An email authentication scheme in which the sending system signs selected headers and the body with a private key, and receivers verify the signature against a public key published in DNS under a selector. A valid signature proves the message was authorised by the signing domain and was not altered in transit. Unlike SPF, DKIM usually survives forwarding, making it the more robust input to DMARC.
DKIM
DomainKeys Identified Mail