Try free for 14 days

Basics

DKIM explained: the digital signature for your emails

DKIM is to emails what a seal is to a letter: the recipient can see that the email truly comes from your domain and was not altered along the way.

3 min readHow well is your domain protected? Check my domain for free

Key points at a glance

  • DKIM digitally signs every email; the recipient checks the signature with the key from your DNS.
  • Every service that sends in your name needs DKIM set up with your own domain.
  • Keys with 2048 bits are standard today; anything shorter than 1024 bits is considered insecure.

What DKIM does

With DKIM (DomainKeys Identified Mail, RFC 6376), your mail server signs every outgoing email with a private key. You publish the matching public key in the DNS. The receiving server uses it to check the signature. If it matches, it is clear: the email comes from an authorised server, and the header and content are unchanged.

How the DKIM signature works
  1. SignYour mail server signs the email with the private key.
  2. SendThe signature travels in the header of the email.
  3. Fetch keyThe recipient reads the public key from your DNS.
  4. VerifyIf the signature matches, the email is genuine and unchanged.

Selector and DNS record

The public key sits under a “selector”, for example selector1._domainkey.example.com. This means every service sending in your name can have its own key. Microsoft 365, Google Workspace and most newsletter services provide you with the necessary records; you only need to add them to the DNS and activate them.

What to watch for

  • Key length: RSA keys should be 2048 bits long; anything shorter than 1024 bits is considered insecure (RFC 8301).
  • Every sending service needs DKIM with your domain (d=example.com), not the service’s own domain.
  • Rotate keys regularly and remove old selectors once a service is no longer used.

Tip

Ask every service that sends in your name – newsletter, CRM, accounting – for DKIM set up with your own domain. Many providers describe this in their help pages.

DKIM and DMARC

Unlike SPF, DKIM usually survives forwarding too. For DMARC, what matters is that the signing domain matches the visible sender address. That makes correctly configured DKIM the most important prerequisite for p=reject.

No safe p=reject without DKIM

SPF often breaks for forwarded emails. If a matching DKIM signature is then missing, p=reject would reject genuine emails too.

How DomainRadar helps

DomainRadar checks the known selectors of your domains, assesses the key length and shows in the DMARC reports which services send without a matching DKIM signature.

The domain check stays free. Afterwards you test Business for 14 days – no credit card, the trial ends on its own.

More guides

How does your domain measure up?

DomainRadar continuously checks the SPF, DKIM and DMARC of your domains and tells you in plain words what to do.