DKIM (DomainKeys Identified Mail) is an email authentication method that adds a digital signature to each message you send, so the receiving mail server can confirm the email really came from your domain and was not altered on the way. It works with SPF and DMARC to show inbox providers that your email is genuine.
How DKIM works
DKIM uses a pair of keys. Your sending service holds a private key and signs each outgoing message with it: it calculates a fingerprint of the body and selected headers, such as From, Subject and Date, and adds the result as a DKIM-Signature header. The signature names the signing domain (the d= value) and a selector (s=), a label saying which key was used.
You publish the matching public key in your DNS as a TXT record at selector._domainkey.yourdomain.co.uk. Many email platforms ask you to add CNAME records instead, which point to keys they manage and rotate for you. When a message arrives, the receiving server looks up the public key, checks the signature and records a pass or fail.
For DMARC, a pass is not enough on its own. The signing domain must also match, or align with, the domain in the From address your readers see. That is why a platform signing with its own domain does nothing for you: you need a signature from your own domain or a subdomain of it.
Unlike SPF, DKIM usually survives forwarding, because the signature travels inside the message. It can break if something along the way rewrites the content, such as a mailing list adding a footer.
Why it matters for a UK business
At the time of writing (October 2026), Gmail, Yahoo and Microsoft’s consumer Outlook service all expect bulk senders to authenticate with DKIM, and unsigned messages are more likely to be filtered or rejected. Even a small business sending invoices, booking confirmations and a monthly newsletter is better off signing everything, because inbox providers build your domain’s reputation from authenticated mail.
DKIM is also a foundation for two other things. It lets you move DMARC to enforcement, which stops criminals sending fake invoices in your name, and that enforced DMARC policy is what your logo needs before it can appear through BIMI.
Common mistakes
- Leaving the email platform on its default shared signature, so DKIM passes but does not align with your From domain.
- Setting up DKIM for the newsletter tool but forgetting the CRM, help desk, online shop or accounting software that also sends as your domain.
- Pasting the key into DNS with a line break or a missing character, so it never validates.
- Staying on an old 1024-bit key when the provider supports 2048-bit.
- Deleting the old record too soon when changing provider, so messages still in transit fail.
How to act on it
List every service that sends email as your domain. Open each one’s domain or authentication settings, complete the custom DKIM set-up and add the records it gives you at your DNS host. Send a test message to a Gmail account and use “Show original” to confirm DKIM: PASS with your own domain named.
Then publish a DMARC record at p=none to collect reports, which will reveal any sender you missed. If you would like a second view on how email fits into your wider marketing, my digital marketing strategy and consulting service is the place to start.
