DKIM protects signed content against later modification
DKIM signs parts of an email so the recipient can tell it has not been altered since it left the sending domain.
It proves the message is unmodified and genuinely associated with that domain. It says nothing about whether the content is honest, and it does not cover everything in the message, so what was signed matters. A valid signature is evidence of origin, not of good intent.
More on Email security
- DMARC depends on alignmentBoth names, or neither
- Forwarding can break email authentication assumptionsIt was re-posted on the way
- A display name is not an email addressThey wrote that name themselves
- Reply-chain hijacking borrows existing trustTrust borrowed from the thread
- Secure email gateways see only traffic that reaches themIt only sees what comes past it
- Quarantine creates a second security decisionHeld is not decided
