Skip to content
arrow_back
search
ISM-1027 policy ASD Information Security Manual (ISM)

Configure Email Distribution Lists to Preserve DKIM Signatures

Ensure email lists don't invalidate DKIM signatures from external senders.

record_voice_over

Plain language

This control ensures that when you send emails through a group email list, the original email's authenticity isn't messed up. Why does this matter? If the DKIM signature isn't preserved, important emails might end up in spam folders or could be tampered with, which could damage trust and communication with your clients.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Email distribution list applications used by external senders is configured such that it does not break the validity of the sender's DKIM signature.
policy ASD Information Security Manual (ISM) ISM-1027
priority_high

Why it matters

Compromised DKIM signatures can result in legitimate emails being marked as spam or malicious, damaging client trust and disrupting communication channels.

settings

Operational notes

Regularly test distribution list behaviour to ensure forwarded mail preserves DKIM validity and avoids header/body rewrites that invalidate signatures.

Mapping detail

Mapping

Direction

Controls