FAQs
Does ASM validate the DKIM public key?
1 min
dkim helps to prevent your emails being spoofed from your domain by digitally signing all your emails this allows the email header, and sometimes the contents and attachments, from your domain to be checked to verify that that they haven't been changed in transit this process is based on a private key held by the mail server and a corresponding public key published as a dns record when the email is sent, the mail server creates some hashes of the email, signs them with the private key, and attaches them to the email the recipient can look up the public key and use it to verify the signature and hashes, and therefore the email, are unchanged hexiosec asm will validate the dkim dns record (for example, format, key, strength etc ) but it does not currently verify that the public key is actively being used by a matching private key it isn't possible to check this without accessing a dkim signed email, which hexiosec asm does not have access to if you want to find out more about dkim, spf, and dmarc, we have blog on https //hexiosec com/blog/email security/ which you may find helpful, and a more recent blog on https //hexiosec com/blog/email security mta sts/