DKIM
A cryptographic signature on your mail, verified against a public key you publish in DNS
DKIM, DomainKeys Identified Mail, signs each outgoing message with a private key and publishes the matching public key in your DNS. A receiving server fetches the key, checks the signature, and learns two things: that the message really was sent by something holding your key, and that the headers and body it signed were not altered on the way.
Unlike SPF, DKIM survives forwarding. A mailing list that relays your message leaves the signature intact as long as it does not rewrite what was signed, which is why DKIM is the stronger of the two signals and why DMARC can pass on DKIM alone.
What a record looks like
A CNAME or TXT record at a selector-scoped name, for example
abc123._domainkey.yourcompany.com. The selector lets one domain carry several keys at
once, which is what makes rotating a key possible without an outage.
In Sendly
Keys are generated for you when you add a domain, and the records to publish are shown in the dashboard. A verified domain whose DKIM record later disappears stops passing — guided DNS setup watches for exactly that.
One migration gotcha worth knowing: if you are moving from a provider that also managed DKIM for this domain, delete their records rather than leaving them. A stale key is not harmful on its own, but it makes diagnosing the next problem considerably harder.
See Verifying domains.