email59

Authentication

DKIM: the wax seal that travels with your message

A signature no one can forge without your private key, and why it breaks when a mailing list edits your mail.

DKIM adds a cryptographic signature to each message. The sending server signs part of the message with a private key. The public key sits in your DNS, and the receiving server checks the signature against it.

How it works

  • The sender's server hashes the headers and body it chooses, then signs the hash.
  • The signature is added as a header, and the public key is published under a selector, for example selector._domainkey.example.com.
  • If anyone changes a signed part on the way, the check fails.

Why it matters

  • Unlike SPF, DKIM survives forwarding, because the signature travels with the message.
  • It proves the domain signed the mail, which is what DMARC needs to align.
  • Keys should be long (2048-bit is common) and rotated on a schedule.

What breaks it

  • Footers and tags added by a list or a relay change the body. Re-signing at the last hop fixes it.
  • Expired or mistyped DNS records. Test the record after every change.

Sources

Send your first email More articles