DKIM check

DKIM is a tamper-proof cryptographic signature on each message. This check confirms every signature actually verified, and that the key it relies on is strong enough to trust.

What this check looks at

DKIM (DomainKeys Identified Mail) attaches a signature to the message, computed with a private key the sender holds. The receiver fetches the matching public key from DNS and verifies it - proving the mail genuinely came from the signing domain and wasn't altered in transit. For each signature on your test message, JoltMx records:

  • The verification verdict - did the signature actually verify against the body and headers as received?
  • The signing domain and selector (e.g. selector._domainkey.example.com).
  • The strength of the published key - revoked, algorithm, and RSA key size.

Why it matters

DKIM is the authentication that survives forwarding, as long as the message body and signed headers aren't modified. Major providers require it for bulk senders and weigh it heavily for everyone else. A failing signature is worse than none at all - it suggests the message was tampered with or the published key is wrong. And a weak key (under 1024 bits) is simply rejected by most verifiers.

How the diagnostic grades it

ResultSeverityWhat it means
Signature verifiedPassA valid signature proves the message is authentic and unaltered.
Key strength: Ed25519 / RSA ≥ 2048-bitPassModern, strong key.
Signature failed verificationCriticalThe signature didn't verify - tampering or a wrong published key.
RSA key under 1024-bitCriticalRejected by most verifiers. Rotate to a 2048-bit key.
Message is not DKIM-signedWarningNo signature at all. Configure your server or provider to sign.
No valid signatureWarningSignatures were present but none verified.
RSA key is 1024-bitWarningStill accepted but weak. Rotate to 2048 bits.
Key is revoked (empty p=)WarningThe published key was deliberately emptied.
Key lookup failed temporarilyInfoDNS was briefly unavailable. Re-test.

How to fix it

  • Turn on DKIM signing in your mail server or sending provider. With JoltMx, a unique key is generated per domain when you add it - you publish the record once and we sign on every send.
  • Use a 2048-bit RSA key (or Ed25519 where supported) and rotate older 1024-bit keys.
  • If a signature is failing, check that nothing in your pipeline rewrites the body or signed headers after signing (some gateways and list servers do).

Related checks

SPF · DMARC · ARC · From alignment · SPF, DKIM & DMARC explained

Free during beta

Start routing mail in minutes.

Point your MX records at JoltMx. Add a domain. Create your first rule. Done.

No credit card required  ·  Free tier stays free