Detecting Phishing Behind a Valid DKIM Signature

A phishing email can pass DKIM and still be dangerous. This is especially true when an attacker controls a forwarding address, mailbox rule, or compromised account that relays a message to a new recipient. The cryptographic signature may remain valid while the delivery path and business context have changed.

DKIM confirms that a signed message was associated with a particular domain and that selected content was not altered after signing. It does not confirm that the sender intended the message, that the account was secure, or that the recipient was meant to receive it.

This matters in Australia, where scammers frequently imitate Australia Post, myGov, Medicare, banks, and major retailers. A message arriving in a busy Melbourne office or a home inbox in Brisbane can look familiar enough to bypass a quick visual check, particularly when it comes from a trusted contact.

The right approach is to examine authentication, routing, message context, links, and account behaviour together. A valid DKIM result is useful evidence, but it is only one part of an email trust assessment.

How A Forwarding Address Changes The Risk

A forwarding address may be a legitimate shared mailbox, an employee account, or an external address added to an account without permission. If an attacker gains access, they can create an automatic rule that forwards invoices, password resets, or internal correspondence to a controlled mailbox.

Forwarding often leaves the original DKIM signature intact because the message body and signed headers have not changed. The receiving mail service therefore sees a valid signature from the original domain, even though an unauthorised person may have selected the recipient or triggered the forwarding event.

Look for unusual recipient details, unexpected “to” or “delivered-to” values, unfamiliar forwarding domains, and message timestamps that do not fit the claimed conversation. A message that appears to come from a supplier but arrives through an unrelated consumer mailbox deserves additional scrutiny.

What DKIM And DMARC Actually Prove

DKIM uses a digital signature to verify that a sending system controlled a private key for the signing domain. It can detect certain alterations in transit, but it does not establish that the sender’s mailbox was uncompromised or that the content is safe.

DMARC adds domain alignment rules. A message may pass DMARC when the visible From domain aligns with the domain authenticated by DKIM or SPF. This still does not detect a legitimate account being used to send a fraudulent request, nor does it identify every malicious forwarding configuration.

DMARC reports can reveal recurring sources, unexpected mail platforms, and policy failures. Understanding negative DMARC feedback can help distinguish a routine forwarding problem from evidence that an unauthorised service is handling mail.

Inspect Headers Beyond The Green Tick

Open the full headers rather than relying on the mail client’s “signed” or “authenticated” indicator. Review Authentication-Results, Return-Path, Received lines, DKIM d= and s= values, SPF results, DMARC alignment, and any ARC-Seal or ARC-Authentication-Results fields.

The earliest trusted Received line can help identify where the message entered the delivery chain. Compare the sending infrastructure with the organisation’s normal providers. A genuine Australian bank will rarely ask customers to move funds through an unrelated overseas mailbox, while a compromised supplier account may use familiar infrastructure and still issue a dangerous request.

Treat Reply-To as a separate identity. Attackers often preserve a valid From address while directing replies to a different domain. Also check whether the display name, signature, writing style, attachment type, and urgency match previous correspondence.

Validate Links, Attachments, And Requests

Hover over links without opening them and compare the destination with the organisation’s known domain. Be cautious with lookalike domains using additional words, hyphens, unusual subdomains, URL shorteners, or punycode characters. A signed email can still contain a credential-harvesting page.

Attachments deserve the same suspicion. HTML files, macro-enabled documents, password-protected archives, and unexpected invoices can hide malware or redirect users to a fake login page. Do not use contact details supplied in the message to validate a payment or account change.

For Australian recipients, independently open the official app or type the known website address into the browser. Report suspected scams to Scamwatch, and follow the organisation’s incident process if a work account, payment, or customer record may be involved.

Correlate Email With Account Activity

Security teams should compare the message with identity-provider logs, mailbox audit events, forwarding-rule changes, sign-in locations, and OAuth consent records. A recent login from an unfamiliar country followed by a new forwarding rule is stronger evidence of compromise than a DKIM result alone.

Domain owners can use reputation checks to identify suspicious sender infrastructure and authentication gaps. For larger environments, API threat enrichment can add domain trust data to SIEM, threat-intelligence, or mail-triage workflows.

If a mailbox is suspected of compromise, revoke active sessions, remove forwarding rules, reset credentials, review multifactor authentication, and check for malicious inbox rules. Preserve headers and audit logs before deleting messages, since they may support an investigation under the organisation’s incident-response procedure.

Use A Layered Decision Process

A practical assessment separates what the message proves from what it merely suggests. The following distinctions help prevent a valid signature from creating false confidence.

Signal What It Shows What It Does Not Show
DKIM pass The signature matched the signed content and domain key That the account or sender was trustworthy
DMARC pass Authentication aligned with the visible From domain That the request was authorised or safe
SPF pass The sending host was authorised for the envelope domain That the visible sender was genuine
Familiar display name The message resembles a known contact That the mailbox was not compromised
Forwarding evidence The message travelled through an additional route Whether forwarding was legitimate without account logs
Safe-looking link text The visible wording appears credible Where the link actually leads

Teams that need repeatable checks can build a custom trust checker to combine domain reputation, authentication results, and header indicators. The strongest decision comes from several independent signals: verify the request out of band, inspect the routing path, and investigate account activity whenever a forwarding address may be involved.

A DKIM pass should therefore be treated as a technical result, not a safety certificate. When authentication succeeds but the request is urgent, financially sensitive, or inconsistent with normal behaviour, the message should remain untrusted until its origin and intent are independently verified.