Does ASM validate the DKIM public key?
DKIM helps to prevent your emails being spoofed from your domain by digitally signing all your emails. This allows the email header, and sometimes the contents and attachments, from your domain to be checked to verify that that they haven't been changed in transit. This process is based on a private key held by the mail server and a corresponding public key published as a DNS record. When the email is sent, the mail server creates some hashes of the email, signs them with the private key, and attaches them to the email. The recipient can look up the public key and use it to verify the signature and hashes, and therefore the email, are unchanged.
Hexiosec ASM will validate the DKIM DNS record (for example, format, key, strength etc.) but it does not currently verify that the public key is actively being used by a matching private key. It isn't possible to check this without accessing a DKIM-signed email, which Hexiosec ASM does not have access to.
If you want to find out more about DKIM, SPF, and DMARC, we have blog on email security basics which you may find helpful, and a more recent blog on improving email security with MTA-STS.