Kavach

Check · Domain & email identity · default severity medium

Email signing (DKIM)

What Kavach checks

DKIM cryptographically signs outgoing mail so receivers can verify it really came from your systems.

Why it matters

Without DKIM, DMARC alignment rests on SPF alone, forwarding breaks authentication, and spoofed mail is harder to reject.

How an attacker uses it

  1. Attacker forges a mail that passes nothing but looks right.
  2. With no signature to check, receivers rely on weaker signals.

How to fix it

Enable DKIM at your mail provider and publish the selector record it gives you (e.g. google._domainkey / selector1._domainkey).

Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare

Limitations

This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.

Scan your site free → Monitor it continuously