SPF, DKIM & DMARC Tips
25 articles on the everyday administration of SPF, DKIM and DMARC. Reading records, rolling out policy, working through reports, and the mistakes that break mail without anyone noticing. Written to be read in order, but each one stands alone.
What DKIM actually does
DKIM signs the message itself, so the proof travels with the mail. That is why it survives forwarding when SPF does not.
Start readingSelectors: how one domain holds many DKIM keys
The selector is the label that lets each sending service have its own key under the same domain, and it is what makes rotation possible without downtime.
1 min readPublishing your first DKIM key
Generate a 2048-bit key, publish the public half as a TXT record, enable signing, and verify with a real message before you trust it.
2 min readRotating DKIM keys without dropping mail
Rotation is a four-step overlap: publish the new key, switch signing, wait out mail in flight, then revoke the old one.
5 min readWhy a valid DKIM signature can still fail
DMARC only counts a DKIM pass when the signing domain in d= matches the From domain. Vendors that sign with their own domain pass DKIM and fail DMARC.
2 min readWhy DKIM signatures break in transit
Anything that modifies signed headers or the body invalidates the signature. Mailing lists are the usual culprit, and there is no way to sign around them.
2 min read