What is DKIM (DomainKeys Identified Mail)?

DKIM (DomainKeys Identified Mail) is an email standard that adds a digital signature to each message a domain sends. The receiving server looks up the domain’s public key in DNS and checks the signature. A valid signature shows the domain took responsibility for the message and that the signed parts weren’t changed on the way.

Also called: DomainKeys Identified Mail, DKIM signature

Updated October 2026. Sources are numbered and listed at the end.

On this page

How DKIM works

DKIM uses a key pair. The sending mail server keeps the private key. The matching public key is published in the domain’s DNS, where anyone can read it.1

  1. The sending server signs the message. It makes a hash of the body and of chosen header lines such as From, To and Date, signs it with the private key, and adds the result as a DKIM-Signature header.
  2. The receiving server finds the key. The signature names the signing domain and a selector. Together they point to a DNS record at selector._domainkey.example.com.
  3. The receiver checks the signature with the public key. If the body or a signed header changed after signing, the check fails.

How to read a DKIM signature

The main tags in a DKIM-Signature header.
TagWhat it holds
d=The domain that signed the message
s=The selector, which says which of the domain’s keys was used
a=The algorithm, usually rsa-sha256
h=The list of header lines covered by the signature
bh=The hash of the message body
b=The signature itself

Selectors let a domain use several keys at once, for example one per sending service, and swap an old key for a new one without a gap. The current guidance is that signers should use RSA keys of at least 2048 bits,2 and a newer option, Ed25519, gives short keys with the same job.3

Why DKIM matters

DKIM gives a receiver something SPF doesn’t: proof tied to the message itself instead of the server that delivered it. A signature still checks out after a message is forwarded, as long as nobody edited it. Gmail requires every sender to set up SPF or DKIM, and both for bulk senders, those sending around 5,000 or more messages a day.4

What DKIM doesn’t do

  • It doesn’t encrypt. A signed message is still readable by every server that carries it. DKIM is about who sent it, not who can read it.
  • It doesn’t check the From address on its own. Any domain can sign any message. DMARC adds the rule that the signing domain must match the From address.
  • It can break when mail is edited. A mailing list that adds a footer changes the body, so the original signature no longer matches.

Where you’ll see DKIM

Open the headers of almost any email and you’ll find a DKIM-Signature line, plus your provider’s verdict on the Authentication-Results line, for example dkim=pass header.d=example.com. If you run email on your own domain, your provider gives you a DKIM record to publish in DNS.

DKIM in Secria

Secria publishes a DKIM key for secria.me in DNS, a 2048-bit RSA key. When you connect your own domain on Mail Plus or Secria Pro, Secria shows you the DKIM record to add, along with the MX, SPF and DMARC records, each with a copy button, and checks them for you.

Sources

  1. IETF, RFC 6376: DomainKeys Identified Mail (DKIM) Signatures (September 2011).
  2. IETF, RFC 8301: Cryptographic Algorithm and Key Usage Update to DomainKeys Identified Mail (DKIM) (January 2018).
  3. IETF, RFC 8463: A New Cryptographic Signature Method for DomainKeys Identified Mail (DKIM) (September 2018).
  4. Google, Email sender guidelines (Google Workspace Admin Help).

Checked October 2026. Secria’s own records are public in DNS and were read on 11 October 2026. Other Secria facts are from our Mail and VPN pages.

Questions about DKIM

Does DKIM encrypt email?

No. DKIM signs a message so receivers can check where it came from and that it wasn’t altered. It doesn’t hide the content. Encryption in transit is the job of TLS, and encryption of the message itself is the job of end-to-end encryption.

What is a DKIM selector?

A selector is a short name that tells the receiver which of a domain’s public keys to fetch. It lets a domain use different keys for different services and replace keys over time.

What is the difference between SPF and DKIM?

SPF checks whether the server that delivered a message is on the domain’s list of allowed senders. DKIM checks a signature carried inside the message. SPF often fails when mail is forwarded, while a DKIM signature stays valid if the message is unchanged.

What is the difference between DKIM and S/MIME?

DKIM is added by the sending domain’s mail server and is checked by the receiving server. S/MIME is applied by a person’s mail app with their own certificate, and it can encrypt the message as well as sign it.

Email that’s ready for what comes next.

Post-quantum encryption on every plan, free included.

Start free

Explore Secria Mail