Does successful DKIM prove the named sender wrote it?¶
No. A valid DKIM result can support that a domain's signing system signed the message and that the signed material still validates.
It does not identify the human author shown in the From field.
What is DKIM actually checking?¶
A DKIM signature is added by a sending system. The receiving system uses a public key published for the signing domain to test the signature.
A simplified signature may contain fields like these:
d=example.org — signing domains=selector1 — selector used to find the public keyh=from:to:subject:date — header fields covered by the signaturebh=... — body hash used in validationIf validation succeeds, that is useful evidence that the signing domain's system signed the message and that the covered material has not changed in a way that breaks the signature.
Read the trusted result, not a line the sender inserted¶
Authentication results are most useful when recorded by the recipient's trusted mail system or another system inside the relevant trust boundary.
A sender can place text that looks like an authentication result into a message header before delivery.
That is why the question is not simply “does the message contain the word PASS?” but which trusted system performed the check and recorded the result?
A valid signature can still sit behind many different senders¶
A legitimate provider, CRM, ticketing system or mailing platform may sign mail for many users.
A compromised genuine mailbox may also produce a message with valid DKIM.
So may a connected application acting with authority to send.
What does DMARC alignment add?¶
DMARC can test whether the authenticated domain aligns with the domain presented in the visible From address.
That can strengthen the relationship between the message and that domain.
It still does not identify the individual who composed or approved the email.
Does the From address identify the sender? covers that next attribution layer.
The signing domain, the fact that the message passed a cryptographic validation check, and integrity of the material covered by the signature.
Which user, delegate, application or person caused the message to be sent, or whether the message is truthful or benign.
The practical point is: use DKIM to understand the authenticated sending route. Then follow the account and session evidence if the investigative question is who actually caused the email to be sent.