E-Mail-Authentifizierung & DMARC9 min read3 sections

DKIM (DomainKeys Identified Mail)

Understanding DKIM: how cryptographic signatures protect email integrity, key management, and selector strategies.

01

What is DKIM?

DKIM (DomainKeys Identified Mail) is an email authentication protocol defined in RFC 6376. It uses public-key cryptography to sign emails, allowing receivers to verify that the email was sent by the domain it claims to be from and that it wasn't modified in transit.

How DKIM Works

  1. Key Generation: The domain owner generates a public/private key pair.
  2. DNS Publication: The public key is published as a DNS TXT record at selector._domainkey.example.com.
  3. Signing: When sending an email, the mail server uses the private key to create a cryptographic signature of specific email headers and the body.
  4. Signature Header: The signature is added as a DKIM-Signature header to the email.
  5. Verification: The receiving server extracts the selector and domain from the signature, retrieves the public key from DNS, and verifies the signature.

The DKIM-Signature Header

DKIM-Signature: v=1; a=rsa-sha256; d=example.com; s=selector1;
  c=relaxed/relaxed; q=dns/txt;
  h=from:to:subject:date:message-id:content-type;
  bh=2jUSOH9NhtVGCQWNr9BrIAPreKQjO6Sn7XIkfJVOzv8=;
  b=AuUoFEfDxTDkHlLXSZEpZj79LICEps6eda7W3deTVFOk2JwA0...
TagDescriptionExample
vVersion (always 1)v=1
aSigning algorithma=rsa-sha256
dSigning domaind=example.com
sSelector (points to the DNS key record)s=selector1
cCanonicalization (header/body)c=relaxed/relaxed
hSigned headersh=from:to:subject:date
bhBody HashBase64-encoded hash of the body
bSignature dataBase64-encoded cryptographic signature
02

DKIM Selectors & Key Management

A selector is a string that identifies which DKIM key to use. This allows a domain to have multiple DKIM keys simultaneously — essential for key rotation and third-party sender support.

Common Selector Patterns

  • Google Workspace: google._domainkey.example.com
  • Microsoft 365: selector1._domainkey.example.com and selector2._domainkey.example.com
  • Amazon SES: Generates three selectors like abc123._domainkey.example.com
  • Custom: Often default._domainkey.example.com or mail._domainkey.example.com

Key Rotation Best Practices

  1. Use 2048-bit RSA keys minimum (1024-bit is considered weak).
  2. Rotate keys regularly (every 6-12 months).
  3. When rotating: publish the new key first, then switch the signing, then remove the old key after the old signatures expire.
  4. Use meaningful selector names that include a date or version: s2024q1._domainkey.example.com.
  5. Consider Ed25519 keys for better performance (supported by newer implementations).
Why multiple selectors? If your domain sends email through Google Workspace AND Amazon SES, each service needs its own DKIM key. Selectors allow both to coexist without conflict.
03

Common DKIM Issues

Issue 1: Body Modified in Transit

Mailing lists, forwarding services, and some security gateways modify the email body (e.g., adding footer text). This invalidates the DKIM Body Hash, causing a failure. Use c=relaxed/relaxed Canonicalization to be more tolerant of minor modifications.

Issue 2: DNS Key Not Found

If the receiving server cannot find the DKIM Public Key in DNS, verification fails. Common causes:

  • Typo in the selector name
  • DNS propagation delay after adding the key
  • Key record too long for a single DNS TXT entry (split into multiple strings)

Issue 3: Key Size Too Small

A 512-bit or 768-bit key is trivially breakable. Most modern receivers will reject signatures made with keys smaller than 1024 bits. Use 2048-bit minimum.

Issue 4: Third-Party DKIM Not Aligned

If a third-party service signs with d=thirdparty.com instead of d=yourdomain.com, DKIM passes but DMARC Alignment fails. Make sure your third-party services support signing with your domain (custom DKIM setup).