DKIM Practitioner — assessment
- questions
- 15
- to pass
- 80%
- retakes
- Unlimited
- time limit
- None
Covers
- What a Signature Covers
- Canonicalisation and Fragility
- The Key Record
- Selectors
- Key Rotation
- Reading a Verification Result
- Vendors Signing As You
- Operating DKIM
Sample question
A message fails DKIM. The verifier reports that the body hash matched but the signature did not verify. What has been ruled out?
- Any modification to the body — the content is byte-identical to what was signed, so the change is in a header named in h=.The body hash matching is a positive result, not a neutral one: it proves the content survived intact. A subject tagger adding [EXTERNAL] is the usual cause of the remaining failure.
- Any problem with the key — a matching body hash means the key was correct.The body hash is computed from the message alone and never involves the key. It says nothing about whether the right key was retrieved.
- Nothing useful — a failed signature means the message could have been altered anywhere.The two-stage check exists precisely so it can be narrowed. Having the body hash reported separately halves the search.
- Modification by an intermediary, since only the sender can change signed headers.Intermediaries routinely alter headers — subject tagging is the clearest case — and a header in h= that changes in transit breaks the signature.
Every option carries an explanation, including the wrong ones.
The assessment needs an account.
Passing issues DKIM Practitioner. A CertaDNS Academy certificate records that you completed a course and passed its assessment on a given date. It is not a professional certification, it is not accredited, and it does not expire.