security / email authentication / dkim
Email authentication

DKIM

DKIM adds a cryptographic signature to your outgoing email, so receivers can prove the message really came from you and wasn't altered on the way.

Severity if missing
Medium
Category
Email authentication
Standard
RFC 6376

What it is

DKIM (DomainKeys Identified Mail) works with a pair of cryptographic keys. Your mail server signs every outgoing message with a private key, and the matching public key is published in your DNS.

When a receiving server gets the message, it fetches your public key and verifies the signature. If it matches, the receiver knows two things: the mail genuinely came from your domain, and nobody tampered with it in transit.

Why it matters

SPF checks which server sent a message, but it doesn't protect the message itself. DKIM does — its signature covers the actual content, so a forwarded or altered email can be detected. Together with SPF, it's what DMARC relies on to decide whether mail is trustworthy.

The risk
Without DKIM, receivers have no way to verify that your emails are genuine and unmodified. Your mail is easier to spoof and more likely to be flagged as spam.

How Pentrawl checks it

Pentrawl checks your DNS for DKIM public keys under the common selectors used by major mail providers. If it finds a valid DKIM record, the check passes; if none are found, we flag it as a warning, since DKIM may simply be configured under a custom selector.

How to fix it

DKIM is set up through your email provider rather than by hand. Enable DKIM signing in your provider's dashboard, and they will give you a DNS record (a selector and a public key) to publish.

Example DKIM record
selector._domainkey.yourdomain.com. TXT "v=DKIM1; k=rsa; p=MIGfMA0GCSq..."

Related checks

Check your domain's DKIM in seconds
Pentrawl scans this and 20+ other security checks in one automated pass.
Scan your website →