Email Security

DKIM

DomainKeys Identified Mail (DKIM) adds a cryptographic signature to outgoing email headers, allowing receiving servers to verify that the email was sent by an authorized sender and has not been altered in transit. The signature is validated against a public key published in the sender's DNS records. DKIM works alongside SPF and DMARC to form a complete email authentication stack. Without DKIM, emails can be tampered with in transit without detection.

Official documentation

Why it matters for your website

  • 1Prevents your domain from being used in phishing and spoofing attacks
  • 2Required for email deliverability to Gmail, Yahoo, and major providers
  • 3Missing records are flagged as high-severity findings in security audits

Check your site for DKIM issues

Run a free scan to see if your domain has any DKIM-related vulnerabilities or misconfigurations.

Related Terms

Browse Glossary

View all 85 terms

Free Security Scan

See your SSL, headers, CORS, DNS, and email security score in seconds.