Contact

What is DKIM (DomainKeys Identified Mail)?

Definition

DKIM (DomainKeys Identified Mail) is an email authentication method, defined in RFC 6376, in which the sending server signs selected headers and the body of a message with a private key, and receivers verify the signature using a public key published in DNS. A valid signature shows that the signing domain took responsibility for the message and that it was not altered in transit. It does not encrypt anything.

Also known as: DomainKeys Identified Mail, DKIM signature, DKIM record, DKIM key, _domainkey

DKIM flow: an outgoing email is signed with a private key and the receiving server verifies it with the public key published in DNS

Signing and verifying, step by step

  1. The sending server computes a hash of the message body, then signs it together with chosen headers such as From, Subject and Date using its private key.
  2. The result goes into a DKIM-Signature header added to the message.
  3. The receiver builds a DNS name from the signature's domain (d=) and selector (s=): s1._domainkey.example.com.
  4. It fetches the public key from the TXT record there, verifies the signature and recomputes the body hash to compare.

The private key never leaves the sender; the public key is world-readable. This is ordinary public-key signing, not encryption: DKIM does nothing to keep message content confidential.

Anatomy of a DKIM-Signature header

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=example.com;
  s=s2026; t=1759480000; h=from:to:subject:date:message-id;
  bh=2jUSOH9NhtVGCQWNr9BrIAPreKQjO6Sn7XIkfJVO...;
  b=dzdVyOfAKCdLXdJOc9G2q8LoXSlEniSbav+yuU4z...
TagMeaning
d=The domain taking responsibility. This is the value DMARC alignment looks at.
s=The selector, which lets one domain publish several keys.
h=The list of headers covered by the signature.
bh= / b=The body hash and the signature itself.
c=Canonicalization; relaxed tolerates minor changes such as whitespace.

Selectors and key management

Because each key lives under its own selector, a domain can have several active at once: corporate mail signs with one, the marketing platform with another. Rotation uses the same trick. Publish a new key under a new selector, switch signing to it, and remove the old record once mail signed with it has been delivered.

RFC 8301 says rsa-sha1 must no longer be used for signing or verifying, RSA keys must be at least 1024 bits, and signers should use 2048 bits or more. RFC 8463 adds Ed25519 signatures, but since receiver support is less universal than for RSA, they are usually deployed alongside an RSA signature rather than instead of one.

What a passing signature does not prove

  • That the visible sender is genuine. The signature belongs to the d= domain. If an email platform signs with its own domain by default, DKIM passes but says nothing about yours. DMARC closes this gap by requiring d= to align with the From domain, which is why platforms offer a “sign with your own domain” setting.
  • That the content is safe. A phisher can send a perfectly signed message from a domain they own.
  • That it will survive every path. Mailing lists that tag subject lines or append footers can invalidate the signature.

To check a real message, open its raw headers and find the Authentication-Results line: look for dkim=pass and the header.d it passed for. The SPF result appears on the same line.

Related terms

← Back to the glossary