DKIM
Also known as DomainKeys Identified Mail
A cryptographic signature added to outbound email that proves the message came from your domain and was not altered.
The sending server signs each message with a private key, and the recipient verifies it against a public key published in your DNS. It survives forwarding better than SPF, which breaks when a message is relayed.
Every service that sends mail on your behalf needs its own DKIM signing configured, otherwise their messages fail the check even though they are legitimate.
Where this comes up
DKIM sits inside our networks and infrastructure work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.
Measure this on your own domain
Our free email authentication checker reads this record for any domain over public DNS, grades what it finds, and gives you the exact record to publish if it is wrong. No sign-up.
Check your domain →