Symptom
You have questions related DKIM activation for email domains.
Environment
SAP S/4HANA Cloud Public Edition
Resolution
1. What is DKIM, is it mandatory to do DKIM activation?
DKIM is an e-mail authentication technique involving a digital signature that allows the receiver to check that an e-mail was sent and authorized by the owner of that domain. The DKIM signature is a header that is added to the message and is secured with encryption. By enabling DKIM you can make sure messages aren't altered in transit between the sending and receiving email servers. It uses public-key cryptography to sign emails with a private key as it leaves a sending email server. Custom domains which are used for internal purposes like workflow item, Purchase order approval, PR approval, etc., should be enabled the DKIM setup. This will ensure that emails sent through your SAP S/4HANA system are secure.
2. How do I request for a DKIM Key Activation?
To request the setup and activation of DKIM for your business emails sent by the system, you need to:
1. Log on to SAP for Me.
2. Under Dashboards, choose Services and Support.
3. On the Service Requests tab, choose New Service Request. The system displays the New Service Request dialog.
4. Choose the Partner & Other Cloud Services radio button, then choose Create Service Request.
5. Select the catalogue as “S/4HANA Cloud” from the dropdown option and click on go.
6. Search for SAP S/4HANA Cloud: DKIM enablement for custom sender domains and open the service request.
7. Read the service-related information and choose Add Service.
8. Under Tenants, specify the relevant tenant for your SAP S/4HANA Cloud Public Edition system (recommended: customizing tenant).
9. In the Enter the Domain Name field, enter a domain name according to your business requirements.
10. A confirmation text for your service request is displayed. Under Confirmation, select the checkbox to confirm that you meet the prerequisites for the service, or you agree to the guidelines as per the SAP Standards, and that you are ready to proceed with the service.
11. Choose Submit to send your service request to SAP
Result: You've successfully submitted the service request to enable DKIM for your email sender domain.
Note: Please follow the instructions mentioned in order to make sure that the request submitted by you is processed and not cancelled due to incorrect inputs :
“Please enter the sender domain. (Example: ondemand.com)
Don't use prefix "@" while providing the domain name.”
3. How the process flow looks like for DKIM Activation?
-
- DKIM key will be generated. Process of DKIM key generation will take approximately 3-4 hours.
- Once the key is generated, SAP team will update the public key details as an attachment in the service request.
- To update DNS, kindly check with your local network/mail server team for assistance. DNS is unique and we have different DNS providers in the market, hence SAP is not have a control over it.
- We have captured few screenshots based on one of the reference customer’s DNS in SAP note 3231960. Please note that it is only for reference purpose and your DNS settings might be different than the captured one.
- Once the DNS is updated, activation is done automatically.
- For more details on validation of the activation , please refer the KBA : 3231960 - How to Update the DNS with the provided DKIM Key - SAP for Me
4. How do I know I have maintained the DKIM key correctly?
Sometimes it may happen that customer will update only half of the key in their DNS. Actual key should end with "DAQAB". Incase if you are getting an error as 'TXT record should not contains more than 255 characters', then please split the keys in a single TXT record as suggested in the DKIM keys and TXT record limits and please inform your network/mail server team that DKIM keys are 2048 bit. They will help you on this.
5. How does DKIM ensure email integrity?
DKIM signs messages with a private key to prevent alteration during transmission between sending and receiving servers.
6. I am not able to receive emails even after DKIM Key Activation. What should I do?
If emails are not delivered to regular inbox, you can check respective Junk/spam folder if emails are received there.
After DKIM Setup, to prevent emails from going into spam please publish SPF Record as per section "4.2.6 Publish SPF Record for Sender Domain" of guide - Setting Up Output Management (1LQ)
If this is not the case, kindly create a ticket to XX-S4C-OPR-SRV Component and provide below details for the failed email:
- Sender Address
- Recipient Address
- Time
- Date
- Subject
7. What is the resolution if mails are not being received by the recipients which are sent from custom sender domains after mail server migration?
Please update the DNS with the provided DKIM Key. Customers can refer KBA How to Update the DNS with the provided DKIM Key for detail.
8. Is it possible to generate 1 K Bit key which are less than 250 characters?
SAP can generate 1024-bit DKIM key which will be less than 250 characters. But 1024 bit keys are kind of outdated and SAP is not recommending to use it. If you still want to go with 1024 bit key, then there might be security related concerns and SAP won't be responsible for that. Because we are doing this against standards.
Before generating the 1024 bit key, a screen sharing session will happen with customer to understand the issue, Based on that SAP can ask for internal security approvals to generate 1024 bit key.
9. How many domains can be added?
SAP supports multiple domains. Please note:
- Each domain requires a separate DKIM activation request.
- Separate DNS configuration is mandatory for each domain.
10. Are any communication arrangements required after DKIM setup?
Communication Arrangements are generally not required for standard email sending.
They are only necessary if you have custom integrations, such as APIs or external mail services. For standard email output, no additional arrangements are needed.
11. Can we connect On-prem SMTP server to S/4 HANA Public Cloud?
This functionality is not supported. SAP does not expose SMTP configuration for connecting on-prem SMTP servers to the S/4HANA Cloud system.
12. Is it possible to have access to the Amazon SES mailbox (SMTP)?
In SAP S/4HANA Public Cloud, emails are sent using SAP-managed infrastructure via Amazon SES. Direct access to the SES mailbox is not available.
For more information, refer to: SAP S/4Hana Cloud mail server configuration
See Also
3223182 - Mandatory DKIM setup - SAP S/4HANA Cloud Public Edition 2208
3223594 - DKIM Enablement in S/4HANA and SMC Systems
Keywords
DKIM activation, SPF Record, Email delivery , KBA , XX-S4C-OPR-SRV , S/4HANA Cloud service requests , How To
SAP Knowledge Base Article - Public