Key points at a glance
- DKIM digitally signs every email; the recipient checks the signature with the key from your DNS.
- Every service that sends in your name needs DKIM set up with your own domain.
- Keys with 2048 bits are standard today; anything shorter than 1024 bits is considered insecure.
What DKIM does
With DKIM (DomainKeys Identified Mail, RFC 6376), your mail server signs every outgoing email with a private key. You publish the matching public key in the DNS. The receiving server uses it to check the signature. If it matches, it is clear: the email comes from an authorised server, and the header and content are unchanged.
- SignYour mail server signs the email with the private key.
- SendThe signature travels in the header of the email.
- Fetch keyThe recipient reads the public key from your DNS.
- VerifyIf the signature matches, the email is genuine and unchanged.
Selector and DNS record
The public key sits under a “selector”, for example selector1._domainkey.example.com. This means every service sending in your name can have its own key. Microsoft 365, Google Workspace and most newsletter services provide you with the necessary records; you only need to add them to the DNS and activate them.
What to watch for
- Key length: RSA keys should be 2048 bits long; anything shorter than 1024 bits is considered insecure (RFC 8301).
- Every sending service needs DKIM with your domain (d=example.com), not the service’s own domain.
- Rotate keys regularly and remove old selectors once a service is no longer used.
Tip
Ask every service that sends in your name – newsletter, CRM, accounting – for DKIM set up with your own domain. Many providers describe this in their help pages.
DKIM and DMARC
Unlike SPF, DKIM usually survives forwarding too. For DMARC, what matters is that the signing domain matches the visible sender address. That makes correctly configured DKIM the most important prerequisite for p=reject.
No safe p=reject without DKIM
SPF often breaks for forwarded emails. If a matching DKIM signature is then missing, p=reject would reject genuine emails too.
How DomainRadar helps
DomainRadar checks the known selectors of your domains, assesses the key length and shows in the DMARC reports which services send without a matching DKIM signature.
The domain check stays free. Afterwards you test Business for 14 days – no credit card, the trial ends on its own.