Skip to content
arrow_back
search
ISM-1026 policy ASD Information Security Manual (ISM)

Verification of DKIM Signatures on Incoming Emails

Ensure that DKIM signatures on received emails are checked to identify legitimate sources.

record_voice_over

Plain language

This control ensures that emails your organisation receives are verified to confirm they're from legitimate senders. This is important because if you don't check these email signatures, you might fall victim to scams or phishing attacks, thinking fraudulent emails are from trusted sources.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

May 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

DKIM signatures on incoming emails are verified.
policy ASD Information Security Manual (ISM) ISM-1026
priority_high

Why it matters

If DKIM on incoming mail is not verified, spoofed or tampered emails may be accepted, increasing phishing risk, fraud, and potential data compromise.

settings

Operational notes

Enforce DKIM verification on inbound gateways, alert on DKIM failures, and review signature failures by domain/selector to detect spoofing or misconfiguration quickly.

Mapping detail

Mapping

Direction

Controls