Email Marketing

DKIM (DomainKeys Identified Mail)

Also called DomainKeys Identified Mail, DKIM signature

An email authentication method that signs each message so receiving servers can confirm it came from your domain and was not changed in transit.

Quick facts: DKIM (DomainKeys Identified Mail)

Category
Email Marketing
Also called
DomainKeys Identified Mail, DKIM signature
Level
Advanced
Affects
Inbox placement, DMARC alignment, domain reputation, protection against spoofing, BIMI eligibility
Where to see it
Your DNS host, your email platform's domain settings, Gmail "Show original", DKIM record checkers, DMARC report readers
In this article4
  1. How DKIM works
  2. Why it matters for a UK business
  3. Common mistakes
  4. How to act on it

DKIM (DomainKeys Identified Mail) is an email authentication method that adds a digital signature to each message you send, so the receiving mail server can confirm the email really came from your domain and was not altered on the way. It works with SPF and DMARC to show inbox providers that your email is genuine.

How DKIM works

DKIM uses a pair of keys. Your sending service holds a private key and signs each outgoing message with it: it calculates a fingerprint of the body and selected headers, such as From, Subject and Date, and adds the result as a DKIM-Signature header. The signature names the signing domain (the d= value) and a selector (s=), a label saying which key was used.

You publish the matching public key in your DNS as a TXT record at selector._domainkey.yourdomain.co.uk. Many email platforms ask you to add CNAME records instead, which point to keys they manage and rotate for you. When a message arrives, the receiving server looks up the public key, checks the signature and records a pass or fail.

For DMARC, a pass is not enough on its own. The signing domain must also match, or align with, the domain in the From address your readers see. That is why a platform signing with its own domain does nothing for you: you need a signature from your own domain or a subdomain of it.

Unlike SPF, DKIM usually survives forwarding, because the signature travels inside the message. It can break if something along the way rewrites the content, such as a mailing list adding a footer.

Why it matters for a UK business

At the time of writing (October 2026), Gmail, Yahoo and Microsoft’s consumer Outlook service all expect bulk senders to authenticate with DKIM, and unsigned messages are more likely to be filtered or rejected. Even a small business sending invoices, booking confirmations and a monthly newsletter is better off signing everything, because inbox providers build your domain’s reputation from authenticated mail.

DKIM is also a foundation for two other things. It lets you move DMARC to enforcement, which stops criminals sending fake invoices in your name, and that enforced DMARC policy is what your logo needs before it can appear through BIMI.

Common mistakes

  • Leaving the email platform on its default shared signature, so DKIM passes but does not align with your From domain.
  • Setting up DKIM for the newsletter tool but forgetting the CRM, help desk, online shop or accounting software that also sends as your domain.
  • Pasting the key into DNS with a line break or a missing character, so it never validates.
  • Staying on an old 1024-bit key when the provider supports 2048-bit.
  • Deleting the old record too soon when changing provider, so messages still in transit fail.

How to act on it

List every service that sends email as your domain. Open each one’s domain or authentication settings, complete the custom DKIM set-up and add the records it gives you at your DNS host. Send a test message to a Gmail account and use “Show original” to confirm DKIM: PASS with your own domain named.

Then publish a DMARC record at p=none to collect reports, which will reveal any sender you missed. If you would like a second view on how email fits into your wider marketing, my digital marketing strategy and consulting service is the place to start.

Do and do not

Do

  • Sign with your own domain on every sending service
  • Use 2048-bit keys where supported
  • Confirm DKIM: PASS in a real message header

Do not

  • Rely on a platform's shared default signature
  • Forget tools that send invoices or alerts
  • Remove an old key before mail in transit has cleared

Questions people ask about this

What is a DKIM selector?

A selector is a label that tells the receiving server which public key to look up, so one domain can hold several DKIM keys at once, typically one per sending service. It appears as s= in the signature and forms the first part of the DNS record name, for example google._domainkey. Your email platform chooses the selector; you publish the record it gives you.

Do I need both SPF and DKIM?

Yes. SPF lists the servers allowed to send for your domain, while DKIM proves each message is signed and unchanged. DMARC only needs one of them to pass and align, but having both means a forwarded message that fails SPF can still pass on DKIM. Large inbox providers expect bulk senders to have both.

How do I check whether DKIM is working?

Send an email to a Gmail address, open it, choose "Show original" and look for DKIM: PASS with your own domain named. Free online checkers can also confirm that a selector's record is published correctly. Once DMARC reporting is switched on, the aggregate reports show DKIM results for all mail sent as your domain.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.