Solo ads sellers / Blog / DKIM overview

Solo ads blog

A DKIM signature is not permission to send

Answer A DKIM signature lets a receiver check that a domain takes responsibility for a message and that the signed parts were not altered. RFC 5585 is the service overview. The signature is not permission from the reader, and a pass does not place the solo ad in the inbox. Compare the domain that signed with the domain you think you bought.

Cream stationery and a teal accent on a dark navy desk
Write the domain on the line before the price.

The note that started this: RFC 5585, DKIM Service Overview, RFC 5585.

By the middle of July the word authenticated has been used for too many different locks. This one is the domain's signature on the message. It is the check a receiver can do without trusting the path that carried the mail. Best solo ad vendors can tell you which domain will sign. The others tell you the mail is authenticated and hope you do not ask which name.

The overview document is from 2009. It is still the right altitude for this question, because it explains the service instead of the byte format. A signer attaches a signature. A verifier checks it against a key the domain publishes. If the check works, the domain named in the signature is willing to be associated with that message, and the signed header fields and body have not been changed since the signature was applied. That is a strong, narrow fact. It says nothing about whether the person at the other end opted in.

What is a DKIM signature for?

RFC 5585 describes DKIM as a way for a domain to take responsibility for a message and for a receiver to check that the signed parts were not changed. It is an identifier, not a permission slip.

Responsibility is the word to keep. The domain is saying this message belongs to our name. It is not saying this recipient is glad. A criminal can sign with a domain they control. A sloppy seller can sign with a domain they control and still mail a tired list. The signature makes the responsibility stick. Sticking is useful because complaints and reputation then have a name to stick to. It is not absolution.

Alteration matters on a solo ad because forwarding and link-rewriting can break a signature if they touch a signed part. A pass means the version you are looking at matches what was signed. A fail means it does not, or the key does not, or the signature is missing. Do not let a seller explain a fail as the filters being moody until they show you the domain and the result side by side.

Does a DKIM pass mean the solo ad will be inbox placed?

No. A pass means the signature checked out. Placement still depends on the list, the complaints, and the receiver's own judgment.

Receivers asked for signatures so they could tell domains apart. They did not agree to deliver every signed message. A new domain with a perfect signature and no history is a stranger with neat handwriting. A known domain with a perfect signature and a spike of complaints is a neighbor who started shouting. The handwriting is fine in both cases. The relationship is not.

Buyers hear pass and feel the order is safe. Safe meant the bytes match. Your refund line should still talk about the drop, the date, and the page the click lands on. None of those are inside the signature. The signature will happily validate a message that points at the wrong URL, if that URL was in the message when it was signed.

What should a buyer compare against the signature?

Compare the domain in the signature with the domain in the quote. If they differ, ask why before you pay. A pass on an unexpected domain is a pass for someone else.

The usual surprise is a platform domain. The quote says the mail is from the seller's brand. The signature is from the platform's shared name. Receivers may show the platform. Alignment with the brand's DMARC record may fail. You have seen this pattern before if you have read a platform's own help pages. The fix is a signature on the domain you think you are hiring, or an honest quote that names the platform domain as the identity.

Ask for one live test to yourself and read the signing domain in the result. RFC 5585 tells you what that result means. It means a domain took responsibility. Make sure it is the domain on the invoice.