In plain English
DKIM works like a wax seal on a letter. When your email server sends a message, it adds a digital signature created with a private key. The recipient's server checks this signature against a public key published in your DNS records. If the signature matches, the email is genuine and unaltered. If it doesn't match, the email may have been forged or tampered with.
