Glossary

What Is DKIM?

How a signed header lets a receiving server verify who sent a message, and why cold senders need it.

Get your free API key →Free to start. No credit card. 1,000 records to spend whenever you like.

DKIM (DomainKeys Identified Mail) is an email authentication standard that attaches a cryptographic signature to each outgoing message, so the receiving server can confirm the message came from an authorized domain and was not changed in transit.

The standard is defined in RFC 6376 (September 2026). The sender signs chosen headers and the body with a private key. The matching public key sits in the sender's DNS.

Why it matters for outbound

Gmail, Outlook and other receivers check authentication before they decide where a message lands. A cold email with no valid DKIM signature is more likely to land in spam. Google's sender guidelines require SPF or DKIM for all senders, and SPF, DKIM and DMARC above 5,000 messages a day (Google, September 2026).

DKIM also carries your domain's reputation. The signing domain, called the d= tag, is what receivers score over time. Sign with your own sending domain, not with a shared default from your mail provider.

DKIM works alongside SPF and DMARC. DMARC passes only when DKIM or SPF passes and the domain matches the visible From address. That match is called domain alignment.

Example

Your mail server adds a header like this to every message from acme.com. The values are placeholders.

code
DKIM-Signature: v=1; a=rsa-sha256; d=acme.com; s=selector1;
  h=from:to:subject:date; bh=BASE64BODYHASH; b=BASE64SIGNATURE

The s= tag is the selector. The receiver builds a DNS name from it and asks for a TXT record:

code
selector1._domainkey.acme.com  TXT  "v=DKIM1; k=rsa; p=BASE64PUBLICKEY"

The receiver uses the public key to check the signature. If the headers or body changed after signing, the check fails. Each sending tool usually needs its own selector, so a domain can hold several keys at once. Rotate a key by publishing a new selector, switching the signer to it, and removing the old record later.

In LeadOcean data

LeadOcean has no DKIM field, filter or endpoint. DKIM is a property of your own sending domain, not of the people or companies in the dataset, so you set it up in your mail provider and your DNS.

What LeadOcean does cover is the other half of deliverability: the recipient address. Every person record carries email_status, and /v1/people/search accepts an emailStatus filter, so you can mail only addresses that were verified (openapi.json, September 2026). A clean signature does not rescue a list full of bounces.

For the setup steps, see the DKIM setup guide and how to set up DKIM in Gmail. For the three standards together, read DMARC, SPF and DKIM explained. Pricing is on /pricing.

Pair a signed domain with emails that are already verified

Free to start. No credit card. 1,000 records to spend whenever you like.

Get your free API key →