DKIM (DomainKeys Identified Mail) is the standard in which the sending server signs a message with a private key on behalf of its domain, and the receiving server verifies that signature with the public key the domain publishes in DNS. The signature proves that the message really came from the domain's authorised systems and was not altered in transit. It is defined in RFC 6376.
This article explains how DKIM works, what a selector is, how to check a domain's DKIM record and the three most common problems.
How does DKIM work?
- The sending server computes a hash over selected headers and the body of the message and signs it with the private key.
- The signature is added to the message as a
DKIM-Signatureheader. Two tags matter: the signing domain (d=) and the selector (s=) that says which key was used. - The receiving server reads the public key from the DNS record
<selector>._domainkey.<domain>and verifies the signature.
A shortened excerpt of a signature header:
DKIM-Signature: v=1; a=rsa-sha256; d=ornek.com.tr; s=selector1; ...
For this message the receiver queries selector1._domainkey.ornek.com.tr.
What is a DKIM selector?
A selector is a name that lets a domain publish more than one key. The mail provider can use one selector and a newsletter service another; during key rotation the old and the new key can stay published side by side. Microsoft 365 uses two selectors for this purpose: selector1 and selector2. Google Workspace uses the google selector by default.
An important limitation: DNS offers no way to list all selectors of a domain. Without the selector name there is no way to find the record. That is why every outside-in DKIM check looks at providers' known selectors and common names.
What does a DKIM record look like?
The public key is published as a TXT record:
selector1._domainkey.ornek.com.tr. IN TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkq..."
| Tag | Meaning |
|---|---|
v=DKIM1 | Version. |
k= | Key type; usually rsa. ed25519 is defined too (RFC 8463). |
p= | Base64-encoded public key. An empty p= means the key has been revoked. |
t=y | The domain is testing DKIM. |
Some providers (such as Microsoft 365) ask for a CNAME instead of a TXT record: your selector name points to a record the provider manages, so the provider can rotate the key without touching your DNS. Details: SPF, DKIM and DMARC in Microsoft 365.
How do you check DKIM?
1. Find the selector in a message header. Open a message sent from your domain and view the headers ("show original" or "message headers"). Note the d= and s= values in the DKIM-Signature line. The same headers also show the receiver's verdict:
Authentication-Results: ... dkim=pass header.d=ornek.com.tr ...
You want dkim=pass with your own domain in header.d=. If the message is signed only with the provider's domain (d= is the provider's domain), DKIM passes but is not aligned for DMARC.
2. Query the record in DNS.
nslookup -type=TXT selector1._domainkey.ornek.com.tr
dig +short TXT selector1._domainkey.ornek.com.tr
If the record is a CNAME, the query returns the CNAME target first and then the TXT record at the target.
3. Assess the key. Is p= empty, is t=y present, how many bits is the key?
What are the common DKIM problems?
No signature at all. This is the most common case. DKIM signing was never enabled at the provider, or it was enabled but the DNS record was never published. Without DKIM, DMARC relies on SPF alone; because forwarded mail fails SPF, moving DMARC to enforcement becomes risky.
Key shorter than 2048 bits. A 1024-bit RSA key is no longer considered strong enough. If the key is broken, an attacker can produce mail that passes DKIM as your domain. The fix is to generate a new 2048-bit key at the provider and update the record.
Testing flag (t=y) left behind. A flag added during setup and never removed. Under RFC 6376, receivers treat mail signed with this key like unsigned mail. If you publish the record yourself, delete the t=y tag and leave the other tags alone. If your provider publishes it (CNAME), turn the flag off in the provider's panel.
The signature breaks in transit. DKIM stays valid as long as the signed headers and the body are unchanged. Mailing lists that tag the subject line or append a footer, and security gateways that rewrite content, break the signature. If your own infrastructure has such an intermediary (e.g. a product that adds a disclaimer or warning to outgoing mail), the DKIM signature must be applied after it.
How do you rotate a DKIM key?
Rotating the key regularly limits the impact of a leaked or weakened key. Selectors make this possible without interruption:
- Generate the new key under a new selector (e.g.
s2026) and publish the public key ats2026._domainkey.ornek.com.tr. - Once the record is visible from outside, switch the sending server to sign with the new selector.
- Keep the old key published for a few more days so that messages in transit can still be verified.
- Then revoke the old key by emptying its
p=value, or delete the record.
With providers that use CNAMEs (such as Microsoft 365), the provider runs these steps; two selectors are used in turn and you only start the rotation from the admin panel. In that case, check that the waiting second key is also 2048 bits; in older setups it may have been left at 1024 bits.
What does Denetta check in DKIM?
Denetta's Domain and Email Security module queries DNS for the known selectors of major mail providers (e.g. selector1, selector2, google) and common selector names; it recognises the mail provider from the MX records and writes the remediation text for it. The relevant rule codes:
- MAIL-010: no DKIM key published (none of the tried selectors has a key).
- MAIL-011: the DKIM key is shorter than 2048 bits.
- MAIL-026: the DKIM key is in testing mode (
t=y).
If you use a different selector name, the MAIL-010 finding says so; once you tell us the selector, the check uses that name. Remediation text is written for your mail provider and DNS hosting provider and is only displayed; Denetta never changes a DNS record.
You can see your DKIM status with the domain security check. It reads only DNS records and produces a pre-check score from 21 rules; the full Domain and Email Security module has 31 rules. For how DKIM works together with DMARC, see What is DMARC?
Frequently asked questions
How do I find my domain's DKIM selector?
Open the headers of a message sent from your domain and look at the s= value in the DKIM-Signature line. Selectors cannot be listed through DNS; you learn them from that header or from your mail provider's admin panel.
Is a 1024-bit key enough for DKIM?
2048-bit RSA is recommended today. A 1024-bit key is considered weak; if it is broken, an attacker can produce mail that passes DKIM as your domain.
What does t=y mean in a DKIM record?
t=y declares that the domain is testing DKIM. Under RFC 6376, receivers then treat signed mail like unsigned mail. Once the setup is finished, the flag should be removed.
Why does DKIM matter for forwarded mail?
Forwarding changes the sending IP address and breaks SPF. A DKIM signature is bound to the message content; as long as the content is unchanged it stays valid after forwarding and lets DMARC pass.