Resources

What is DKIM?

DKIM signs outgoing mail with a key whose public half lives in your DNS. The signature survives forwarding.

The sending server signs selected headers and the body. The receiver fetches the public key from <selector>._domainkey.yourdomain and verifies it.

The selector lets you run several keys at once, which is what makes a rotation possible without a gap.

Unlike SPF, a DKIM signature stays valid when a message is forwarded, as long as the content is not modified in transit.

A DKIM record that exists but does not match the key in use is worse than none — it fails instead of being absent, so verify after every change.

All resources