DKIM Failure
DKIM failure means the signature could not be validated—missing key, wrong key, modified content, or unsupported algorithms.
Frequent causes
Selector TXT not published, CNAME to ESP broken, body modified in transit (bh= mismatch), or dual-signing confusion during migrations.
Message vs DNS checks
Compare s= and d= from the signature to live DNS. Then validate whether intermediaries altered the signed headers/body.
How QuickDMARC helps
Correlate DKIM fails in aggregate reports with specific sources and selectors.
Frequently asked questions
Does DKIM fail break DMARC always?
DMARC can still pass via aligned SPF.
ARC and DKIM?
Authenticated Received Chain can help some forwarded scenarios; still aim for robust origin signatures.
First tool?
DKIM checker + header analyzer.