In plain English
Each message is signed with a private key, and the matching public key is published in your DNS. The receiving server verifies the signature, confirming the message came from your domain and was not altered.
Unlike SPF it survives forwarding, which makes it the stronger of the two checks.
What to know
Cryptographic signature
Applied to each outgoing message.
Public key in DNS
Used by receivers to verify.
Survives forwarding
Where SPF often fails.
Per sending service
Each platform needs its own key published.
Why it matters
DKIM is what allows a receiver to trust that the message genuinely originated from your domain. It is also required for DMARC to be useful.
Common mistakes
×Not enabling DKIM on every sending platform.
×Keys that expire or are rotated without updating DNS.
×Assuming the email platform published the record for you.
×Weak key lengths on older setups.
FAQs
Is DKIM better than SPF?
Stronger, and complementary. You need both.
Do I need a separate DKIM key per service?
Yes, one per sending platform, each published in DNS.
WRITTEN BY TARIQ SALLAM
Marketing Consultant. Entrepreneur. Content Creator.
I'm a marketing consultant, entrepreneur and content creator. I help businesses grow through practical marketing, websites, SEO, content and AI.
More About Tariq →