DMARC Analyzer

What is DKIM?

DKIM (DomainKeys Identified Mail, RFC 6376) attaches a DKIM-Signature header to outgoing mail, signed with a private key the sending domain controls. The receiver fetches the matching public key from a DNS TXT record at <selector>._domainkey.<domain> and verifies the signature, which also covers key headers and (usually) the body — so DKIM additionally proves the message wasn't tampered with in transit, unlike SPF.

Unlike SPF (tied to the sending IP), DKIM signatures survive being relayed through intermediate servers, which is why forwarded mail is more likely to still pass DKIM than SPF.

References