Antispam MxGuard Business General help New

Enabling DKIM signing and understanding ARC sealing

leah.kaur 10 May 2026, 21:06

Two deliverability features affect how the world treats mail that has passed through MxGuard.

ARC sealing (automatic). Because MxGuard forwards your mail, it changes the sending path — which can break SPF and DMARC checks at the final destination. To prevent that, MxGuard applies RFC 8617-compliant ARC sealing (openarc), preserving the original authentication results across the forwarding hop and adding Authentication-Results headers with the AuthservID mx1.mxguard.uk. You do not need to configure this; it happens on every forwarded message.

Outbound DKIM signing (optional). MxGuard can DKIM-sign mail per domain using a provided selector. Most customers already sign at their own mail server, in which case you can leave this off; enable it if you want MxGuard to add the signature instead.

Together with SPF and DMARC enforcement, these ensure that legitimate mail relayed through MxGuard continues to authenticate correctly at the receiving end.

0 comments

Sign in with your TDesk account to comment.

← Back to all posts