DKIM (DomainKeys Identified Mail)

DKIM (DomainKeys Identified Mail) is a method with which outgoing emails are cryptographically signed by the sending domain. This allows receiving systems to check whether a message has been altered in transit and whether it actually originates from the specified domain.

To this end, the sending server adds a signature header that is generated with a private key; the domain publishes the corresponding public key in its DNS as a so-called selector record. Receiving systems validate the signature against this key and thus detect manipulation of the content as well as spoofed sender domains. Unlike SPF, DKIM also survives forwarding as long as the message remains unchanged.

DKIM shows its full strength in combination with SPF and DMARC, which together form the basis of modern email authentication. Especially in complex email landscapes with cloud services, newsletters, platforms and applications, a clean DKIM strategy is an important lever against spoofing, brand abuse and delivery problems.