Skip to main content
Guidance

Email security and anti-spoofing

A guide for IT managers and systems administrators

Page 9 of 14

Create and manage a DKIM record

DKIM provides email authentication, which can be used to give the recipient server confidence an email came from a given address.

When DKIM is in use, the sending email service adds a DKIM signature to its outbound email. The receiving email service retrieves the sender's DKIM public key, which has been published in its DNS records.

The receiving email server verifies the signature on the email using the DKIM public key. If the signature is successfully verified, the DKIM check is marked as passed, which will contribute to the DMARC policy check.

You should configure DKIM on domains you send email from, as it's a stronger authentication mechanism than SPF. It will help recipients validate the legitimacy of email which has passed through an email relay en-route.

If you already have DKIM records

If you already have DKIM records, you'll need to know the DKIM selector to find the record. You can find the selector in the header of any email you send.



Published

Reviewed

Version

2.0