DKIM monitoring

How SealedMail confirms your email is being signed and verified, so legitimate mail is not treated as forged.

DKIM is the cryptographic seal that proves your email genuinely came from you. Here is what SealedMail checks, and where it tends to fail.

Watch: DKIM in plain English

What DKIM is

DKIM (DomainKeys Identified Mail) adds a cryptographic signature to your outgoing email: tamper-proof evidence that the message genuinely came from your domain and was not altered in transit. For the full detail, see our guide: What is DKIM?

Why it matters to your business

SPF checks where email came from; DKIM proves it was not forged or modified. Together they are the foundation DMARC builds on, and major receivers increasingly expect both.

How SealedMail monitors it

Health checks confirm your DKIM records where they are discoverable, and your weekly DMARC data shows whether your mail is actually being signed and verified by receivers.

What commonly goes wrong

Keys that were never set up for a particular sending service, or keys rotated by a provider without the DNS record being updated. The result is legitimate email that looks unsigned, and increasingly, undelivered.

Want the full technical detail? Read our plain-English guide: What is DKIM?

Scope: reporting only

SealedMail monitors, interprets and reports. It does not change your DNS, configure your systems, or remediate problems. Your reports tell you clearly what is wrong and what kind of fix is needed, and the changes remain in your hands (or your IT provider’s). That boundary keeps the service simple, affordable and honest.