DKIM stands for DomainKeys Identified Mail. It adds a cryptographic signature to outgoing email so the receiving server can verify that the message was signed by an authorized system.
How does DKIM work?
The sending mail server signs selected parts of the message with a private key. The receiving server retrieves the corresponding public key from the sender domain’s DNS records and verifies the signature.
What does DKIM prove?
A successful DKIM verification indicates that the message was signed for a specific domain and that the signed portions were not modified in transit.
What is a DKIM selector?
DKIM keys are published under identifiers known as selectors. This allows a domain to use multiple keys and rotate them over time.
Why does DKIM matter?
DKIM contributes to both domain security and email deliverability. It is also one of the authentication mechanisms evaluated by DMARC.
How is DKIM different from SPF?
SPF evaluates whether a sending server is authorized, while DKIM verifies a cryptographic signature attached to the message. The two technologies complement each other.
Continue with our guide: What Is SPF?