DomainKeys Identified Mail (DKIM) is an email authentication mechanism that uses digital signatures to verify the authenticity and integrity of messages.
When you send an email, the sending server digitally signs it with a private key. This signature includes a cryptographic hash of different parts of the message, such as the headers and the body. The sending domain publishes a DKIM record in the DNS with the corresponding public key. Receiving servers use this key to verify that:
- The message has not been modified during transmission.
- The email truly originates from the domain claiming to be the sender.
Why is DKIM important?
Using DKIM provides several advantages for email security and deliverability:
- Authenticity: confirms that the message was sent from a server authorised by the domain.
- Integrity: ensures that the content of the email has not been tampered with during transmission.
- Better deliverability: increases the chances that emails reach the Inbox instead of being marked as spam.
- Sender reputation: mail servers and spam filters take DKIM signatures into account, reinforcing domain trust and credibility.
- Works with SPF and DMARC: DKIM is a key element, together with SPF and DMARC, to deploy a robust authentication system that protects against phishing and spoofing.
Example of a DKIM record
A DKIM record in DNS is a TXT entry and usually looks like this:
default._domainkey.example.com. IN TXT "v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3...public key..."
The prefix default is the selector, which may vary depending on the configuration. This value indicates which key pair (private/public) is used to validate the signature.
Conclusion

DKIM is now an essential standard for secure and reliable email delivery. Its implementation not only protects against tampering and forgery but also helps improve domain reputation and ensures that legitimate messages reach their intended destination.
When combined with SPF and DMARC, DKIM becomes part of a robust authentication ecosystem that combats phishing, spoofing, and other forms of email fraud, creating stronger trust between senders and recipients.