1. The Cryptographic Architecture of DKIM (RFC 6376)
DomainKeys Identified Mail (DKIM), formalized under RFC 6376, is an industry-standard asymmetric cryptographic authentication protocol. DKIM provides two essential security guarantees for email communications: Sender Domain Authentication and Message Tamper Resistance.
When an outbound email is dispatched by your mail transfer agent (MTA), the signing engine generates a cryptographic digest (hash) of the email's core headers (including From, To, Subject, and Date) and the body content using the SHA-256 algorithm. The MTA then encrypts this digest using your confidential RSA Private Key and attaches the resulting digital signature into the message headers under the DKIM-Signature field.
When the destination server receives the email, it extracts the selector and domain tags (s=mail; d=yourdomain.com) from the signature header, retrieves the corresponding RSA Public Key published in your DNS zone at mail._domainkey.yourdomain.com, and decrypts the signature. If the calculated hash matches the decrypted signature exactly, the email is certified authentic and unaltered.
2. Anatomy of the DKIM-Signature Email Header
An authentic DKIM header contains multiple standardized tags defined under RFC 6376:
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yourdomain.com; s=mail; t=1724284800; h=from:to:subject:date:message-id; bh=47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=; b=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...v=1: Identifies the DKIM specification version.a=rsa-sha256: The cryptographic signing algorithm (RSA with SHA-256).c=relaxed/relaxed: Canonicalization algorithms applied to headers and body.d=yourdomain.com: The organizational signing domain.s=mail: The selector name used to locate the public key in DNS.bh=: The Base64-encoded hash of the canonicalized email body.b=: The digital cryptographic signature over the headers and body hash.
3. Safe Key Rotation Strategies and Best Practices
To maintain robust cryptographic posture, organizations should rotate DKIM keys every 6 to 12 months. Never overwrite an active selector key in DNS without transitioning mail flows first:
2026b) and publish its TXT public key at 2026b._domainkey.domain.com.2026b.4. Frequently Asked Questions (DKIM Cryptography FAQ)
How does IncogSay generate DKIM keys securely?
IncogSay uses the native W3C Web Cryptography API (window.crypto.subtle) built directly into your browser engine. Cryptographic key pairs are mathematically computed on your local CPU. The private key is never transmitted across any network or saved on our servers.
Why is a 2048-bit DKIM key mandatory in 2026?
1024-bit RSA keys are cryptographically vulnerable to prime factorization attacks by modern GPU clusters and cloud compute. Google, Yahoo, and Microsoft enforce 2048-bit RSA signatures as mandatory for trusted deliverability.
What is a DKIM selector?
A DKIM selector is an alphanumeric string (e.g. 'google', 'selector1', 'mail') that allows a single domain to publish multiple distinct DKIM public keys in DNS simultaneously. Selectors enable key rotation without service disruption and support multiple independent sending services.
What is the difference between DKIM and SPF?
SPF authenticates the connecting IP address of the sending server against a DNS whitelist. DKIM attaches a digital cryptographic signature to the email headers and body itself. DKIM survives email forwarding through mailing lists and intermediate relays where SPF typically breaks.
How often should DKIM keys be rotated?
Industry security frameworks (such as NIST and M3AAWG) recommend rotating DKIM keys every 6 to 12 months. When rotating, publish the new selector key in DNS first, verify propagation, switch your mail server to sign with the new key, and retire the old selector after 14 days.
What is DKIM Canonicalization (c=relaxed/relaxed)?
Canonicalization specifies how email headers and message bodies are normalized before calculating the cryptographic hash. The 'relaxed/relaxed' algorithm ignores minor whitespace modifications and header case alterations introduced during transit, preventing false signature verification failures.
What is a DKIM selector and how do I name it?
A DKIM selector is a label you choose that identifies which public key to use for verification. It is published at [selector]._domainkey.yourdomain.com. Common naming conventions include the year (e.g. '2026'), a descriptive tag ('mail', 's1', 'google'), or a date string ('20260101'). You can have multiple active selectors simultaneously.
What is BYODKIM (Bring Your Own DKIM) in Amazon SES?
BYODKIM allows you to generate your own RSA key pair and provide the public key directly to Amazon SES, instead of using Easy DKIM's auto-generated 3-CNAME approach. Use this when you need direct control over your cryptographic key material for compliance or audit requirements.
Why should I use 2048-bit DKIM keys instead of 1024-bit?
NIST SP 800-131A and RFC 8301 deprecated 1024-bit RSA keys. Major inbox providers including Gmail began rejecting messages signed with 1024-bit DKIM keys. 2048-bit RSA keys provide significantly stronger security against factorization attacks and are the current industry minimum requirement.
Can I verify my DKIM is working after publishing the DNS record?
Yes. Use IncogSay's DKIM Checker to perform a live DNS lookup of your selector and validate that the TXT record resolves, the key parses correctly, and the key size meets RFC 8301 minimums. Also send a test email and check the Authentication-Results header in Gmail to confirm DKIM=pass.
Does DKIM protect against phishing if the attacker controls a different domain?
DKIM alone does not prevent domain lookalike phishing (e.g. amaz0n.com). DKIM validates that the email was signed by the sender's domain, but the attacker's domain can have its own valid DKIM. DMARC with p=reject is what enforces that the From: header domain must match the DKIM signing domain.
Where is the DKIM private key stored and who can access it?
The DKIM private key must be stored securely on your mail transfer agent (MTA) server — in Postfix, typically at /etc/opendkim/keys/yourdomain.com/. Only the mail server process needs read access. Never upload your private key to any third-party tool or store it in a publicly accessible location.
What happens to emails already in transit when I rotate DKIM keys?
Emails already sent and in the delivery queue are signed with the old private key. Receiving servers will validate them against the old selector's DNS record. This is why you must keep the old selector in DNS for at least 14 days after rotation — to allow delayed or queued messages to verify successfully before you delete the obsolete record.
Is there a size limit on DKIM TXT records in DNS?
DNS TXT records have a 255-character limit per string, but can contain multiple strings concatenated together. 2048-bit RSA public keys exceed this limit and are split across multiple quoted strings in the TXT record (e.g. p=MIIBIjAN...""BgkqhkiG...). Most DNS management tools handle this automatically. Verify the full key is present using IncogSay's DKIM Checker.