Patchkit

Learn

What is DKIM?

DKIM signs each message so receivers can verify it came from you and wasn't changed along the way.

How signing works

Your email service signs selected headers and the body with a private key. The matching public key is published in DNS. Receivers fetch it and check the signature. If anything was altered, the check fails.

Selectors

The public key lives at selector._domainkey.yourdomain.com. The selector lets one domain have several keys, one per service or per rotation. You'll find it in the s= tag of the DKIM-Signature header in any message you sent.

Why DKIM matters for DMARC

Newsletter and help-desk tools usually send with their own return-path, so SPF can't align with your domain. When they sign with your domain's DKIM key, DMARC passes anyway. That's why these services ask you to add CNAME or TXT records under _domainkey.

Key length

Use 2048-bit RSA keys. 1024-bit keys still verify but are considered weak, and keys shorter than that may be ignored. When you rotate, keep the old selector published for a few days so mail already in transit still verifies.

Look up your keys with the DKIM checker.