Honest Intros Sign in

Glossary

DKIM

DKIM (DomainKeys Identified Mail) is a way for a sending server to sign each message with a private key, so the receiver can check the signature against a public key published in the sender's DNS.

Updated · By Otman Ounana · How we research

Why it matters when you send from your own Gmail

A valid signature shows two things: the message really passed through a server the domain trusts, and its signed headers were not changed on the way. Messages that Google cannot authenticate might be marked as spam or rejected.[1] On a personal Gmail address Google signs for you. On a Google Workspace domain an administrator has to switch signing on and publish the key. Unsubscribe headers matter here too: the standard for one-click unsubscribe requires them to be covered by the signature.[2]

Example

Your administrator generates a key in the Google Workspace admin console and adds the public half to your domain's DNS as a TXT record. From then on every message you send carries a signature that receivers can verify.

What to do

Open the same original headers and look for dkim=pass. If it says none or fail, ask whoever administers your domain to switch signing on, and wait for DNS to update before sending.

Related terms

All terms are on the glossary.

Sources

  1. Google, Email sender guidelines. “Messages that aren’t authenticated with these methods might be marked as spam or rejected with a 5.7.26 error.” Read on 1 October 2026.
  2. IETF, RFC 8058, section 4. “The List-Unsubscribe and List-Unsubscribe-Post headers MUST be covered by the signature and included in the "h=" tag of a valid DKIM-Signature header field.” Read on 1 October 2026.