A valid signature can still be unwanted mail
Answer A valid DKIM signature can sit on mail nobody wanted. RFC 4686 is the threat analysis that motivated DKIM. It does not say a signature makes mail welcome. A real domain can sign unwanted mail. A signed message can also be replayed if nothing else notices. Permission is still a question you ask the list, not the signature.
The note that started this: RFC 4686, Analysis of Threats Motivating DKIM, RFC 4686.
The middle of the month has been full of locks. Logins, TLS, selectors, reports. A buyer can leave that sequence believing a pass is a moral certificate. It is an identifier. Identifiers are how you know who to blame. Blame is not the same as an invitation. Solo ads for affiliate marketing still have to be mail the list has a reason to receive.
The threat document is from 2006, which is a useful embarrassment. The problems it names are old because unwanted mail is old. Bad actors use domains they control and sign honestly with those domains. Replay takes a signed message and sends it again. Modification is what the signature actually detects, when the modified part was covered. A seller who tells you DKIM solved spam is telling you a story from a brochure. The threat writeup is more adult than the brochure.
Does DKIM stop unwanted mail from a real domain?
No. RFC 4686 describes threats DKIM was meant to address. A domain can still sign mail the recipient does not want. The signature identifies the domain. It does not grant permission.
Permission is the list. People joined for a topic, from a page, on a date you can ask about. A signature does not contain that page. A spammer with a freshly registered domain can publish a key and sign every message. Receivers will verify the signature and still be free to throw the mail away. Verification succeeded. Welcome did not.
On a solo, the same split saves you from a common pitch. The seller shows a pass and calls the list clean. Clean, in that sentence, means the bytes match a key. Ask the other question. Where did these people join, and when did they last hear from you? A pass plus a shrug is a signed shrug. Do not pay extra for it.
- A DKIM pass is recorded as a pass, not as opt-in.
- The join path for the list is a separate answer.
- A new domain with a valid key is still a new domain.
- Complaints still count against the domain that signed.
Does a valid signature stop replay by itself?
No. A captured message can be sent again with the signature still valid if the signed content has not changed. DKIM alone is not a replay defense. Ask what else the sender does.
Replay matters if your creative is valuable or if a leaked copy keeps circulating with your links. The signature will keep checking out. The clicks may be real and still be from a send you did not schedule. This is not a reason to abandon signatures. It is a reason to notice unique links, short schedules, and a seller who can see when a creative is used twice. Ask who else has the HTML. Ask what they do if the same signature shows up on a day you did not buy.
You will not get a perfect replay shield from a solo vendor, and this note will not invent one. You can get an honest limit. The signature says the content was not edited. It does not say the content was sent only once, to only the list in the quote, on only the date you paid for. Those are contract terms. Put them in the contract.
What should a solo ad buyer require besides a DKIM pass?
Require a list people joined, a domain that matches the quote, and a refund if the drop is not the drop you approved. The pass is one line. It is not the order.
Three requirements, all older than the signature and all still due. The list is the relationship. The domain is the identity, which the signature can confirm and cannot replace. The refund is what makes the identity and the list worth writing down. A seller who leads with the pass and will not write the other three has handed you the least interesting line of the audit.
RFC 4686 is worth reading because it refuses the halo. Use the signature so you know which domain took responsibility. Then decide whether that domain's mail was wanted. Both questions. In that order. A valid signature on unwanted mail is still unwanted mail.