Blog article

29 Jul 20264 minutes read

Waseem OsmanWaseem OsmanDMARC Enthusiast

DKIM Signature: How Generation and Key Compromise Work at Scale

A Blue Digital Key In Cyber Space With Data Lines Flowing Behind It

DKIM signature overview:

  • A DKIM signature is a base64-encoded cryptographic signature, generated using a private key
  • DKIM canonicalization controls how much message reformatting a signature can tolerate
  • A compromised key lets an attacker forge signed messages until it’s rotated and revoked
  • PermError: The receiving server can’t verify the signature. Common causes include an invalid record or a missing key. This typically indicates a configuration problem.
  • Temp Error: The verifying server couldn’t complete the DNS lookup at the time of delivery. This is usually transient. These failures often self-resolve but should be monitored for patterns.
  • fail: The signature can’t be evaluated. This is the result of a syntax error or a missing key.
  • none: No DKIM signature is present. This isn’t a validation failure; it’s an absence. DMARC still treats it as a DKIM failure.

Share

Get our latest blogs delivered to your inbox each month

Leave a reply

Your email address will not be published. Required fields are marked *

Useful Tools

DNS Lookup
Free toolNo sign-up

DNS Lookup

Use Sendmarc's DNS lookup tool to instantly analyze domain records, verify configurations, and detect DNS issues for better performance.

Email Header Analyzer
Free toolNo sign-up

Email Header Analyzer

Quickly analyze email headers with Sendmarc’s email header analyzer. Check SPF, DKIM, and DMARC results, detect phishing, and improve email deliverability.

Domain Checker
Free toolNo sign-up

Domain Checker

Use the Sendmarc domain checker to test against malicious use - free, no sign-up required, with results in under a minute.