WKD – automatic key discovery
WKD (Web Key Directory) helps compatible email clients find a public OpenPGP key using the recipient's email address. You do not have to send the key file manually to every contact.
WKD does not create keys, encrypt messages or distribute S/MIME certificates. The client decides how to retrieve and accept a key.
With a Meil address
For addresses on Meil's standard domains, including onmeil.eu, Meil manages the service's DNS and HTTPS. You only need to publish your public key. An account without a published key has no key to retrieve.
With a custom domain
WKD is never enabled automatically for customer domains. Ordinary email, MX, SPF and DKIM can work without WKD being configured.
A workspace administrator can request WKD under Domains in the administration portal. Meil then displays this record:
| Field | Value |
|---|---|
| Type | CNAME |
| Name/host | openpgpkey |
| Target/value | openpgpkey.meil.no |
| TTL | 300 or your provider's default |
You create the record at your DNS provider. Meil does not ask for DNS credentials and never changes customer DNS. Do not create an A or AAAA record with the same name, and do not change MX.
Choose Check and fix setup after saving the record. When at least two public DNS resolvers see the correct CNAME, Meil automatically handles the certificate, routing and public verification. The status becomes Active only after the HTTPS endpoint is verified. Users on the domain can then publish their public key.
Awaiting your DNS means the record is missing or not visible yet. Needs attention means DNS points elsewhere or Meil could not complete the certificate or routing; compare the displayed record and retry. Disabling WKD stops new discovery and withdraws published keys. Copies already downloaded by email clients may remain there.
If a key cannot be found
Check that you are looking up the exact address for which the key is published. Check that the key remains published and the domain has WKD. Clients may cache old keys; try the client's refresh or key-discovery function.
A key discovered through WKD is not a guarantee of a person's identity. Check unexpected key changes with your contact. For troubleshooting, give support the domain, client version and error message — never the private key.