
An email authentication method designed to detect email spoofing, DomainKeys Identified Mail (DKIM) provides a mechanism for receiving mail exchangers to verify that incoming mail from a domain is authorized by that domain's administrators. The process involves attaching a digital signature to the email, which the recipient validates using a public key published in the sender's DNS.
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=example.com; s=jan24; h=from:subject:date; bh=j9Uv8Lq5S7D...; b=N7qWzX9yP2r5T... Host: jan24._domainkey.example.com
Value: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA75... Authentication-Results: mx.google.com; dkim=pass header.i=@example.com header.s=jan24 DKIM Functionality
DKIM operates as a cryptographic handshake that proves an email’s origin and ensures its content remained unaltered during transit. The process involves three main phases:
- Signing Phase: Before an email leaves the sender’s server, the system generates a digital signature. It selects specific headers (like From and Subject) and the message body to create a unique hash. This hash is encrypted using a Private Key kept secret on the server. The result is the DKIM-Signature Header attached to the email.
- Publication Phase: For a recipient to verify the signature, the sender must "publish" the matching Public Key. This is stored in the domain's DNS settings as a TXT record. The Selector (s=) in the email header tells the recipient exactly where to look in the DNS to find this key.
- Verification Phase: When the receiving server gets the email, it performs the following logic: Retrieve the Public Key in the DNS using the domain ($d=$) and selector ($s=$), decrypt the signature ($b=$) using that Public Key to reveal the original hash, and compare it to a re-hashed version of the received email. If the hashes match, the message is authentic.
Loading formula...
Loading formula...
DKIM Importance
- Integrity: Ensures the message content (headers and body) has not been modified in transit.
- Authenticity: Links a domain name to an email message, providing legal and technical accountability.
- Deliverability: Verified emails are less likely to be flagged as spam or phishing by major Inbox Service Providers (ISPs).
- DMARC Dependency: Acts as one of the two foundational pillars (alongside SPF) required for a DMARC (Domain-based Message Authentication, Reporting, and Conformance) pass.
DKIM Limitations
- No Encryption: DKIM does not encrypt email content for privacy; it only signs it for authenticity.
- Replay Attacks: If a signed message is captured, it can be re-sent multiple times without breaking the signature unless additional expiration tags (t=, x=) are strictly enforced.
- Forwarding Issues: Traditional email forwarding can sometimes break DKIM signatures if the intermediate server modifies the message headers or footer.