Skip to content
FormReceipt

Email deliverability

DKIM signing explained

DomainKeys Identified Mail: cryptographic signatures, selectors, and DNS TXT publishing.

Published: 2026-05-01Last reviewed: 2026-05-01

What DKIM does

DKIM adds a cryptographic signature to outgoing messages. Receivers fetch the public key from DNS (via the selector) and verify the message was not altered in transit.

Selectors

Providers publish keys under names like selector1._domainkey.example.com. Rotating keys usually means adding a new selector and migrating sending systems before retiring the old key.

Alignment

For DMARC to pass on DKIM, the signing domain often needs to align with the From domain depending on your DMARC policy mode—pair DKIM setup with your SPF and DMARC records.

FAQ

What does a DKIM selector name control?
It tells receivers which DNS TXT record holds the public key used to verify signatures for your outbound mail stream.
Can DKIM alone guarantee inbox placement?
No. DKIM proves message integrity and supports DMARC alignment, but receivers still apply spam filtering, reputation, and policy beyond authentication.

← Email deliverabilityKnowledge base home← Back to home

Cookie choices

We use a required session cookie for login and optional analytics cookies for marketing pages. Read cookie policy