Security & DNS
DKIM
Cryptographic signing of outbound mail so recipients can verify that a message really came from your domain and was not altered in transit.

Capabilities
What we implement
- Key generation and selector strategy per sending platform
- Signing enabled on tenant, gateway and application senders
- Verification against real message headers
- Scheduled key rotation
Security
How it is hardened
- 2048-bit keys where the platform supports them
- Private keys held only on the signing platform
- Retired selectors removed from the zone
Architecture
DKIM signing and verification flow
Outbound mail is signed at the platform; receivers fetch the public key from your DNS and verify the signature before applying policy.
01 · Key management
Key pair generationSelector naming2048-bit keysRotation scheduleOne selector per sending platform so keys can be rotated independently.
02 · Signing
Tenant signingGateway signingApplication signingEvery legitimate sender signs; unsigned senders are either fixed or retired.
03 · Publication
selector._domainkey TXTPublic key recordRetired selectors removedOld selectors are cleaned out of the zone once traffic has moved.
04 · Verification
Receiver validationHeader inspectionDMARC alignmentVerified against real message headers rather than assumed to be working.
FAQ
DKIM questions we are asked
- How often should DKIM keys be rotated?
- Annually is a reasonable baseline for most organisations, and immediately if a signing platform is suspected of compromise. Rotation is planned so both selectors are valid during the change.
- Does DKIM survive forwarding?
- Usually yes, which is why it matters. As long as the signed headers and body are not altered, the signature validates after a forward where SPF would fail.
- Can one domain have several DKIM keys?
- Yes, and it normally should — a separate selector for the mail tenant, the marketing platform and any application relay.
Related
Other security & dns platforms
DKIM is referenced to describe engineering capability. All trademarks and product names are the property of their respective owners; no partnership or endorsement is implied.
Ready to scope the work?
Share your environment and objectives. You will get an engineering response covering scope, approach and considerations.