DMARC Engine
Glossary

DKIM

A cryptographic signature added to outgoing email that lets receivers verify the message was not altered and came from your domain.

DKIM (DomainKeys Identified Mail), defined in RFC 6376, adds a digital signature to each outgoing message. The sending server signs selected headers and the body with a private key; the receiver fetches the matching public key from DNS and verifies the signature.

The signature travels in the DKIM-Signature header, which names a selector and the signing domain. The receiver looks up the public key at selector._domainkey.yourdomain.com, where a TXT record holds the key type k= and the public key p=. An empty p= revokes the key, and t=y marks the selector as testing.

Keys should be RSA 2048-bit; 1024-bit is weak and being phased out, while ed25519 offers a compact modern alternative. Because DKIM signs content rather than the connecting IP, the signature survives most forwarding, unlike SPF.

Under DMARC, DKIM only helps if the signing domain aligns with the visible From address. Rotate selectors periodically; see key rotation. Confirm your published key with the checker below.

Check it on your domain

  • DKIM Checker: look up and validate a DKIM public key by selector.
  • DKIM Generator: generate a DKIM key pair and DNS record in your browser.
  • DMARC Checker: look up and validate a domain's DMARC record and policy.

Written and reviewed by the DMARC Engine team · Last reviewed June 2026

See where your domain stands today

Run a free DMARC scan, then let us take you to enforced p=reject with no email outage.