Authentication
DKIM: the wax seal that travels with your message
A signature no one can forge without your private key, and why it breaks when a mailing list edits your mail.
DKIM adds a cryptographic signature to each message. The sending server signs part of the message with a private key. The public key sits in your DNS, and the receiving server checks the signature against it.
How it works
- The sender's server hashes the headers and body it chooses, then signs the hash.
- The signature is added as a header, and the public key is published under a selector, for example
selector._domainkey.example.com. - If anyone changes a signed part on the way, the check fails.
Why it matters
- Unlike SPF, DKIM survives forwarding, because the signature travels with the message.
- It proves the domain signed the mail, which is what DMARC needs to align.
- Keys should be long (2048-bit is common) and rotated on a schedule.
What breaks it
- Footers and tags added by a list or a relay change the body. Re-signing at the last hop fixes it.
- Expired or mistyped DNS records. Test the record after every change.