technical · sourced answer

DKIM DomainKeys Identified Mail Explained

DKIM is an email authentication method that allows a sender to cryptographically sign an email header. This signature proves that the email was authorized by the domain owner and that the message content was not altered during transit. Receiving servers verify the signature using a public key published in the sender's DNS records.

Mechanical Process

DKIM operates using a public key infrastructure. The sending server uses a private key to create a digital signature of specific message headers and the body. This signature is attached to the email as a DKIM-Signature header. The receiving mail server extracts the domain and selector from this header, fetches the corresponding public key from the DNS record, and decrypts the signature to verify the hash of the message content.

Importance for Senders

DKIM provides a layer of trust that SPF cannot offer alone because it survives email forwarding. While SPF validates the sending IP, DKIM validates the message itself. This prevents spoofing and reduces the likelihood of messages being flagged as spam by major providers. It is a prerequisite for implementing DMARC and BIMI, which rely on DKIM alignment to verify sender identity.

Operational Notes and Mistakes

Common failures occur when the private key is rotated without updating the DNS public key, or when a mail relay modifies the message body or headers after signing, which breaks the cryptographic hash. Senders should use selectors to manage multiple keys for different services. You can use SendHQ free tools (https://sendhq.cc/tools) to verify your current DNS configuration.

Concrete Example

A sender configures a selector named google. The DNS record at selector._domainkey.example.com contains the public key. When an email is sent, the DKIM-Signature header specifies s=google and d=example.com. The receiver looks up the TXT record at that specific DNS path to find the key needed to validate the signature.

DKIM and DMARC Alignment

For DMARC to pass, the domain in the DKIM signature must align with the domain in the From header. This is called DKIM alignment. If the signature is valid but the domain does not match the From address, the DKIM check passes but the DMARC check fails, potentially leading to delivery issues depending on the defined policy.

Questions teams ask

Does DKIM encrypt the email body?

No, DKIM does not encrypt the content for privacy. It creates a cryptographic hash to ensure integrity and authenticity, meaning the receiver can verify the sender but the message remains readable.

What happens if a DKIM signature is invalid?

An invalid signature may cause the email to be marked as spam or rejected entirely, as it suggests the message was tampered with or the sender is unauthorized.

Can I have multiple DKIM keys?

Yes, by using different selectors, you can have multiple DKIM keys for different sending services or rotate keys without interrupting mail flow.

Primary sources