Skip to content

Security & DNS

DKIM

Cryptographic signing of outbound mail so recipients can verify that a message really came from your domain and was not altered in transit.

DKIM signing key module with an illuminated key indicator beside a corporate mail server
SYSTEM ACTIVE
MESSAGE SIGNING · DKIM

Capabilities

What we implement

  • Key generation and selector strategy per sending platform
  • Signing enabled on tenant, gateway and application senders
  • Verification against real message headers
  • Scheduled key rotation

Security

How it is hardened

  • 2048-bit keys where the platform supports them
  • Private keys held only on the signing platform
  • Retired selectors removed from the zone

Architecture

DKIM signing and verification flow

Outbound mail is signed at the platform; receivers fetch the public key from your DNS and verify the signature before applying policy.

  1. 01 · Key management

    Key pair generationSelector naming2048-bit keysRotation schedule

    One selector per sending platform so keys can be rotated independently.

  2. 02 · Signing

    Tenant signingGateway signingApplication signing

    Every legitimate sender signs; unsigned senders are either fixed or retired.

  3. 03 · Publication

    selector._domainkey TXTPublic key recordRetired selectors removed

    Old selectors are cleaned out of the zone once traffic has moved.

  4. 04 · Verification

    Receiver validationHeader inspectionDMARC alignment

    Verified against real message headers rather than assumed to be working.

FAQ

DKIM questions we are asked

How often should DKIM keys be rotated?
Annually is a reasonable baseline for most organisations, and immediately if a signing platform is suspected of compromise. Rotation is planned so both selectors are valid during the change.
Does DKIM survive forwarding?
Usually yes, which is why it matters. As long as the signed headers and body are not altered, the signature validates after a forward where SPF would fail.
Can one domain have several DKIM keys?
Yes, and it normally should — a separate selector for the mail tenant, the marketing platform and any application relay.

Related

Other security & dns platforms

DKIM is referenced to describe engineering capability. All trademarks and product names are the property of their respective owners; no partnership or endorsement is implied.

Ready to scope the work?

Share your environment and objectives. You will get an engineering response covering scope, approach and considerations.