DKIM — DomainKeys Identified Mail
How DKIM uses cryptographic signatures to prove email integrity and authenticity.
What is DKIM?
DKIM (DomainKeys Identified Mail) is an email authentication method defined in RFC 6376. It uses public-key cryptography to allow the sending mail server to attach a digital signature to outgoing emails. The recipient's server retrieves the public key from DNS and verifies the signature, confirming that the email was not altered in transit and was genuinely sent by the claimed domain.
How DKIM Works
1. The sending server generates a cryptographic signature of the email headers and body using a private key.
2. The signature is added to the email as a DKIM-Signature header.
3. The sending domain publishes the corresponding public key in DNS as a TXT record at: {selector}._domainkey.{domain}
4. The receiving server queries this DNS record, retrieves the public key, and verifies the signature.
5. If the signature matches, DKIM passes. If the email was altered in transit, the signature will not match.
DKIM DNS Record Format
DKIM public keys are published at: {selector}._domainkey.{domain}
Example:
mail._domainkey.example.com IN TXT "v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GN..."Key fields:
• v=DKIM1 — version
• k=rsa — key type (rsa or ed25519)
• p= — the Base64-encoded public key
• s= — acceptable service types (email or *)
• t=s — strict mode (no subdomain signing)
DKIM Selectors
A selector is a label used to distinguish between multiple DKIM keys for the same domain. This allows domains to use different keys for different mail streams (e.g., transactional vs. marketing), rotate keys without downtime, and delegate signing to third-party ESPs. Common selectors include "default", "google", "k1", "s1", "mail", and provider-specific names. Your ESP will tell you which selector to use.
DKIM and Email Forwarding
Unlike SPF, DKIM survives email forwarding as long as the message body and signed headers are not modified. This makes DKIM a more reliable authentication signal for forwarded email. However, some mailing lists or forwarders that modify the subject line or body will break DKIM signatures.
DKIM Best Practices
1. Use 2048-bit RSA keys or Ed25519 for modern, strong signatures.
2. Rotate DKIM keys periodically (at least annually) to limit exposure if a key is compromised.
3. Use separate selectors for each sending service so you can revoke one without affecting others.
4. Always pair DKIM with SPF and DMARC — DKIM alone doesn't prevent spoofing of the From header.
5. Verify your DKIM setup before enforcing DMARC policy.
Related