{"id":18392,"date":"2026-09-29T23:17:28","date_gmt":"2026-09-29T20:17:28","guid":{"rendered":"https:\/\/www.hyyat.com\/knowledgebase\/what-is-dkim\/"},"modified":"2026-09-29T23:17:28","modified_gmt":"2026-09-29T20:17:28","password":"","slug":"what-is-dkim","status":"publish","type":"docs","link":"https:\/\/www.hyyat.com\/en\/knowledgebase\/what-is-dkim\/","title":{"rendered":"What Is a DKIM Record and How Does It Protect Your Email?"},"content":{"rendered":"<div class=\"hy-tldr\" style=\"background:#f6f7fb;border-left:4px solid #d83954;border-radius:10px;padding:14px 18px;margin:0 0 20px;line-height:1.8\"><strong>In short:<\/strong> DKIM adds a digital signature to your emails: the sending server signs each message with a private key, and the receiving server checks the signature with the public key published in a TXT record in your domain&#8217;s DNS. It proves the message really came from your domain and was not changed, so fewer of your emails land in spam and it becomes harder to spoof your domain.<\/div>\n<p><img decoding=\"async\" src=\"https:\/\/www.hyyat.com\/zasogooh\/2019\/11\/email-deliverability.png.12cefe9b943d1b272457809589a0186f.png\" alt=\"DKIM and email deliverability\" \/><\/p>\n<p>Are your emails, or your marketing campaigns, ending up in spam folders? A DKIM record is one of the first things to check.<\/p>\n<h2>What is DKIM?<\/h2>\n<p>DKIM (DomainKeys Identified Mail) is an email authentication method that adds a digital signature to every message you send. It confirms that the email comes from a trusted source and was not changed on its way between the sending and receiving servers.<\/p>\n<p>A private\/public key pair is used. The private key signs the email, and the public key is published in your domain&#8217;s DNS as a TXT record, so receiving servers can use it to verify your emails.<\/p>\n<h2>Is it important?<\/h2>\n<p>Yes. Email was not designed with security in mind, so it is easy to send messages that appear to come from a legitimate address (email spoofing). For example, the recipient sees the sender as example@hyyat.com, while the message actually came from somewhere else. This trick is common in phishing and spam.<\/p>\n<p>With DKIM, the receiving server can check that a message claiming to be from your domain really came from it, which makes it much harder to impersonate your brand. Authenticated email also builds your domain&#8217;s reputation with email providers, which helps keep your messages out of spam.<\/p>\n<h2>How does it work?<\/h2>\n<ol>\n<li>The sending server turns the message headers and body into a hash (a unique string), then signs the hash with the private key.<\/li>\n<li>The receiving server sees the DKIM signature on the incoming email.<\/li>\n<li>It fetches the public key from your domain&#8217;s DKIM TXT record and uses it to check the signature.<\/li>\n<li>It creates its own hash of the message. If the two match, the email is genuine and was not changed.<\/li>\n<\/ol>\n<p>DKIM works best together with SPF and DMARC. See how to enable SPF and DKIM in cPanel and <a href=\"https:\/\/www.hyyat.com\/en\/knowledgebase\/why-website-emails-go-to-spam\/\">why website emails go to spam<\/a>.<\/p>\n<p class=\"hy-svc-link\" style=\"background:#fff5f7;border-left:4px solid #d83954;border-radius:10px;padding:14px 18px;margin:20px 0;line-height:1.8\"><strong>Related service:<\/strong> <a href=\"https:\/\/www.hyyat.com\/en\/business-hosting\/\">Hyyat Host business hosting<\/a> gives you professional email on your own domain with SPF and DKIM set up, plus 24\/7 support.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In short: DKIM adds a digital signature to your emails: the sending server signs each message with a private key, and the receiving server checks the signature with the public key published in a TXT record in your domain&#8217;s DNS. It proves the message really came from your domain and was not changed, so fewer [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","template":"","meta":{"inline_featured_image":false,"_templately_pack_id":"","_templately_imported_at":"","_templately_source":"","_templately_import_session_id":"","footnotes":""},"doc_category":[2734],"doc_tag":[],"class_list":["post-18392","docs","type-docs","status-publish","hentry","doc_category-whm-cpanel-control-panels"],"year_month":"2026-10","word_count":399,"total_views":"1","reactions":{"happy":"0","normal":"0","sad":"0"},"author_info":{"name":"ahmed fathy","author_nicename":"ahmed-fathy","author_url":"https:\/\/www.hyyat.com\/en\/author\/ahmed-fathy\/"},"doc_category_info":[{"term_name":"whm\/cpanel control panels","term_url":"https:\/\/www.hyyat.com\/en\/kb\/whm-cpanel-control-panels\/"}],"doc_tag_info":[],"knowledge_base_info":[],"knowledge_base_slug":[],"_links":{"self":[{"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/docs\/18392","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/types\/docs"}],"author":[{"embeddable":true,"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/comments?post=18392"}],"version-history":[{"count":0,"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/docs\/18392\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/media?parent=18392"}],"wp:term":[{"taxonomy":"doc_category","embeddable":true,"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/doc_category?post=18392"},{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/doc_tag?post=18392"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}