DKIM: the cryptographic signature that completes your email authentication trio.
Published 2026-04-29 · Last updated 2026-04-29 · Vantyris editorial
DKIM (DomainKeys Identified Mail) is the third leg of modern email authentication, alongside SPF and DMARC. SPF says 'these servers are allowed to send for me' and DMARC says 'here's what to do when SPF or DKIM fails'. DKIM adds a cryptographic signature to every outgoing email, which receiving servers check against a public key in your DNS. Without it, your DMARC enforcement is half-strength. Most email providers (Google Workspace, Microsoft 365, Mailgun, SendGrid) set up DKIM automatically. When it's missing, the reason is usually 'I didn't realise I had to enable it'.
What this means for your business
- Your sending server adds a
DKIM-Signatureheader to every outgoing email. It contains a hash of the body and selected headers, signed with a private key that only your sending server holds. - The receiving server reads that header, fetches the matching public key from your domain's DNS (at
<selector>._domainkey.<yourdomain>) and verifies the signature. A match proves cryptographically that the email came from you and wasn't modified in transit. - DMARC's 'alignment' check requires either SPF or DKIM to pass for the domain in the
From:header. With DKIM in place, mail forwarded through an intermediary (where SPF often breaks) still passes DMARC, because the signature survives forwarding.
How to fix
In your email provider's admin console, enable DKIM signing. Copy the public key it generates and publish it as a TXT record at the <selector>._domainkey.<yourdomain> host.
- Locate the DKIM setting in your email provider. Google Workspace: Admin Console → Apps → Google Workspace → Gmail → Authenticate email → Generate new record. Microsoft 365: Security & Compliance Center → Threat management → Policy → DKIM. Mailgun / Postmark / SendGrid: the DKIM record is on the verification page of your sending-domain setup.
- Publish the TXT record. Your provider gives you a host (e.g.,
google._domainkeyorselector1._domainkey) and a value (the public key, often 1000+ characters). At your DNS provider, add a TXT record at that host with that value. Some DNS panels split long values into 255-character strings. That's normal, and it works. - Enable signing in the email provider's UI. Once the DNS record is live, go back to the email provider and click 'Start authentication' or 'Enable DKIM'. The provider checks the public key matches what it expects and starts signing outgoing mail.
- Test by sending yourself an email. Send a test message from your domain to a Gmail account you control. Open it and choose Show original from the three-dot menu. Look for
dkim=passin the headers. If you seedkim=fail, or no DKIM result at all, the public key didn't match.
Owner: Your email administrator (typically the same person who set up your inbox). · Time: 20 minutes once you've found the right setting.
Common gotchas
- DKIM keys are typically 2048-bit RSA. If your DNS provider rejects long TXT values, move to a provider that accepts them, or use DKIM2 / Ed25519 keys (smaller, but newer).
- If you use multiple senders (Google Workspace for staff + Mailgun for transactional + Mailchimp for newsletters), each one needs its own DKIM selector. Don't reuse a key across providers.
- Modern guidance is to rotate DKIM keys every 12 months. Few SMEs bother. We won't push back if you do it every 24 months.
- DKIM signs mail. It doesn't encrypt it, so anyone in transit can still read the message. Your provider handles encryption, through TLS at the transport layer.
How to verify the fix
A Vantyris verified scan checks for DKIM support against your published TXT records. You can also send a test email to dkimvalidator.com (free), which checks the signature in detail.
Cyber Essentials alignment
This finding informs the following Cyber Essentials control areas (the UK government's baseline scheme, a sound checklist in any country):
- A1. Firewalls: boundary protection between the internet and your services.
- A2. Secure configuration: devices and services hardened against the weaknesses they ship with by default.
Vantyris is not a CE certifying body. The mapping above is informational.
Common follow-up questions
Do I need DKIM if I already have SPF + DMARC?
Yes. SPF breaks on forwarded mail (mailing lists, redirect rules). DKIM survives forwarding because the signature is in the message itself. Without DKIM, your DMARC enforcement misses any mail that crosses a forwarder, which is much more common than it sounds.
What's a DKIM selector?
A label that lets you have multiple DKIM keys for the same domain. The selector appears in the DKIM-Signature header and tells receivers which public key to fetch. Common ones: default, google, selector1, s1. Pick any string. It only has to match the DNS host where you publish the public key.
Can I sign with multiple selectors at once?
Yes, and it's useful during key rotation. Publish the new selector, wait for it to propagate, switch the signing service to the new key, then retire the old selector. Most providers don't expose this directly. You'd need access to the SMTP-layer config.
References
- RFC 6376: DKIM IETF RFC
- NCSC: email authentication NCSC
- Google Workspace: enable DKIM Vendor
Related explainers
- What is DMARC, and why every business with a domain needs one.
- SPF records, explained: the first line of defence against email spoofing.
Want Vantyris to check your domain for this and 196 other problems?
The teaser scan is free and needs no card. A verified scan starts at $10€10£10A$15¥1,500AED 40 and comes with the workspace: finding workflow, score trend, three PDF layouts, share links and monitoring.
Written by Vantyris