What is a technical summary of the way DKIM works?
DKIM defines an authentication mechanism for email, using: • A domain name identifier • Public-key cryptography • A DNS-based public key publishing service. An agent in the message transit path can sign the message content and selected header fields. The signature information is placed into a field of the RFC2822 message header. Validation of the signature, by a later agent in the path, demonstrates that the signing identity took responsibility for the message. There also are mechanisms for listing formal assertions about the signature or the message. This publicly registers the signing organization’s message signing practices.