Check · Domain & email identity · default severity medium
Email signing (DKIM)
What Kavach checks
DKIM cryptographically signs outgoing mail so receivers can verify it really came from your systems.
Why it matters
Without DKIM, DMARC alignment rests on SPF alone, forwarding breaks authentication, and spoofed mail is harder to reject.
How an attacker uses it
- Attacker forges a mail that passes nothing but looks right.
- With no signature to check, receivers rely on weaker signals.
How to fix it
Enable DKIM at your mail provider and publish the selector record it gives you (e.g. google._domainkey / selector1._domainkey).
Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare
Limitations
This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.