# How to fix google dkim=neutral (body hash did not verify)

**URL:** <https://forum.dmarcian.com/t/how-to-fix-google-dkim-neutral-body-hash-did-not-verify/1284>\
**Category:** Community Area\
**Created:** [July 15, 2020, 9:46am UTC](https://forum.dmarcian.com/t/how-to-fix-google-dkim-neutral-body-hash-did-not-verify/1284 "2020-07-15T09:46:19Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rob76](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.dmarcian.com/rob76/32/100_2.png) [@Rob76](https://forum.dmarcian.com/u/Rob76)\
**Post date:** [July 15, 2020, 9:46am UTC](https://forum.dmarcian.com/t/how-to-fix-google-dkim-neutral-body-hash-did-not-verify/1284/1 "2020-07-15T09:46:19Z")

</div>

Ref Synology NAS \> DS118 \> Package \> Mail server  
SPF DKIM DMARC is activated \> DKIM Selector=key1

My ISP block Outgoing Port 25 to solve this  
by using Dynu SMTP Outbound RELAY Services  
I create Dynu Private and Public keys \> DKIM Selector=key2  
Finally I get my mail server running

Mails sending to [gmail.com](http://gmail.com) \> SPF=pass DKIM=neutral DMARC=pass  
Google Authentication-Results: dkim=neutral (body hash did not verify)

My DNS Zone setup, see below

QST How to fix google dkim=neutral (body hash did not verify)

Hope somebody can help me out…

Thx Robert (PL)

 ![DNS zone](https://canada1.discourse-cdn.com/flex036/uploads/dmarcian/original/1X/7bdedbcda0459a603d464b16e8a6bf2e3af2943d.png)

---

<div class="post-metadata">

**Author:** ![Asher](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.dmarcian.com/asher/32/104_2.png) [@Asher](https://forum.dmarcian.com/u/Asher)\
**Post date:** [July 17, 2020, 6:09pm UTC](https://forum.dmarcian.com/t/how-to-fix-google-dkim-neutral-body-hash-did-not-verify/1284/2 "2020-07-17T18:09:34Z")

</div>

Hello Rob76,

The issue could be several things, and it would likely be difficult to hone in the problem without a thorough review of the infrastructure at play.

The error dkim=neutral (body hash did not verify) implies there is modification in some ways occurring during the email path to delivery. First off, have you verified that the correct key pairs are being used? Meaning, the public key published in your DNS is the correct key for the pair used with the selector in question?

In this example, is the DKIM signing done by Dynu outbound gateway, or something else beforehand?

AM

---

<div class="post-metadata">

**Author:** ![Rob76](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.dmarcian.com/rob76/32/100_2.png) [@Rob76](https://forum.dmarcian.com/u/Rob76)\
**Post date:** [July 17, 2020, 7:29pm UTC](https://forum.dmarcian.com/t/how-to-fix-google-dkim-neutral-body-hash-did-not-verify/1284/3 "2020-07-17T19:29:24Z")

</div>

Thx for your reply,

AM, There is modification in some ways occurring during the email path to delivery.  
Agree, yes I try out add some commands like include: not working…

AM, Have you verified that the correct key pairs are being used?  
Yes, Tested with Dmarcian DKIM Records checker all ok.

AM, Is the DKIM signing done by Dynu outbound gateway, or something else beforehand?  
Dynu [DomainKeys Identified Mail (DKIM)](https://www.dynu.com/NetworkTools/DKIMWizard)  
**Step 2** : Save the private key on your email server for easy reference.

To solve my problem I change philosophy using the 2 DKIM key’s:  
01 Client connect to the server using IMAP-SSL Port 993 (secure connection).  
02 Dynu SMTP Relay using TLS Outgoing Port 587 (secure connection).  
03 Dynu DKIM Public key2 are in place to control mail transfer (Secure).  
Mains all communication IN and OUT the mail server is secure connected.

QST Do I still need the DKIM DMARC from my Synology mail server?  
I don’t thinks so, maybe I am wrong tell me…

So I disable DKIM DMARC in the mail server and remove DKIM key1, DNS TXT Record.  
From here I test Gmail again SPF DKIM DMARC resulting ALL PASS.

AM, It is working for now

Best regards Robert (PL)

---

<div class="post-metadata">

**Author:** ![alexsunny123](https://avatars.discourse-cdn.com/v4/letter/a/51bf81/32.png) [@alexsunny123](https://forum.dmarcian.com/u/alexsunny123)\
**Post date:** [January 30, 2022, 9:00am UTC](https://forum.dmarcian.com/t/how-to-fix-google-dkim-neutral-body-hash-did-not-verify/1284/4 "2022-01-30T09:00:37Z")

</div>

> [@Rob76](#):
>
> To solve my problem I change philosophy using the 2 DKIM key’s:  
> 01 Client connect to the server using IMAP-SSL Port 993 (secure connection).  
> 02 Dynu SMTP Relay using TLS Outgoing Port 587 (secure connection).  
> 03 Dynu DKIM Public key2 are in place to control mail transfer (Secure).  
> Mains all communication IN and OUT the mail server is secure connected.
> 
> QST Do I still need the DKIM DMARC from my Synology mail server?  
> I don’t thinks so, maybe I am wrong tell me…
> 
> So I disable DKIM DMARC in the mail server and remove DKIM key1, DNS TXT Record.  
> From here I test Gmail again SPF DKIM DMARC resulting ALL PASS.
> 
> AM, It is working for now
> 
> Best regards Robert (PL)

thanks for the awesome information.

---

<div class="post-metadata">

**Author:** ![alexsunny123](https://avatars.discourse-cdn.com/v4/letter/a/51bf81/32.png) [@alexsunny123](https://forum.dmarcian.com/u/alexsunny123)\
**Post date:** [November 28, 2022, 7:52am UTC](https://forum.dmarcian.com/t/how-to-fix-google-dkim-neutral-body-hash-did-not-verify/1284/5 "2022-11-28T07:52:44Z")

</div>

> [@alexsunny123](#):
>
> > [@Rob76](#):
> >
> > To solve my problem I change philosophy using the 2 DKIM key’s:  
> > 01 Client connect to the server using IMAP-SSL Port 993 (secure connection).  
> > 02 Dynu SMTP Relay using TLS Outgoing Port 587 (secure connection).  
> > 03 Dynu DKIM Public key2 are in place to control mail transfer (Secure).  
> > Mains all communication IN and OUT the mail server is secure connected.
> > 
> > QST Do I still need the DKIM DMARC from my Synology mail server?  
> > I don’t thinks so, maybe I am wrong tell me…
> > 
> > So I disable DKIM DMARC in the mail server and remove DKIM key1, DNS TXT Record.  
> > From here I test Gmail again SPF DKIM DMARC resulting ALL PASS.
> > 
> > AM, It is working for now
> > 
> > Best regards Robert (PL) [.](https://ometv.onl)[.](https://chatroulette.top)
> 
> thanks for the awesome information.

thanks my issue has been fixed.

---

<div class="post-metadata">

**Author:** ![felixabel](https://avatars.discourse-cdn.com/v4/letter/f/ea666f/32.png) [@felixabel](https://forum.dmarcian.com/u/felixabel)\
**Post date:** [March 22, 2023, 6:59am UTC](https://forum.dmarcian.com/t/how-to-fix-google-dkim-neutral-body-hash-did-not-verify/1284/6 "2023-03-22T06:59:58Z")

</div>

If you’re seeing the message “dkim=neutral (body hash did not verify)” in the Google Authentication-Results for your emails, it means that the DKIM signature in your outgoing emails is not valid. This can happen if there is an issue with the DKIM key, the DNS configuration, or the email server configuration.

Here are some steps you can take to fix the issue:

Check the DKIM selector: Make sure that you’re using the correct DKIM selector in your email server configuration and DNS records. In your case, you have two DKIM selectors (key1 and key2), so make sure that you’re using the correct selector in your outgoing emails.

Verify the DKIM key: Check that the DKIM key is valid and matches the one specified in your DNS records. You can use online DKIM validators to check the validity of your DKIM key.

Check DNS configuration: Make sure that your DNS records are correctly configured. In particular, check that the DKIM public key is correctly published in the DNS TXT record for your domain.

Test email deliverability: Send a test email to a different email service provider, such as Yahoo or Outlook, to see if the DKIM signature is valid. If the signature is valid for other email providers but not for Gmail, then it could be an issue with Gmail’s spam filters.

Contact Google support: If the above steps don’t solve the issue, you can contact Google support for further assistance.

I hope this helps you fix the issue with your DKIM signature! For other historical insights check out this [page](https://www.aroundrobin.com/services).
