Hello Mark! DKIM signing will unfortunately not work for this domain if traffic is going through another device and having its headers/body modified. This is due to the body/headers being hashed, then modified after leaving the server, which invalidates the DKIM signature. To correct that you'll want to adjust your Firewall MTA settings so that modifications are not being made.
That being said, I could see benefit in being able to export the DKIM key for inclusion in the firewall, so I'm going to get a feature request submitted on this for you and will follow up with you when I hear back from our Product Management team.
In the meantime I hope that the reply here may help to stimulate further responses as there may be administrators out there that have made this work. Have a good one!
Kyle Kerst
IT Coordinator
SmarterTools Inc.
www.smartertools.com