DKIM Practitioner
Operating DKIM: what a signature covers, why it breaks in transit, key records and their tags, selector and rotation strategy, vendor signing, and reading a verification failure down to its cause.
- lessons
- 23
- total
- 4 h
- level
- Intermediate
Assumes SPF Practitioner.
You will be able to
- Read a DKIM-Signature header tag by tag and say what it commits to
- Predict whether a signature survives a given intermediary
- Read any key record, including its size, flags and revocation state
- Design a selector scheme and a rotation with a safe overlap window
- Name the cause of a verification failure from the result alone
- Judge a vendor’s signing arrangement, shared keys included
- Respond to an exposed private key without breaking live mail
Syllabus
1. What a Signature Covers
The two hashes, every tag in the header, and choosing which headers to sign.
2. Canonicalisation and Fragility
The four combinations, what each tolerates, and why a signature breaks in transit.
3. The Key Record
Every tag, reading key size off the record, and what an empty p= means.
4. Selectors
Why keys are not enumerable, one selector per sender, and delegating by CNAME.
5. Key Rotation
What rotation buys, the overlap window in TTL terms, and the rotations that lose mail.
6. Reading a Verification Result
Each dkim= value, the body-hash failure, and a signature with no key behind it.
7. Vendors Signing As You
Shared against dedicated keys, getting d= aligned, and signature replay.
8. Operating DKIM
What decays, what to monitor, and what to do the day a private key is exposed.
9. Final assessment
15 scenario questions · 80% to pass · unlimited retakes
What the assessment covers
DKIM Practitioner
- Complete every lesson in DKIM Practitioner
- Pass the DKIM Practitioner assessment with at least 80%
CertaDNS Engineering · last reviewed