What is DKIM ?

DKIM, Domain Keys Identified Mail, was put together to enable digital signatures on emails verifying their integrity.

The Problem:

Even though SPF record authorizes IP Addresses to send email on behalf of a domain, an IP Address can be spoofed, which allows forged emails to pass the SPF check. This makes the forged email look genuine.

The Solution:

DKIM was introduced to enable your mail server to digitally sign your emails before they are sent out. If by any means, the message got changed in transit, the signature would get removed automatically. Even when the email is forwarded with the contents changed, the signature does not survive.

SPF authorizes who can send an email on behalf of a domain, and DKIM verifies the integrity of the message in the email.

