Skip to content
Skip to main content
Email Evidence Technical Explainer

Does successful DKIM prove the named sender wrote it?

No. A valid DKIM result can support that a domain's signing system signed the message and that the signed material still validates.

It does not identify the human author shown in the From field.

The short version
DKIM authenticates a domain-level signing act, not a person. Treat it as evidence about the message's signing route and integrity, then continue into the account, service or person responsible for causing the message to be sent.

What is DKIM actually checking?

A DKIM signature is added by a sending system. The receiving system uses a public key published for the signing domain to test the signature.

A simplified signature may contain fields like these:

Selected DKIM fields
d=example.org — signing domains=selector1 — selector used to find the public keyh=from:to:subject:date — header fields covered by the signaturebh=... — body hash used in validation

If validation succeeds, that is useful evidence that the signing domain's system signed the message and that the covered material has not changed in a way that breaks the signature.

Read the trusted result, not a line the sender inserted

Authentication results are most useful when recorded by the recipient's trusted mail system or another system inside the relevant trust boundary.

A sender can place text that looks like an authentication result into a message header before delivery.

That is why the question is not simply “does the message contain the word PASS?” but which trusted system performed the check and recorded the result?

A valid signature can still sit behind many different senders

A legitimate provider, CRM, ticketing system or mailing platform may sign mail for many users.

A compromised genuine mailbox may also produce a message with valid DKIM.

So may a connected application acting with authority to send.

Message submittedSending system receives mailUser, application or automated process causes the message to be sent.
DKIM signatureDomain signing system signs itThe signature covers selected headers and the body.
Recipient validationTrusted receiving system checks itA valid result supports the signing-domain relationship.
AttributionWho caused the send?Account, session, application and person evidence are still separate questions.

What does DMARC alignment add?

DMARC can test whether the authenticated domain aligns with the domain presented in the visible From address.

That can strengthen the relationship between the message and that domain.

It still does not identify the individual who composed or approved the email.

Does the From address identify the sender? covers that next attribution layer.

Valid DKIM may support

The signing domain, the fact that the message passed a cryptographic validation check, and integrity of the material covered by the signature.

It does not establish

Which user, delegate, application or person caused the message to be sent, or whether the message is truthful or benign.

The practical point is: use DKIM to understand the authenticated sending route. Then follow the account and session evidence if the investigative question is who actually caused the email to be sent.

Sources

Reference: EML-007Email Evidence