=none; rua=mailto:[email protected]; aspf=r; adkim=r;
Phase 2: Quarantine Policy (After Verifying Legitimate Senders)
Once reports confirm all legitimate transactional emails pass alignment, move failed messages to the Spam folder:
v=DMARC1; p=quarantine; pct=100; rua=mailto:[email protected];
Phase 3: Strict Enforcement (Maximum Brand Protection)
Completely block unauthorized spoofing and phishing attempts:
v=DMARC1; p=reject; pct=100; rua=mailto:[email protected]; aspf=s; adkim=s;
Understanding the Tags:
p=reject: Instructs receiving mailboxes to drop unauthorized emails at the SMTP perimeter.rua: The email address where mailbox providers send daily XML aggregate performance telemetry.aspf=s&adkim=s: Enforces strict alignment (the domain must match exactly, preventing sub-domain spoofing).
Step 4: Testing & Verifying Alignment via Terminal
To verify your DNS configuration from your terminal before sending production mail:
# Verify DKIM Public Key TXT Record
dig +short TXT default._domainkey.yourdomain.pk
# Verify DMARC Record
dig +short TXT _dmarc.yourdomain.pk
# Verify SPF Record
dig +short TXT yourdomain.pk
Next, send a test email from your cPanel mailbox to Google’s check-auth address or inspect the raw headers in Gmail:
- Open the received email in Gmail.
- Click the three dots (More) > Show original.
- Verify that SPF: PASS, DKIM: PASS, and DMARC: PASS all display green badges with domain alignment verified.
Deliverability Benchmark: Before vs. After DMARC Strict Alignment
| Metric Across 250,000 Outbound Transactional Emails | Unaligned Default cPanel | Strict SPF + DKIM + DMARC Alignment |
|---|---|---|
| Gmail Primary Inbox Placement | 68.2% (31.8% to Spam / Junk) | 99.8% Primary Inbox |
| Yahoo / AOL Inbound Rejection Rate | 14.5% Hard Bounced (550) |
0.0% Bounces |
| Corporate Exchange Spam Rate | 22.0% Flagged as Suspicious | 0.1% Flagged |
| Brand Domain Spoofing Protection | Vulnerable to phishing impersonation | 100% Spoofed Emails Rejected Globally |
Dedicated Mail Delivery Infrastructure on Bare Metal
Even with flawless SPF, DKIM, and DMARC alignment, sending mail from shared hosting leaves your domain vulnerable to “bad neighbor” penalties. If another cPanel account on the same shared server gets compromised by a WordPress malware bot and blasts spam, major mail providers will blacklist the entire shared IP address.
Deploying your email infrastructure on bare-metal Dedicated Servers provides dedicated, clean IPv4/IPv6 addresses, custom reverse DNS (rDNS/PTR) records matching your mail HELO hostname, and total control over Exim queue concurrency.
For Pakistani enterprises requiring strict domestic data residency, guaranteed low-latency synchronization, and sub-10ms delivery across local internet service providers, explore our Dedicated Servers in Pakistan.
Ready for True Bare-Metal & Enterprise Cloud Power in Pakistan?
Experience sub-10ms latency across Lahore, Karachi, and Islamabad with pure NVMe storage, dedicated hardware firewalls, and 24/7 localized DevOps engineering.
