DNS, email and security
DKIM
DKIM adds a digital signature to outgoing email, checked against a public key published in the sender's DNS, so receivers can tell the message was not altered.
What DKIM means in practice
The sending mail system signs each message with a private key. The matching public key is published as a DNS record under a name called a selector, and receivers use it to verify the signature.
Because the selector is chosen by the sender, a simple lookup cannot tell for sure whether DKIM is set up unless you know the selector.
Why it matters
A valid DKIM signature helps mail arrive in the inbox and gives dmarc something to check.
Try it
- Domain Health Check Expiry date, transfer lock, DNS, SPF and DMARC email security, and blocklists for a .com.
Related terms
- SPF record An SPF record is a DNS entry that lists the servers allowed to send email for a domain, so receivers can spot mail that is faked.
- DMARC DMARC is a DNS policy that tells receiving mail servers what to do with email that fails SPF or DKIM checks, and where to send reports about it.
- DNS (Domain Name System) DNS is the internet's phone book: it turns a domain name into the addresses and settings that browsers and mail servers need to reach it.