Email security and anti-spoofing
Pages
Page 9 of 14
Create and manage a DKIM record
DKIM provides email authentication, which can be used to give the recipient server confidence an email came from a given address.
When DKIM is in use, the sending email service adds a DKIM signature to its outbound email. The receiving email service retrieves the sender's DKIM public key, which has been published in its DNS records.
The receiving email server verifies the signature on the email using the DKIM public key. If the signature is successfully verified, the DKIM check is marked as passed, which will contribute to the DMARC policy check.
You should configure DKIM on domains you send email from, as it's a stronger authentication mechanism than SPF. It will help recipients validate the legitimacy of email which has passed through an email relay en-route.
If you already have DKIM records
If you already have DKIM records, you'll need to know the DKIM selector to find the record. You can find the selector in the header of any email you send.
Creating a DKIM record and signing email
Generate the key
How you go about creating and implementing a DKIM key will vary depending on your email service. If you use a cloud-based email service, your DKIM configuration will be automated to some extent. Look for a DKIM option in your administration panel, or contact your service provider.
If you are configuring DKIM on your email servers directly, you will need to generate an RSA public/private key pair. We recommend you use a 2048-bit key. There are several good guides on how to generate RSA key pairs for Windows or Linux.
DKIM keys do not expire, but you should rotate them periodically (we suggest every 12 months). Create a new key with a new selector and follow the same steps as above. Keep the old DNS record live for a few days after making changes, to give the DNS time to update.
Create an entry in the public DNS record
Add the DKIM signature to a TXT record in your DNS record. This is made up of a selector (the name of your record), the version, the key type, and the public key itself.
Anyone receiving email which claims to be from you can verify the signature on the email with the key from your DNS. A successful verification proves the message hasn’t been tampered with in transit.
Your DNS record should have the host, or record name of:
selector._domainkey.yourdomain.gov.uk
and the value:
v=DKIM1, k=rsa,
You can check this has been applied using a DKIM lookup service and your selector. The result should look like:
v=DKIM1; k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCG26OM/bk0vNm/TM2DnOQjPZNLIWspF4xtIX12LGHHjfushjsaudfysuf+DUigzM6h2oJMEdNt1S/CWVXW0pUBqfU0fzdw90+jyqOduh4cCnEk0z0w1w1j4xOYy0FLHhKoeoZJwWQFtwrlhrjxD6jM+sGeeRnbn2rQIDAQAB
Apply DKIM signatures to outbound email
How you achieve this will vary, depending on your email service. DKIM signatures may be applied by your filtering service rather than your email server. Ask your service provider for details.
A DKIM signature should be the last addition to a message before it is released by an email server. Since modifying the email or its headers will change its cryptographic hash, it is necessary for any signatures or standard disclaimers to be applied before it is signed with DKIM.
When using email scanning services on outbound email, ensure they are configured in a way that does not break the DKIM signature (e.g. through adding a disclaimer line to the bottom of the email body).
Passing DKIM alignment checks
It is important to check if your DKIM configurations are passing an ‘alignment check’. An alignment check is in addition to the standard DKIM check described above.
What is DKIM alignment?
A DKIM alignment check will simply assess if the domain used in the ‘Header From’ address is the same as the domain used for DKIM signing.
The ‘Header From’ address is the address that the recipient sees (eg [email protected]), whereas the domain used for DKIM signing is often hidden to the recipient. Commonly when you set up a new system, your provider will by default set up DKIM signing of your emails with their domain (eg onmicrosoft.com).
How does DKIM alignment work?
The following are the most common scenarios you will come across for DKIM alignment:
- Emails are failing DKIM alignment. If you are using 'example.co.uk’ in the Header From address, but using ‘onmicrosoft.com’ to DKIM sign your emails, then DKIM alignment will fail in all situations.
- Emails are passing DKIM ‘relaxed’ alignment. Most commonly, the default position if for alignment checks is ‘relaxed’. This means if you are using ‘example.co.uk ’ or a subdomain like ‘mail.example.co.uk’ in the Header From address, and then using ‘example.co.uk' for DKIM signing, then DKIM alignment will pass.
- Emails fail DKIM ‘strict’ alignment. If an organisation has added the term ‘adkim=s’ to their DMARC policy, then alignment checks need to be ‘strict’. A strict alignment policy will mean that the two domains used must be exactly the same. So in this case, if you are using ‘mail.example.co.uk’ in the Header From address, but using ‘example.co.uk ’ for DKIM signing, then this now fails alignment.
How to test and address alignment issues
If you have set up a DMARC reporting tool, any issues with alignment will be raised through that. To fix any issues arising, you will have to consult your technology provider for specific instructions on how to address DKIM alignment issues for your email sending system.


