How DKIM works
DKIM uses a key pair. The sending mail server keeps the private key. The matching public key is published in the domain’s DNS, where anyone can read it.1
- The sending server signs the message. It makes a hash of the body and of chosen header lines such as From, To and Date, signs it with the private key, and adds the result as a DKIM-Signature header.
- The receiving server finds the key. The signature names the signing domain and a selector. Together they point to a DNS record at
selector._domainkey.example.com. - The receiver checks the signature with the public key. If the body or a signed header changed after signing, the check fails.
How to read a DKIM signature
| Tag | What it holds |
|---|---|
| d= | The domain that signed the message |
| s= | The selector, which says which of the domain’s keys was used |
| a= | The algorithm, usually rsa-sha256 |
| h= | The list of header lines covered by the signature |
| bh= | The hash of the message body |
| b= | The signature itself |
Selectors let a domain use several keys at once, for example one per sending service, and swap an old key for a new one without a gap. The current guidance is that signers should use RSA keys of at least 2048 bits,2 and a newer option, Ed25519, gives short keys with the same job.3
Why DKIM matters
DKIM gives a receiver something SPF doesn’t: proof tied to the message itself instead of the server that delivered it. A signature still checks out after a message is forwarded, as long as nobody edited it. Gmail requires every sender to set up SPF or DKIM, and both for bulk senders, those sending around 5,000 or more messages a day.4
What DKIM doesn’t do
- It doesn’t encrypt. A signed message is still readable by every server that carries it. DKIM is about who sent it, not who can read it.
- It doesn’t check the From address on its own. Any domain can sign any message. DMARC adds the rule that the signing domain must match the From address.
- It can break when mail is edited. A mailing list that adds a footer changes the body, so the original signature no longer matches.
Where you’ll see DKIM
Open the headers of almost any email and you’ll find a DKIM-Signature line, plus your provider’s verdict on the Authentication-Results line, for example dkim=pass header.d=example.com. If you run email on your own domain, your provider gives you a DKIM record to publish in DNS.
DKIM in Secria
Secria publishes a DKIM key for secria.me in DNS, a 2048-bit RSA key. When you connect your own domain on Mail Plus or Secria Pro, Secria shows you the DKIM record to add, along with the MX, SPF and DMARC records, each with a copy button, and checks them for you.
Related terms
Sources
- IETF, RFC 6376: DomainKeys Identified Mail (DKIM) Signatures (September 2011).
- IETF, RFC 8301: Cryptographic Algorithm and Key Usage Update to DomainKeys Identified Mail (DKIM) (January 2018).
- IETF, RFC 8463: A New Cryptographic Signature Method for DomainKeys Identified Mail (DKIM) (September 2018).
- Google, Email sender guidelines (Google Workspace Admin Help).
Checked October 2026. Secria’s own records are public in DNS and were read on 11 October 2026. Other Secria facts are from our Mail and VPN pages.
Questions about DKIM
Does DKIM encrypt email?
No. DKIM signs a message so receivers can check where it came from and that it wasn’t altered. It doesn’t hide the content. Encryption in transit is the job of TLS, and encryption of the message itself is the job of end-to-end encryption.
What is a DKIM selector?
A selector is a short name that tells the receiver which of a domain’s public keys to fetch. It lets a domain use different keys for different services and replace keys over time.
What is the difference between SPF and DKIM?
SPF checks whether the server that delivered a message is on the domain’s list of allowed senders. DKIM checks a signature carried inside the message. SPF often fails when mail is forwarded, while a DKIM signature stays valid if the message is unchanged.
What is the difference between DKIM and S/MIME?
DKIM is added by the sending domain’s mail server and is checked by the receiving server. S/MIME is applied by a person’s mail app with their own certificate, and it can encrypt the message as well as sign it.