The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →To authenticate Node.js transactional email, configure SPF for the message’s actual envelope sender (MAIL FROM) domain, enable DKIM signing and publish the matching public-key DNS record, then confirm that at least one passing mechanism aligns with the domain in the visible From header for DMARC. Nodemailer can sign messages itself or send through Amazon SES, which can manage DKIM for an SES identity.
What SPF, DKIM, and DMARC each verify
SPF and DKIM check different parts of a message. SPF evaluates whether the sending server is authorized for the envelope sender, or MAIL FROM, domain; it does not automatically evaluate the visible From domain. This distinction is described in RFC 7208, dated April 2014.
DKIM validates a cryptographic signature associated with a signing domain. The recipient uses a public key published in DNS to verify that signature. DMARC then checks whether SPF or DKIM passes and whether the domain used by that passing mechanism aligns with the visible From domain. At least one aligned, passing mechanism is needed for DMARC to pass. Amazon SES’s DMARC documentation explains these roles and alignment.
Choose where SPF and DKIM will be managed
First identify the domain shown in the message’s From header and the service that sends the email. Then follow that provider’s instructions for the identity and sending configuration you use. DNS record names and values are specific to the provider and signing method; do not copy another service’s selector, key, or SPF mechanism.
#1 Best Overall
| Choice | What to configure | Important distinction |
|---|---|---|
| Provider-default MAIL FROM | Use the provider’s documented default envelope-sender setup. | For Amazon SES, the default MAIL FROM uses an amazonses.com subdomain and has SPF implicitly configured. The visible From domain may still differ, so check DMARC alignment. AWS documentation |
| Custom MAIL FROM | Publish the SPF TXT and MX records SES requires at the custom MAIL FROM domain. | These records belong at the custom envelope-sender domain, not automatically at the visible From domain. AWS documentation |
| Provider-managed DKIM | Enable and verify the provider’s DKIM method for the sending identity; publish its supplied DNS records. | For SES, identity setup documents Easy DKIM and BYODKIM. The record details depend on the selected method. AWS identity configuration |
| Nodemailer-managed DKIM | Configure Nodemailer with the signing domain, selector, and private key; publish the corresponding public key in DNS. | You control the signing key and selector. Keep the private key secret. Nodemailer DKIM documentation |
Configure Nodemailer DKIM signing
Nodemailer’s DKIM option needs a domain name, a key selector, and the private key used to sign messages. The matching public key must be available at <selector>._domainkey.<domain>. Nodemailer supports settings for a transport and for an individual message; when both are supplied, the per-message configuration takes precedence. See the Nodemailer DKIM options for the current configuration shape.
Use the exact selector and domain associated with the key you intend to use. A DNS query for a different selector can appear to show that the key is missing even when another selector is published.
Rank #2
When configuring DNS, publish only the public key as directed. The private key belongs in the application’s protected configuration or secret store; it is used by Nodemailer to create signatures and must not be published in DNS or exposed to recipients.
Send through Amazon SES from Nodemailer
Nodemailer provides an SES transport using the AWS SDK v3. Its documented setup requires an initialized SESv2Client as sesClient and the SendEmailCommand class. Follow the current Nodemailer SES transport documentation for the code and SDK setup.
Rank #3
Choosing the SES transport does not by itself determine who signs DKIM. If SES handles signing, enable and verify DKIM through the SES identity workflow. If Nodemailer signs instead, ensure the signing domain and DNS key are configured as intended. Avoid layering an independent application-side DKIM setup on top of SES signing unless you have deliberately chosen and understand the resulting signing behavior. Nodemailer also documents other transport options, including SMTP, in its transports guide.
Publish and verify the DNS records
- Get the records from the chosen sender. For an SES identity, use its identity authentication workflow and selected DKIM method. For custom SES MAIL FROM, obtain the required SPF TXT and MX values. Enter the exact record names and values supplied by the provider in the authoritative DNS zone.
- Check a Nodemailer DKIM key at its exact selector path. For a Nodemailer-managed selector, run
dig TXT <selector>._domainkey.<domain>, replacing both placeholders with the configured values. Confirm that the expected public-key TXT response is visible. - Complete provider verification. Confirm the provider reports the identity or DNS configuration as verified before relying on it. Amazon SES says DNS changes for identity verification can take up to 72 hours to propagate; that is an SES-specific estimate, not a universal DNS guarantee. See SES identity creation and verification.
Check DMARC alignment before changing policy
Inspect the actual visible From domain, MAIL FROM domain, and DKIM signing domain (the signature’s d= value). SPF contributes to DMARC only when SPF passes and the MAIL FROM domain aligns with the visible From domain. DKIM contributes when the signature passes and its signing domain aligns with the visible From domain. Alignment can be relaxed or strict, so a relationship that aligns under relaxed mode may not align under strict mode.
Rank #4
Review the existing _dmarc.<domain> record and the domain’s sending sources before changing policy. SES shows a TXT-record example for _dmarc.example.com that includes p=quarantine; this is an illustration, not a universal recommendation. Choose policy values based on the domain’s sending inventory and monitoring needs. See Amazon SES’s DMARC guidance.
Quick Recap
Troubleshoot common authentication failures
- SPF passes, but DMARC fails: Check the domain used by MAIL FROM, not just whether the visible From domain has an SPF record. Then compare MAIL FROM with the visible From domain under the domain’s relaxed or strict alignment setting.
- DKIM lookup returns no key: Verify the configured selector and signing domain, then query
<selector>._domainkey.<domain>. A lookup using the wrong selector is not evidence that the configured key is absent. - The provider does not verify a new record immediately: Confirm the record was entered at the provider-specified name with the exact value, and allow for propagation. SES notes a possible delay of up to 72 hours for its identity DNS changes.
- A message has a passing SPF or DKIM result but still fails DMARC: A pass alone is insufficient; verify that the passing mechanism’s domain aligns with the visible From domain.
- Two signing configurations are present: Decide whether Nodemailer or the provider is meant to sign and check the actual signature behavior. Do not assume that enabling both produces the intended result.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Recommended Free Tools

