DKIM (DomainKeys Identified Mail) adds a cryptographic signature header to each message. The public key lives in DNS under a selector, and receivers verify the signature to confirm the message was not altered and was authorized by the signing domain.
Checkers and validators#
Free lookup tools confirm that records resolve and are syntactically valid. Primary Deliverability runs SPF, DKIM, DMARC, and BIMI checks in one report and flags alignment problems.
Provider dashboards#
Google Postmaster Tools and Microsoft SNDS are free and authoritative for their networks. Register every sending domain and IP.
Report analyzers and monitoring#
DMARC aggregate reports are XML and unreadable by hand; an analyzer turns them into a per-source view. Monitoring services alert on reputation drops, blocklistings, and record changes.
Sending platforms#
Your ESP or outreach tool should expose authentication setup, bounce and complaint handling, and per-mailbox limits. For AI-drafted sequences with reply detection, Mailflow in MailMaid Engine handles the sending side.
How to choose#
- Start with the free provider dashboards and a checker.
- Add a DMARC analyzer once you have more than two sending sources.
- Add monitoring when email is revenue-critical.
- Choose sending platforms by their deliverability controls, not template libraries.
Frequently asked questions#
What is a DKIM selector?
A label that lets one domain publish multiple keys. The selector appears in the s= tag and forms the DNS name selector._domainkey.domain.
Why does DKIM pass but DMARC fail?
Alignment. DMARC requires the d= domain to match the From header domain. If your vendor signs with their own domain, set up a custom DKIM domain with them.
Can I use one DKIM key for all my ESPs?
You can publish separate selectors per vendor. Never share private keys between platforms.