GlossaryAttack surface and pentesting

DKIM

Short answer

DKIM (DomainKeys Identified Mail) is an email authentication standard that adds a cryptographic signature to outgoing messages. Receivers use a public key published in the sender's DNS to verify that the message really comes from that domain and was not altered in transit.

How it works

The sending server signs selected parts of each message, such as the From address, the subject and the body, with a private key. The matching public key is published in DNS under a selector. The receiving server retrieves the key, checks the signature and records whether it passed. If someone altered the signed content in transit, the check fails.

Why it matters

Unlike SPF, DKIM usually survives forwarding, because the signature travels with the message. It also lets receivers build a reputation for the signing domain. Combined with DMARC, it is the main way to stop attackers sending email that appears to come from your exact domain.

Setting it up

Each service that sends email for the company, such as Microsoft 365, Google Workspace, a CRM or a marketing platform, needs DKIM enabled with its own selector and published key. Use keys of at least 2048 bits, rotate them periodically and remove the keys of services that are no longer used.

What it does not do

DKIM proves that a message came from the signing domain; it does not prove that the domain is trustworthy. Attackers can sign phishing emails with their own lookalike domains, so DKIM does not replace security awareness training or the monitoring of lookalike domains.

Related terms

Keep reading on this topic

External and internal attack surface management, cloud configuration and application security: finding exposures and prioritising them by real risk.

Go to the topic hub