1. Home
  2. Glossary
  3. DKIM

What is a dkim?

Also called: DomainKeys Identified Mail

DKIM, or DomainKeys Identified Mail, adds a cryptographic signature to outgoing email using a private key, with the matching public key published in DNS. A receiving server verifies the signature to confirm the message genuinely came from the domain and was not altered in transit.

The public key lives at a selector-specific hostname — selector._domainkey.example.com — which is why checking DKIM requires knowing the selector. Providers use predictable ones: Google uses google, Microsoft selector1 and selector2, and many ESPs use their own brand name.

DKIM survives forwarding in a way SPF does not. When a message is forwarded, the sending IP changes and SPF breaks, but the signature still validates, which is why DKIM is the more durable of the two.

A DKIM signature that fails is worse than no signature at all, because it looks like tampering. Rotating keys without updating DNS is the usual cause.

Last reviewed 2026-09-11

Ready to clean your email lists?

Start verifying emails today and boost your deliverability.

Get Started

Cancel anytime • No setup required