← All terms

DKIM

DKIM (DomainKeys Identified Mail) adds a cryptographic signature to outgoing email, letting receivers verify the message really came from the signing domain and was not altered in transit.

DKIM — DomainKeys Identified Mail — attaches a cryptographic signature to every outgoing message, generated with a private key held by the sending infrastructure. The matching public key is published in the domain's DNS, so any receiving server can verify two things at once: the message was sent by infrastructure authorized for that domain, and the signed content — headers and body — was not modified on the way.

How it works

The sending server computes a hash over selected headers and the message body, signs it, and inserts the result as a DKIM-Signature header naming the signing domain and a selector. The receiver fetches the public key from selector._domainkey.domain.com, recomputes the hash, and checks the signature. Unlike SPF, the signature travels with the message, so DKIM survives forwarding — which is why mailing lists and relay chains that break SPF still verify cleanly under DKIM.

What it does not stop

A valid DKIM signature proves which domain signed the message — not that the domain is trustworthy. Attackers register their own domains, configure DKIM flawlessly, and send fully authenticated phishing. A signature also proves nothing about the visible From header unless DMARC alignment enforces that the signing domain and the displayed domain match. And when a legitimate mailbox is taken over, as in vendor email compromise, every malicious message is signed by the victim's own infrastructure: perfectly authenticated, perfectly fraudulent. The AI-generated phishing wave compounds this — flawless prose from a flawlessly authenticated domain leaves human judgment as the control that has to hold.

How to defend

  • Sign all outgoing mail, including messages from marketing and transactional platforms, each with its own selector so a leaked key can be rotated narrowly.
  • Rotate keys periodically and retire weak ones — 1024-bit keys are deprecated; use 2048-bit.
  • Enforce alignment with DMARC. DKIM only constrains the visible sender once DMARC requires the signing domain to align with the From domain.
  • Train for the authenticated-but-fraudulent case. Payment-change requests and urgent vendor emails deserve out-of-band verification regardless of what the authentication headers say.

Related terms

SPFSPF (Sender Policy Framework) is an email authentication standard that lets a domain publish which servers may send mail on its behalf, helping receivers reject forged senders.DMARCDMARC (Domain-based Message Authentication, Reporting and Conformance) is an email authentication standard that tells receiving servers how to handle messages that fail SPF or DKIM checks, blocking exact-domain spoofing.SpoofingSpoofing is the falsification of an identity signal — sender address, caller ID, domain, or website — to make an attack appear to come from a trusted source.Vendor Email Compromise (VEC)Vendor email compromise hijacks a supplier's real email account or thread to redirect customer payments — BEC's hardest-to-spot variant.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo