Skip to content
Back to Glossary

Authentication

Updated

DKIM (DomainKeys Identified Mail)

Definition

DKIM (DomainKeys Identified Mail) is a cryptographic signature added to each email's headers. Receivers fetch the sender's public key from DNS to confirm the message was authorized by the signing domain and was not altered in transit.

How it works

DKIM is defined in RFC 6376. The sending server hashes selected headers and the body, signs the hash with a private key, and adds a DKIM-Signature header. That header names the signing domain (d=) and a selector (s=).

The receiver looks up the public key at selector._domainkey.domain, for example s1._domainkey.example.com, recomputes the hashes and verifies the signature. A pass proves the d= domain vouched for the message and that the signed parts did not change.

Selectors let one domain run several keys at once, one per sending service, and rotate keys without downtime.

Example

DKIM-Signature header
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=example.com; s=s1; t=1759363200; h=from:to:subject:date:message-id; bh=2jUSOH9NhtVGCQWNr9BrIAPreKQjO6Sn7XIkfJVOzv8=; b=dzdVyOfAKCdLXdJOc9G2q8LoXSlEniSb... s1._domainkey.example.com. TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkq..."

d= is the signing domain, s= the selector. The public key lives at s1._domainkey.example.com.

Why it matters

DKIM is the authentication method that survives forwarding, because the signature travels with the message. That makes it the most reliable path to a DMARC pass.

Gmail and Yahoo's 2024 sender requirements expect bulk senders to sign with DKIM, and mailbox providers build domain reputation on the d= domain. Signing with your own domain means your reputation is yours, not a shared ESP domain's.

Best practices

  • Use 2048-bit RSA keys. RFC 8301 requires at least 1024 bits and recommends 2048. Some DNS hosts need long TXT values split into quoted strings.
  • Sign with your own domain (d=yourdomain.com) so DKIM aligns with your From address for DMARC.
  • Use a separate selector per sending service. You can then revoke one without touching the others.
  • Rotate keys periodically and remove the DNS record of a retired selector only after mail signed with it has stopped arriving.
  • If your DNS is on Cloudflare, keep DKIM CNAMEs DNS-only (grey cloud). Proxied records do not resolve to the key.

How Lumail handles DKIM

Lumail issues three DKIM CNAME records for each sending domain. They point to keys managed by Amazon SES, so mail is signed with a 2048-bit key aligned with your domain and rotation happens without DNS edits on your side.

Lumail verifies the CNAMEs on the domain page and flags DKIM that is missing, failing or weak in Settings, Deliverability.

Check a real message with the free mail tester or the spam tester.

Frequently asked questions

What is a DKIM selector?

A label in the DKIM-Signature header (s=) that tells the receiver where to find the public key: selector._domainkey.yourdomain.com. Each sending service usually gets its own selector.

Does DKIM encrypt my email?

No. DKIM signs the message so tampering is detectable. The content stays readable. Encryption in transit is handled by TLS.

Why does DKIM fail after forwarding or with a mailing list?

DKIM survives plain forwarding, but it fails if an intermediary changes signed content, such as a mailing list adding a footer or rewriting the subject. ARC (RFC 8617) exists to carry the original authentication result through those hops.

Is 1024-bit DKIM still acceptable?

It is the minimum RFC 8301 allows, but 2048-bit is the recommended size and what most providers now issue. Lumail flags weak keys as a deliverability issue.

Related terms, tools and docs

Browse every definition in the email marketing glossary.

Send your next email with Lumail.

3,000 emails a month free. Unlimited subscribers on every plan. Campaigns, automations and transactional email on one domain.