Glossary · Authentication
DKIM adds a cryptographic signature to outgoing email, verified against a public key in the sender's DNS, proving the message is genuine and unaltered.
With DKIM (RFC 6376), the sending server signs each message with a private key and adds a DKIM-Signature header. The header names the signing domain (d=) and a selector (s=), which together tell the receiver where to find the public key: a TXT record at selector._domainkey.domain.
The signature covers the body and chosen headers, so any change in transit breaks it. Unlike SPF, DKIM usually survives forwarding, because it's tied to the message rather than the server that delivered it.
Use 2048-bit RSA keys; 1024-bit keys are now considered weak. For DMARC to count a DKIM pass, the signing domain has to align with the From address.
selector1._domainkey.acme.com TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkqh…"Every domain you run in one inbox, from $3 a mailbox. 14 days free, no card.