What this check looks at
DKIM (DomainKeys Identified Mail) attaches a signature to the message, computed with a private key the sender holds. The receiver fetches the matching public key from DNS and verifies it - proving the mail genuinely came from the signing domain and wasn't altered in transit. For each signature on your test message, JoltMx records:
- The verification verdict - did the signature actually verify against the body and headers as received?
- The signing domain and selector (e.g.
selector._domainkey.example.com). - The strength of the published key - revoked, algorithm, and RSA key size.
Why it matters
DKIM is the authentication that survives forwarding, as long as the message body and signed headers aren't modified. Major providers require it for bulk senders and weigh it heavily for everyone else. A failing signature is worse than none at all - it suggests the message was tampered with or the published key is wrong. And a weak key (under 1024 bits) is simply rejected by most verifiers.
How the diagnostic grades it
| Result | Severity | What it means |
|---|---|---|
| Signature verified | Pass | A valid signature proves the message is authentic and unaltered. |
| Key strength: Ed25519 / RSA ≥ 2048-bit | Pass | Modern, strong key. |
| Signature failed verification | Critical | The signature didn't verify - tampering or a wrong published key. |
| RSA key under 1024-bit | Critical | Rejected by most verifiers. Rotate to a 2048-bit key. |
| Message is not DKIM-signed | Warning | No signature at all. Configure your server or provider to sign. |
| No valid signature | Warning | Signatures were present but none verified. |
| RSA key is 1024-bit | Warning | Still accepted but weak. Rotate to 2048 bits. |
Key is revoked (empty p=) | Warning | The published key was deliberately emptied. |
| Key lookup failed temporarily | Info | DNS was briefly unavailable. Re-test. |
How to fix it
- Turn on DKIM signing in your mail server or sending provider. With JoltMx, a unique key is generated per domain when you add it - you publish the record once and we sign on every send.
- Use a 2048-bit RSA key (or Ed25519 where supported) and rotate older 1024-bit keys.
- If a signature is failing, check that nothing in your pipeline rewrites the body or signed headers after signing (some gateways and list servers do).
Related checks
SPF · DMARC · ARC · From alignment · SPF, DKIM & DMARC explained