What is DKIM?
DKIM (DomainKeys Identified Mail) is an email authentication method that uses cryptographic signatures to verify that an email was sent by an authorized server and wasn't modified in transit.
How DKIM Works
DKIM uses public-key cryptography to sign outgoing emails. The sending server attaches a digital signature to each email, and receiving servers can verify this signature using the public key published in DNS.
The DKIM Process
- 1Signing: The sending server creates a hash of certain email headers and body, then encrypts it with a private key
- 2Header Addition: The signature is added to the email as a DKIM-Signature header
- 3DNS Lookup: The receiving server looks up the public key using the selector and domain in the signature
- 4Verification: The server decrypts the signature and compares it to the email content
Key Point: DKIM proves the email hasn't been tampered with and comes from an authorized sender for the domain.
DKIM Results
The signature is valid. The email is authentic and unmodified.
The signature doesn't match. The email may have been modified or forged.
No DKIM signature present. The email cannot be verified.
Example DKIM-Signature Header
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=example.com; s=selector1; h=from:to:subject:date:message-id; bh=base64hash...; b=base64signature...
Key DKIM Components
v- Version (always "1")a- Algorithm (usually rsa-sha256)d- Signing domains- Selector (used to find the public key in DNS)h- Headers included in the signaturebh- Body hashb- The signature itself
DKIM DNS Record
The public key is published in DNS at selector._domainkey.example.com:
Why DKIM Matters
- Proves email authenticity and integrity
- Prevents email content tampering
- Required for DMARC alignment
- Improves sender reputation and deliverability
- Protects against man-in-the-middle attacks
Common DKIM Issues
- Key mismatch: Private and public keys don't match
- Expired key: DKIM key needs rotation
- Missing DNS record: Public key not published
- Header modification: Email was altered in transit (e.g., by mailing lists)
- Wrong selector: Using the wrong selector in the signature
Check Your DKIM Configuration
Use our free spam checker to verify your DKIM signature is working correctly.
Check Your EmailNeed DKIM verification in your app?
Mailhooks validates DKIM signatures on every inbound email and includes the verification results in your webhook payload.
Try Mailhooks free