{"id":11532,"date":"2025-12-11T11:53:29","date_gmt":"2025-12-11T10:53:29","guid":{"rendered":"https:\/\/www.retarus.com\/blog\/en\/wenn-eine-scheinbar-harmlose-dkim-option-zum-sicherheitsrisiko-wird\/"},"modified":"2026-01-14T17:01:33","modified_gmt":"2026-01-14T16:01:33","slug":"seemingly-harmless-dkim-option-emerges-as-security-risk","status":"publish","type":"post","link":"https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/","title":{"rendered":"Seemingly harmless DKIM option emerges as security risk"},"content":{"rendered":"\n

In discussions with the security teams of many of our enterprise customers, Retarus\u2019 experts often encounter a commonly overlooked risk. The issue is that some email security solutions activate the DKIM \u201cl=\u201d tag (length tag) by default. While this option indeed made sense in the past, it now poses significant security risks.<\/p>\n\n\n\n

What is the DKIM \u201cl=\u201d tag? And what was it originally conceived to do?<\/h2>\n\n\n\n

DKIM (DomainKeys Identified Mail) is a proven method for ensuring that emails are not surreptitiously tampered with while in transit. The recipient uses a public key to verify that the content and certain headers have not been altered.<\/p>\n\n\n\n

The \u201cl=\u201d tag specifies up to which byte of the message text the signature extends. The rest of the email is left unsecured. Originally, this option was useful for scenarios involving mailing lists or forwarding, in which the message body is altered (e.g., by attaching footers), as it enables the core email text \u00a0to still be recognized as valid.<\/p>\n\n\n\n

Why does the \u201cl=\u201d tag pose a security risk?<\/h2>\n\n\n\n

At the same time, this mechanism exposes a substantial attack surface, for instance through phishing links or unwanted content, without the DKIM check being triggered. Since the signature remains formally valid, DMARC checks also become less effective. What\u2019s more, it opens up the opportunity for attacks to be carried out by means of forwarding, which has led some large email providers to respond with warnings or rejections.<\/p>\n\n\n\n

What makes this particularly dangerous is that some security solutions activate the \u201cl=\u201d tag by default without users even being aware of it. All the while, our customers had assumed that their emails were fully signed and secure. This is not just a theoretical problem. Audits conducted by our experts show that DKIM signatures using the \u201cl=\u201d tag are still in use in some organizations, potentially exposing their emails to manipulation without any impact on DKIM verification.<\/p>\n\n\n\n

Recommendations for inbound emails<\/h2>\n\n\n\n

Recipients are well advised to carefully examine emails with \u201cl=\u201d tags. One option would be for companies to initially quarantine these messages by default using their own email security solutions, or alternatively they could ignore the DKIM signature so that the email remains subject to other security mechanisms such as SPF or DMARC.<\/p>\n\n\n\n

Recommendations for outbound emails<\/h2>\n\n\n\n

Senders should avoid using the \u201cl=\u201d tag and instead digitally sign the entire message content. Security can additionally be bolstered through periodically rotating DKIM keys, using distinct selectors for different mail streams and, where applicable, setting expiration dates for signatures.<\/p>\n","protected":false},"excerpt":{"rendered":"

In discussions with the security teams of many of our enterprise customers, Retarus\u2019 experts often encounter a commonly overlooked risk. The issue is that some email security solutions activate the DKIM “l=” tag (length tag) by default. While this option indeed made sense in the past, it now poses significant security risks.<\/p>\n","protected":false},"author":12,"featured_media":11533,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","_s2mail":"yes","footnotes":""},"categories":[8],"tags":[102],"class_list":["post-11532","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-email-security"],"acf":[],"yoast_head":"\nSeemingly harmless DKIM option emerges as security risk - Retarus Corporate Blog - EN<\/title>\n<meta name=\"description\" content=\"In discussions with the security teams of many of our enterprise customers, Retarus\u2019 experts often encounter a commonly overlooked risk. The issue is that some email security solutions activate the DKIM "l=" tag (length tag) by default. While this option indeed made sense in the past, it now poses significant security risks.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Seemingly harmless DKIM option emerges as security risk\" \/>\n<meta property=\"og:description\" content=\"In discussions with the security teams of many of our enterprise customers, Retarus\u2019 experts often encounter a commonly overlooked risk. The issue is that some email security solutions activate the DKIM "l=" tag (length tag) by default. While this option indeed made sense in the past, it now poses significant security risks.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/\" \/>\n<meta property=\"og:site_name\" content=\"Retarus Corporate Blog - EN\" \/>\n<meta property=\"article:published_time\" content=\"2025-12-11T10:53:29+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-01-14T16:01:33+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.retarus.com\/blog\/en\/wp-content\/uploads\/sites\/22\/2025\/12\/AdobeStock_614986248.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"1080\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"S\u00f6ren Schulte\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"S\u00f6ren Schulte\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/\"},\"author\":{\"name\":\"S\u00f6ren Schulte\",\"@id\":\"https:\/\/www.retarus.com\/blog\/en\/#\/schema\/person\/da5eb37e5936738ea4e12be8b429433d\"},\"headline\":\"Seemingly harmless DKIM option emerges as security risk\",\"datePublished\":\"2025-12-11T10:53:29+00:00\",\"dateModified\":\"2026-01-14T16:01:33+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/\"},\"wordCount\":427,\"commentCount\":0,\"image\":{\"@id\":\"https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.retarus.com\/blog\/en\/wp-content\/uploads\/sites\/22\/2025\/12\/AdobeStock_614986248.jpg\",\"keywords\":[\"Email Security\"],\"articleSection\":[\"News\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/\",\"url\":\"https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/\",\"name\":\"Seemingly harmless DKIM option emerges as security risk - Retarus Corporate Blog - EN\",\"isPartOf\":{\"@id\":\"https:\/\/www.retarus.com\/blog\/en\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.retarus.com\/blog\/en\/wp-content\/uploads\/sites\/22\/2025\/12\/AdobeStock_614986248.jpg\",\"datePublished\":\"2025-12-11T10:53:29+00:00\",\"dateModified\":\"2026-01-14T16:01:33+00:00\",\"author\":{\"@id\":\"https:\/\/www.retarus.com\/blog\/en\/#\/schema\/person\/da5eb37e5936738ea4e12be8b429433d\"},\"description\":\"In discussions with the security teams of many of our enterprise customers, Retarus\u2019 experts often encounter a commonly overlooked risk. The issue is that some email security solutions activate the DKIM \\\"l=\\\" tag (length tag) by default. While this option indeed made sense in the past, it now poses significant security risks.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/#primaryimage\",\"url\":\"https:\/\/www.retarus.com\/blog\/en\/wp-content\/uploads\/sites\/22\/2025\/12\/AdobeStock_614986248.jpg\",\"contentUrl\":\"https:\/\/www.retarus.com\/blog\/en\/wp-content\/uploads\/sites\/22\/2025\/12\/AdobeStock_614986248.jpg\",\"width\":1920,\"height\":1080},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.retarus.com\/blog\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Seemingly harmless DKIM option emerges as security risk\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.retarus.com\/blog\/en\/#website\",\"url\":\"https:\/\/www.retarus.com\/blog\/en\/\",\"name\":\"Retarus Corporate Blog - EN\",\"description\":\"Always up to date\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.retarus.com\/blog\/en\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.retarus.com\/blog\/en\/#\/schema\/person\/da5eb37e5936738ea4e12be8b429433d\",\"name\":\"S\u00f6ren Schulte\",\"url\":\"https:\/\/www.retarus.com\/blog\/en\/author\/sschulte\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Seemingly harmless DKIM option emerges as security risk - Retarus Corporate Blog - EN","description":"In discussions with the security teams of many of our enterprise customers, Retarus\u2019 experts often encounter a commonly overlooked risk. The issue is that some email security solutions activate the DKIM \"l=\" tag (length tag) by default. While this option indeed made sense in the past, it now poses significant security risks.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/","og_locale":"en_US","og_type":"article","og_title":"Seemingly harmless DKIM option emerges as security risk","og_description":"In discussions with the security teams of many of our enterprise customers, Retarus\u2019 experts often encounter a commonly overlooked risk. The issue is that some email security solutions activate the DKIM \"l=\" tag (length tag) by default. While this option indeed made sense in the past, it now poses significant security risks.","og_url":"https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/","og_site_name":"Retarus Corporate Blog - EN","article_published_time":"2025-12-11T10:53:29+00:00","article_modified_time":"2026-01-14T16:01:33+00:00","og_image":[{"width":1920,"height":1080,"url":"https:\/\/www.retarus.com\/blog\/en\/wp-content\/uploads\/sites\/22\/2025\/12\/AdobeStock_614986248.jpg","type":"image\/jpeg"}],"author":"S\u00f6ren Schulte","twitter_card":"summary_large_image","twitter_misc":{"Written by":"S\u00f6ren Schulte","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/#article","isPartOf":{"@id":"https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/"},"author":{"name":"S\u00f6ren Schulte","@id":"https:\/\/www.retarus.com\/blog\/en\/#\/schema\/person\/da5eb37e5936738ea4e12be8b429433d"},"headline":"Seemingly harmless DKIM option emerges as security risk","datePublished":"2025-12-11T10:53:29+00:00","dateModified":"2026-01-14T16:01:33+00:00","mainEntityOfPage":{"@id":"https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/"},"wordCount":427,"commentCount":0,"image":{"@id":"https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/#primaryimage"},"thumbnailUrl":"https:\/\/www.retarus.com\/blog\/en\/wp-content\/uploads\/sites\/22\/2025\/12\/AdobeStock_614986248.jpg","keywords":["Email Security"],"articleSection":["News"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/","url":"https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/","name":"Seemingly harmless DKIM option emerges as security risk - Retarus Corporate Blog - EN","isPartOf":{"@id":"https:\/\/www.retarus.com\/blog\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/#primaryimage"},"image":{"@id":"https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/#primaryimage"},"thumbnailUrl":"https:\/\/www.retarus.com\/blog\/en\/wp-content\/uploads\/sites\/22\/2025\/12\/AdobeStock_614986248.jpg","datePublished":"2025-12-11T10:53:29+00:00","dateModified":"2026-01-14T16:01:33+00:00","author":{"@id":"https:\/\/www.retarus.com\/blog\/en\/#\/schema\/person\/da5eb37e5936738ea4e12be8b429433d"},"description":"In discussions with the security teams of many of our enterprise customers, Retarus\u2019 experts often encounter a commonly overlooked risk. The issue is that some email security solutions activate the DKIM \"l=\" tag (length tag) by default. While this option indeed made sense in the past, it now poses significant security risks.","breadcrumb":{"@id":"https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/#primaryimage","url":"https:\/\/www.retarus.com\/blog\/en\/wp-content\/uploads\/sites\/22\/2025\/12\/AdobeStock_614986248.jpg","contentUrl":"https:\/\/www.retarus.com\/blog\/en\/wp-content\/uploads\/sites\/22\/2025\/12\/AdobeStock_614986248.jpg","width":1920,"height":1080},{"@type":"BreadcrumbList","@id":"https:\/\/www.retarus.com\/blog\/en\/seemingly-harmless-dkim-option-emerges-as-security-risk\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.retarus.com\/blog\/en\/"},{"@type":"ListItem","position":2,"name":"Seemingly harmless DKIM option emerges as security risk"}]},{"@type":"WebSite","@id":"https:\/\/www.retarus.com\/blog\/en\/#website","url":"https:\/\/www.retarus.com\/blog\/en\/","name":"Retarus Corporate Blog - EN","description":"Always up to date","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.retarus.com\/blog\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.retarus.com\/blog\/en\/#\/schema\/person\/da5eb37e5936738ea4e12be8b429433d","name":"S\u00f6ren Schulte","url":"https:\/\/www.retarus.com\/blog\/en\/author\/sschulte\/"}]}},"_links":{"self":[{"href":"https:\/\/www.retarus.com\/blog\/en\/wp-json\/wp\/v2\/posts\/11532","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.retarus.com\/blog\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.retarus.com\/blog\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.retarus.com\/blog\/en\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/www.retarus.com\/blog\/en\/wp-json\/wp\/v2\/comments?post=11532"}],"version-history":[{"count":3,"href":"https:\/\/www.retarus.com\/blog\/en\/wp-json\/wp\/v2\/posts\/11532\/revisions"}],"predecessor-version":[{"id":11537,"href":"https:\/\/www.retarus.com\/blog\/en\/wp-json\/wp\/v2\/posts\/11532\/revisions\/11537"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.retarus.com\/blog\/en\/wp-json\/wp\/v2\/media\/11533"}],"wp:attachment":[{"href":"https:\/\/www.retarus.com\/blog\/en\/wp-json\/wp\/v2\/media?parent=11532"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.retarus.com\/blog\/en\/wp-json\/wp\/v2\/categories?post=11532"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.retarus.com\/blog\/en\/wp-json\/wp\/v2\/tags?post=11532"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}