diagnostic · sourced answer

DKIM Fail Body Hash Did Not Verify Diagnostic

A DKIM body hash did not verify error occurs when the email body is modified after the DKIM signature was applied. The receiving server recalculates the hash of the received body and finds it does not match the hash stored in the DKIM-Signature header, leading to a verification failure.

Causes of Body Modification

The most common cause is an intermediary mail server or security appliance altering the message content. This includes adding trailing whitespace, inserting tracking pixels, appending legal disclaimers, or modifying line endings from CRLF to LF. Even a single character change in the body or the MIME structure will invalidate the cryptographic hash and trigger a fail result.

Canonicalization Settings

DKIM uses canonicalization algorithms to determine how much modification is allowed before a hash fails. Simple canonicalization is strict and fails on any change. Relaxed canonicalization ignores certain whitespace changes and header case differences. If your messages are frequently modified by relays, switching to relaxed canonicalization can prevent unnecessary failures.

MIME and Encoding Issues

Incorrect handling of Content-Transfer-Encoding can lead to hash mismatches. If a relay converts a message from quoted-printable to 8bit or modifies the charset, the resulting body hash will change. Ensure that the signing agent and the transport layers adhere to the standards defined in RFC 2045 to maintain body integrity.

Diagnostic Steps

To resolve this, examine the raw headers of the failed message. Compare the original sent body with the received body to identify exactly where the modification occurred. You can use SendHQ or its free tools (https://sendhq.cc/tools) to verify your current DKIM record configuration and ensure the public key is correctly published in your DNS.

Prevention Strategies

Avoid using mail relays that modify content. If you must use a service that appends footers, ensure the signing happens at the final hop of the delivery chain. Alternatively, implement ARC (Authenticated Received Chain) to preserve the original authentication results across multiple hops, allowing the final receiver to trust the original signature.

Questions teams ask

Does a body hash failure affect SPF?

No, SPF and DKIM are independent. A DKIM body hash failure does not invalidate an SPF pass, but it may impact DMARC alignment if DKIM was the primary authentication method.

Can a footer addition cause this error?

Yes, adding a corporate disclaimer or a mailing list footer after the message is signed changes the body content, which invalidates the DKIM body hash.

What is the difference between simple and relaxed canonicalization?

Simple is strict and fails on any change. Relaxed allows for minor changes in whitespace and header casing, making it more resilient to relay modifications.

Does changing the subject line cause a body hash fail?

No, the subject is part of the header. A subject change would cause a header hash failure, not a body hash failure.

Primary sources