Skip to content
arrow_back
search
ISM-0861 policy ASD Information Security Manual (ISM)

Enable DKIM Signing for Organisational Emails

Ensure emails from your organisation's domains use DKIM to verify authenticity and prevent forgery.

record_voice_over

Plain language

This control means your organisation needs to use a security method called DKIM to ensure that emails sent from your business are genuine. It's like giving your emails a signature that proves they're really from you and not a scammer pretending to be you. If you don’t do this, someone could fake emails from your domain, which might trick your customers or partners into providing sensitive information or making wrong decisions.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

DKIM signing is enabled on emails originating from an organisation's domains (including subdomains).
policy ASD Information Security Manual (ISM) ISM-0861
priority_high

Why it matters

Without DKIM signing, attackers can spoof your domains, increasing phishing success and causing fraud, data loss, and reputational harm.

settings

Operational notes

Regularly audit DKIM selectors/keys for all domains and rotate keys; monitor DNS and mail gateway changes to detect unauthorised DKIM disablement.

Mapping detail

Mapping

Direction

Controls