Reference · LeakTrace Intelligence Team
DKIM signing absent on the primary mail sender
A domain's outbound mail is not cryptographically signed, so receivers cannot verify integrity or authenticity beyond IP-based SPF.
Pattern summary
- Category
- Email authentication
- Severity
- Medium
- Prevalence framing
- Common in firms that migrated mail providers without re-checking DNS.
- Remediation effort
- Moderate
- Verticals affected
- All
DKIM (DomainKeys Identified Mail) attaches a cryptographic signature to outbound mail that receivers verify against a public key published in DNS. Without DKIM, DMARC alignment can only rely on SPF, which fails on legitimate forwarded mail and gets brittle under any mail-flow change (new marketing platform, new e-sign vendor, forwarded newsletters).
## Why attackers exploit it
Attackers rarely attack DKIM directly — they attack its absence. A domain with SPF-only alignment produces intermittent DMARC failures on legitimate mail, which pressures the domain owner to set `p=none` and keep it there. That permissive posture is what the attacker actually wants.
## Remediation direction
Enable DKIM signing on every legitimate sender (Google Workspace, Microsoft 365, marketing platform, ATS, e-sign vendor) with 2048-bit keys. Publish each selector at `._domainkey.`. Verify with a DMARC aggregate report review after two weeks.
Concerned this pattern touches your exposure surface?
LeakTrace runs continuous intelligence on principals, households, and advisor tenants across every observable public exposure surface. Discovery call under mutual NDA, first-touch reply within one business day from an authenticated LeakTrace address.
See services and pricing