DKIM (DomainKeys Identified Mail)

DKIM (DomainKeys Identified Mail) is an email authentication standard, defined in RFC 6376, in which the sending domain adds a cryptographic signature to each message. Receivers verify it with a public key published in the domain's DNS.

Deliverability & Email InfrastructureUpdated September 30, 2026

In short

DKIM signs each email with a private key so receivers can confirm, using a public key in DNS, that a domain vouched for it and it was not altered.

Key points

  1. The signature travels in a DKIM-Signature header that names the signing domain (d=) and a selector (s=) used to find the key [1].
  2. The public key is published as a TXT DNS Record at selector._domainkey.example.com, so one domain can run several keys at once [1].
  3. RFC 8301 requires RSA keys of at least 1,024 bits, recommends 2,048 bits, and bans the older rsa-sha1 algorithm for signing [2].
  4. Gmail requires bulk senders to sign with DKIM, and Google Workspace admins turn it on in the Admin console [3][4].
  5. For DMARC, the d= domain must align with the From domain; a signature from a vendor's domain passes DKIM but fails Domain Alignment.
  6. Unlike SPF (Sender Policy Framework), a DKIM signature usually survives forwarding, because it depends on the message content, not the connecting IP.

How DKIM signing and verification work

The sending server hashes selected Email Headers, such as From, Subject and Date, along with the message body, then signs the result with the domain's private key [1]. It adds a DKIM-Signature header containing the signature, the hash, the list of signed headers, the d= domain and the s= selector. The receiver reads the selector and domain, fetches the public key from selector._domainkey plus the domain, and checks the signature. If any signed header or the body changed in transit, the check fails. A pass proves that the named domain took responsibility for the message; it does not by itself prove the visible From address is honest. That link is supplied by DMARC through Domain Alignment, which compares the d= domain with the From domain.

Setting up DKIM

Most mailbox providers and Email Service Provider (ESP) platforms generate the key pair for you. In Google Workspace, an admin creates a key in the Admin console, publishes the provided TXT record at the google._domainkey selector, waits for DNS to update and then starts signing [4]. Microsoft 365 uses two CNAME records so it can rotate keys automatically. Google recommends 2,048-bit keys where the DNS host supports them, which matches the guidance in RFC 8301 [2]. Every service that sends as your domain, including a CRM or help desk, needs its own selector and must sign with your domain rather than its own. A Secondary Sending Domain used for outreach needs its own keys as well. After setup, the Authentication-Results header on a test message should show dkim=pass with your domain.

Why DKIM matters for deliverability

DKIM gives mailbox providers a stable identity to attach Domain Reputation to. IP addresses change and are often shared, but a signing domain stays the same, so providers can learn over time whether mail signed by that domain is wanted. Gmail's bulk sender rules, in force since February 2024, require both SPF (Sender Policy Framework) and DKIM, plus a DMARC record, for anyone sending more than 5,000 messages a day to Gmail accounts [3]. Because a DKIM pass survives forwarding and mailing lists better than SPF, it is often the check that keeps DMARC passing for real-world mail. For Cold Email teams, a missing or unaligned signature is one of the most common reasons for poor Inbox Placement, and one of the easiest to fix. An aligned DKIM signature is also part of the DMARC foundation that BIMI logos depend on.

Sources
  1. RFC 6376: DomainKeys Identified Mail (DKIM) Signatures — IETF
  2. RFC 8301: Cryptographic Algorithm and Key Usage Update to DomainKeys Identified Mail (DKIM) — IETF
  3. Email sender guidelines — Gmail Help
  4. Set up DKIM — Google Workspace Admin Help
External sources open in a new tab.

Related terms

Mentioned in

Outreach without the busywork.

PineLead finds new B2B prospects every day, qualifies them against your criteria and writes the first email in your voice. You approve — PineLead sends.

Start free with 100 credits →