How does DKIM signing work, and what is DKIM alignment with the From domain?
Suggested answer
DKIM (DomainKeys Identified Mail) adds a cryptographic digital signature to the email header. The sending server signs outgoing mail with a private key; the public key is published as a DNS TXT record at selector._domainkey.domain.com. Receiving servers retrieve the public key and verify the signature — confirming the email has not been tampered with in transit and originated from an authorised sender.
Alignment: DMARC requires DKIM alignment — the d= domain in the DKIM signature must match (or be a subdomain of) the RFC5322 From header domain. When Marketing Cloud sends with its own DKIM key (@exacttarget.com), DKIM alignment with your From domain fails. The Sender Authentication Package (SAP) provides your own private domain and DKIM keys, enabling proper alignment.
Relaxed vs strict alignment: Relaxed allows subdomain matching; strict requires exact domain match.
Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.
Community comments (0)
No comments yet.
Sign in or create a free account to add a comment. Comments are moderated before they appear.