How it works
The sending server signs selected parts of each message, such as the From address, the subject and the body, with a private key. The matching public key is published in DNS under a selector. The receiving server retrieves the key, checks the signature and records whether it passed. If someone altered the signed content in transit, the check fails.
Why it matters
Unlike SPF, DKIM usually survives forwarding, because the signature travels with the message. It also lets receivers build a reputation for the signing domain. Combined with DMARC, it is the main way to stop attackers sending email that appears to come from your exact domain.
Setting it up
Each service that sends email for the company, such as Microsoft 365, Google Workspace, a CRM or a marketing platform, needs DKIM enabled with its own selector and published key. Use keys of at least 2048 bits, rotate them periodically and remove the keys of services that are no longer used.
What it does not do
DKIM proves that a message came from the signing domain; it does not prove that the domain is trustworthy. Attackers can sign phishing emails with their own lookalike domains, so DKIM does not replace security awareness training or the monitoring of lookalike domains.




