---
title: DKIM Signature Header Explained | SendHQ
description: Technical overview of the DKIM-Signature header, explaining how cryptographic signatures verify email integrity and sender identity.
canonical: https://sendhq.cc/terms/dkim-signature
last-updated: 2026-08-26
---
# DKIM Signature Header Explained

A DKIM signature header is a specific field added to an email message by the sending server. It contains a cryptographic hash of the message body and selected headers, allowing the receiving mail server to verify that the email was authorized by the domain owner and has not been altered during transit.

## Mechanical Operation

The sending server uses a private key to create a digital signature of the email content. This signature is inserted into the DKIM-Signature header. The receiving server retrieves the corresponding public key via a DNS TXT record. By decrypting the signature with the public key and comparing the resulting hash to a fresh hash of the received message, the receiver confirms the message is authentic.

## Importance for Senders

DKIM provides a layer of trust that SPF cannot, as it survives email forwarding. It proves that the content of the message remains intact and that the domain listed in the signature is the actual sender. This reduces the likelihood of messages being flagged as spam or spoofed, which is critical for maintaining a positive sender reputation.

## Common Operational Mistakes

A frequent error is failing to include critical headers in the signature, leading to verification failure if a relay modifies those headers. Another common issue is key rotation failure, where the private key is updated on the server but the public DNS record remains outdated. You can use SendHQ free tools (https://sendhq.cc/tools) to verify your current authentication status.

## Header Example

A typical header looks like: DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=example.com; s=selector1; h=from:to:subject:date; bh=hash_of_body; b=digital_signature_value. The d tag specifies the domain, s specifies the selector for the DNS record, and bh contains the body hash.

## Verification Process

When a message arrives, the receiver parses the DKIM-Signature header to find the domain and selector. It queries DNS for the public key at selector.\_domainkey.example.com. If the cryptographic check passes, the message is marked as DKIM-pass. If the hash does not match or the key is missing, it results in a DKIM-fail or neutral result.

## Questions teams ask

**Does DKIM encrypt the email body?**

No, DKIM does not encrypt the content for privacy. It provides a digital signature to ensure integrity and authenticity, meaning the content remains readable but cannot be changed without breaking the signature.

**What happens if a DKIM signature is invalid?**

An invalid signature may cause the receiving server to increase the spam score of the email or reject it entirely, depending on the DMARC policy configured by the domain owner.

**Can an email have multiple DKIM signatures?**

Yes, an email can have multiple signatures. This often happens when a message passes through a mailing list or a forwarding service that adds its own signature while preserving the original.

## Primary sources

- [RFC 6376: DomainKeys Identified Mail](https://www.rfc-editor.org/rfc/rfc6376) — RFC Editor
- [RFC 7489: Domain-based Message Authentication, Reporting and Conformance](https://www.rfc-editor.org/rfc/rfc7489) — RFC Editor

## Continue learning

[check for dkim](https://sendhq.cc/guides/check-for-dkim.md) [dkim setup](https://sendhq.cc/guides/dkim-setup.md) [email dkim spf dmarc](https://sendhq.cc/guides/email-dkim-spf-dmarc.md) [email domain verification](https://sendhq.cc/guides/email-domain-verification.md)
