Cybersecurity glossary
What is DomainKeys Identified Mail (DKIM)?
Learn what DKIM is, how DKIM signatures and selectors work, and why DKIM matters for email integrity, sender authentication, and DMARC alignment.
Definition
DomainKeys Identified Mail (DKIM) is an email-authentication method in which a sending system signs selected message headers and content with a private key, while receivers verify the signature using a public key published in DNS.
Why DKIM matters
Where SPF asks whether a host is allowed to send, DKIM asks whether the message itself carries a valid cryptographic signature from an expected domain. That makes DKIM especially useful when mail passes through relays or services that preserve signed content but change the path it took to arrive. DKIM also matters because it becomes one of the two major identity signals DMARC can align to the visible From domain. Without that alignment, a valid signature may still fail to protect your brand from direct spoofing.
Core DKIM building blocks
Private signing key
The sender uses a private key to sign selected headers and body content before the message leaves the outbound system.
Selector
A selector chooses which DNS-published public key the receiver should use to verify the signature.
Signed headers and body
The DKIM-Signature header indicates which parts of the message are covered by the signature.
Signing domain
The `d=` value identifies the domain claiming responsibility for the signature.
How DKIM verification works
The sender prepares the message
Before delivery, the outbound service decides which headers and body content should be covered by the DKIM signature.
A DKIM signature is generated
The sender signs the selected message material with its private key and inserts a DKIM-Signature header.
The selector and domain travel with the message
The signature tells the receiver which selector and signing domain to use for key lookup.
The receiver queries DNS for the public key
It looks up the selector-specific TXT record, usually at a name like `selector._domainkey.example.com`.
The signature is recomputed and checked
The receiver verifies that the message still matches the signed content and that the key validates the signature.
DMARC may evaluate alignment
If the signing domain aligns with the visible From domain, the DKIM result becomes much more meaningful for brand protection.
DKIM choices that affect real-world behavior
Many DKIM problems come from operational details rather than the signature idea itself.
| Element | What it means | Why it matters |
|---|---|---|
| Selector strategy | Different senders or environments can use different selectors and keys under the same organizational domain. | This makes rotation and vendor separation easier, but it also creates inventory and retirement work. |
| Canonicalization | DKIM allows relaxed or stricter ways of deciding what message formatting changes are acceptable during verification. | The choice affects how robust signatures remain when intermediate systems reformat messages. |
| Alignment to visible From | A valid DKIM signature may still be unaligned with the From domain the user sees. | That is why DMARC is essential: it converts a raw signature success into a brand-relevant policy outcome. |
| Key size and rotation | Keys need to be strong enough and rotated often enough to keep long-term compromise risk manageable. | Stale selectors are a common sign that a mail-authentication program is no longer being actively governed. |
DKIM practices that reduce drift and breakage
DKIM is easy to “turn on” and much harder to keep correct across vendors, forwarding paths, and organizational change.
- Publish clearly named selectors and keep an inventory of which vendor or service signs with each one.
- Prefer strong keys and rotate selectors on a planned schedule so old DNS-published keys do not linger indefinitely.
- Sign the headers that matter for trust decisions and test that downstream systems do not routinely rewrite them.
- Align the DKIM signing domain with the visible From domain whenever feasible so [DMARC](/glossary/domain-based-message-authentication-reporting-and-conformance-dmarc) can use the result effectively.
- Retire selectors promptly when vendors are decommissioned or sending paths are removed.
- Validate TXT-record syntax carefully because small formatting mistakes can make a healthy signing system look broken.
- Monitor failure rates by sender and workflow so broken signatures are caught before they become a deliverability or spoofing problem.
- Deploy DKIM alongside [SPF](/glossary/sender-policy-framework-spf), not instead of it, because the two controls protect different parts of mail identity.
DKIM proves signing, not universal legitimacy
A valid DKIM signature means the message was signed by whoever controls the private key and that the covered content still matches. It does not mean the message is benevolent, that the sending mailbox was not compromised, or that the brand in the visible From line is necessarily aligned. That is why high-confidence mail trust comes from the combination of domain governance, DKIM signing hygiene, and DMARC policy enforcement rather than from cryptography alone.
The practical takeaway
DKIM is the email-signing system that lets receivers verify selected message content against a DNS-published public key. The practical takeaway is to manage DKIM as a living key and selector program: sign consistently, rotate deliberately, align to the visible From domain, and measure results through DMARC-aware reporting.
Related security terms
Email Spoofing
DKIM helps receivers verify that a message was signed by an authorized domain and not altered in transit.
Sender Policy Framework (SPF)
SPF validates sending hosts while DKIM validates signed message content and domain association.
Domain-Based Message Authentication, Reporting and Conformance (DMARC)
DMARC uses DKIM alignment to decide whether visible sender identity should be trusted.
TXT Record
DKIM public keys are commonly published as TXT records at selector-specific DNS names.
Brand Indicators for Message Identification (BIMI)
Strong DKIM and DMARC posture is part of the foundation for BIMI adoption.
Frequently asked questions
What is DKIM in simple terms?
DKIM is a digital signature for email that lets receivers verify the message was authorized by a domain and not changed in certain important ways.
What is a DKIM selector?
A selector is the DNS label that points the receiver to the right public key for verifying a specific message signature.
How is DKIM different from SPF?
SPF authorizes sending servers. DKIM signs the message itself, which often survives relay paths better than source-IP authorization.
Can DKIM stop all email spoofing?
No. DKIM helps, but spoofing defenses become much stronger only when DMARC aligns DKIM or SPF with the visible From domain.
What breaks DKIM?
Message modifications by intermediaries can break verification if they change signed headers or content outside the allowed canonicalization rules.
Should DKIM keys be rotated?
Yes. Selectors and keys should be rotated deliberately so long-lived signing keys do not become forgotten high-value secrets.
References
Explore authoritative guidance and frameworks related to domainkeys identified mail (dkim).
Explore every security definition
Return to the glossary to search by term, alias, starting letter, or security category.