DKIM (DomainKeys Identified Mail)
Definition
A cryptographic signing mechanism: the sending server signs the message headers and body with a private key, and the receiving server verifies the signature using the public key published in DNS. A valid DKIM signature proves the message was not altered in transit and was signed by the claimed domain.
- Full name
- DomainKeys Identified Mail
- Signs
- Message headers and body
- Key pair
- Private key on sender, public key in DNS
- Proves
- No alteration in transit and claimed-domain origin
Common questions
What happens to DKIM validation if a message is forwarded?+
Forwarding can break the original signature if the forwarding server modifies headers or the body, which is why some legitimate forwarded mail fails DKIM even though it was not maliciously altered, a common source of false-positive spoofing suspicion.
Why is DKIM alone insufficient to prove a sender's identity?+
DKIM confirms the signing domain, not the visible From address, so an attacker with their own signed domain can still forge a display name; DMARC alignment is what ties the signing domain to the visible sender.
Related terms
- DMARC (Domain-Based Message Authentication, Reporting, and Conformance)
- A policy layer that requires the domain in the visible From header to align with a domain that passes SPF or DKIM....
- Envelope Sender (Return-Path)
- The address used at the SMTP protocol level for bounce notifications, recorded in the Return-Path header. It is distinct from the display...
- Message-ID
- A globally unique identifier assigned to each message by the originating mail server, recorded in the Message-ID header. It is set by...
- Received Header
- A header line prepended by each mail server that accepts a message in transit, recording the server's own identity, the IP or...
- SPF (Sender Policy Framework)
- A DNS-based mechanism by which a domain owner publishes the list of IP addresses authorised to send mail for that domain. A...