A DKIM record, short for DomainKeys Identified Mail record, is a type of Domain Name System (DNS) TXT record that stores the public key used to verify the digital signature in an email message. DKIM is an essential email authentication protocol that helps prevent spoofing and ensures message integrity.
A DKIM record enables receiving mail servers to confirm that an email was not altered in transit and that an authorized domain sent it. It works by using cryptographic keys:
When a receiving mail server processes an email, it retrieves the DKIM public key from the sender’s domain DNS to verify the email’s digital signature. If the signature matches, the email passes DKIM authentication.
The DKIM process involves these steps:
The DKIM record is stored in DNS under a selector, which allows multiple keys for different services or purposes.
DKIM records are critical for:
Without a valid DKIM record, messages may fail authentication and risk being blocked or filtered into spam.
DKIM records are widely used for:
Example scenario: A company adds a DKIM record for its domain when configuring Google Workspace or Microsoft 365. This ensures all outbound emails include a verifiable digital signature, reducing the risk of being flagged as spam.
Check your DNS settings or use online lookup tools to view the DKIM TXT record associated with your domain.
Yes. Multiple selectors allow separate DKIM keys for different services or servers.
No. DKIM improves authentication and trust, but deliverability also depends on SPF, DMARC, list quality, and engagement.
Verify all your emails, even Catch-alls in real-time with our Email Verification Software.
Create an account for free.