DKIM
DKIM adds a cryptographic signature to your outgoing email, so receivers can prove the message really came from you and wasn't altered on the way.
What it is
DKIM (DomainKeys Identified Mail) works with a pair of cryptographic keys. Your mail server signs every outgoing message with a private key, and the matching public key is published in your DNS.
When a receiving server gets the message, it fetches your public key and verifies the signature. If it matches, the receiver knows two things: the mail genuinely came from your domain, and nobody tampered with it in transit.
Why it matters
SPF checks which server sent a message, but it doesn't protect the message itself. DKIM does — its signature covers the actual content, so a forwarded or altered email can be detected. Together with SPF, it's what DMARC relies on to decide whether mail is trustworthy.
How Pentrawl checks it
Pentrawl checks your DNS for DKIM public keys under the common selectors used by major mail providers. If it finds a valid DKIM record, the check passes; if none are found, we flag it as a warning, since DKIM may simply be configured under a custom selector.
How to fix it
DKIM is set up through your email provider rather than by hand. Enable DKIM signing in your provider's dashboard, and they will give you a DNS record (a selector and a public key) to publish.
selector._domainkey.yourdomain.com. TXT "v=DKIM1; k=rsa; p=MIGfMA0GCSq..."