SiteAlertAI SiteAlertAI
๐Ÿ›ฐ Web Scan ๐Ÿ”’ SSL/TLS ๐Ÿ“ฌ MX Record โœ‰ Email Header ๐ŸŽฃ URL Check ๐ŸŒ IP Geo
๐Ÿ›ฐ Web Scan ๐Ÿ”’ SSL/TLS ๐Ÿ“ฌ MX Record โœ‰ Email Header ๐ŸŽฃ URL Check ๐ŸŒ IP Geo
โ† All articles
Email Security 2026-02-04 ยท 4 min read

DKIM: How a Cryptographic Signature Proves Your Email Is Real

DomainKeys Identified Mail (DKIM) attaches a cryptographic signature to every message you send. The receiving server fetches your public key from DNS and verifies the signature, proving the message genuinely came from your domain and was not altered in transit.

How it works

  • Your mail provider signs outgoing mail with a private key.
  • A matching public key is published as a DNS TXT record at a selector (for example selector1._domainkey.yourdomain.com).
  • Receivers verify the signature against that key.

Best practice

Use a 2048-bit key where your provider supports it, rotate keys periodically, and make sure every sending service (marketing platform, ticketing system, CRM) has its own DKIM set up โ€” unsigned mail from a forgotten service is a common deliverability problem. DKIM, SPF and DMARC together form the modern email-authentication stack.

Put this into practice
Run a free, private scan โ€” no login, nothing stored.
๐Ÿ›ก Web Scan ๐Ÿ”’ SSL/TLS ๐Ÿ“ฌ MX & Email ๐ŸŽฃ URL Check

Related articles

Email Security SPF Records Explained: Stop Others Spoofing Your Email SPF tells the world which servers may send mail for your domain. Here is how to write one that actually protects you. Email Security DMARC: The Policy That Ties SPF and DKIM Together DMARC tells receivers what to do with mail that fails authentication โ€” and reports who is sending as you. Here is how to roll it out. Email Security How Email Spoofing Works โ€” and How to Read a Header The "From" address is trivially faked. Learn how spoofing works and how the headers reveal a message's true origin.
SiteAlertAI · © 2026 All rights reserved · Built for security professionals and developers.
Blog Guides Privacy Terms About Contact Social

⚠ For authorised security testing only. Scanning domains you do not own may violate laws in your jurisdiction. SiteAlertAI accepts no liability for misuse. CVE data is indicative โ€” verify with NVD.