CertaDNS

DKIM Practitioner

Operating DKIM: what a signature covers, why it breaks in transit, key records and their tags, selector and rotation strategy, vendor signing, and reading a verification failure down to its cause.

lessons
23
total
4 h
level
Intermediate

Assumes SPF Practitioner.

You will be able to

  • Read a DKIM-Signature header tag by tag and say what it commits to
  • Predict whether a signature survives a given intermediary
  • Read any key record, including its size, flags and revocation state
  • Design a selector scheme and a rotation with a safe overlap window
  • Name the cause of a verification failure from the result alone
  • Judge a vendor’s signing arrangement, shared keys included
  • Respond to an exposed private key without breaking live mail

Syllabus

  1. 1. What a Signature Covers

    The two hashes, every tag in the header, and choosing which headers to sign.

    1. The two hashes10 min
    2. DKIM-Signature, tag by tag13 min
    3. Choosing what to sign11 min
  2. 2. Canonicalisation and Fragility

    The four combinations, what each tolerates, and why a signature breaks in transit.

    1. Relaxed and simple11 min
    2. What breaks a signature in transit12 min
  3. 3. The Key Record

    Every tag, reading key size off the record, and what an empty p= means.

    1. Anatomy of a key record12 min
    2. Key size and algorithm11 min
    3. Revocation, and the empty p=10 min
  4. 4. Selectors

    Why keys are not enumerable, one selector per sender, and delegating by CNAME.

    1. Selectors are not enumerable9 min
    2. One selector per sender10 min
    3. CNAME delegation, and who holds the key12 min
  5. 5. Key Rotation

    What rotation buys, the overlap window in TTL terms, and the rotations that lose mail.

    1. What rotation is actually for9 min
    2. The overlap window12 min
    3. Rotations that lose mail11 min
  6. 6. Reading a Verification Result

    Each dkim= value, the body-hash failure, and a signature with no key behind it.

    1. Every dkim= value11 min
    2. body hash did not verify11 min
    3. No key for signature11 min
  7. 7. Vendors Signing As You

    Shared against dedicated keys, getting d= aligned, and signature replay.

    1. Shared keys11 min
    2. Getting d= aligned11 min
    3. Signature replay11 min
  8. 8. Operating DKIM

    What decays, what to monitor, and what to do the day a private key is exposed.

    1. What decays11 min
    2. What to monitor10 min
    3. The day a private key is exposed12 min
  9. 9. Final assessment

    15 scenario questions · 80% to pass · unlimited retakes

    What the assessment covers

DKIM Practitioner

  • Complete every lesson in DKIM Practitioner
  • Pass the DKIM Practitioner assessment with at least 80%
About the certificates

CertaDNS Engineering · last reviewed