Email Deliverability

DKIM Body Hash Mismatch

A DKIM body hash mismatch occurs when the hash of the email body (bh= tag in the DKIM-Signature header) doesn't match the actual body content at the time of verification. This means the email body was modified after the DKIM signature was applied, causing DKIM validation to fail even if the DKIM key is correct.

Symptoms

  • DKIM verification fails with "body hash did not verify" error
  • Email headers showing dkim=fail (body hash did not verify)
  • DKIM passes for some recipients but fails for others
  • Emails from mailing lists consistently failing DKIM

Common Causes

  • Mailing list software appending footer text to the body
  • Email gateway or antivirus modifying message content
  • Content-Transfer-Encoding changes during transit
  • Email forwarding services altering the body
  • Character encoding conversion changing body bytes

Step-by-Step Troubleshooting

  1. 1

    Validate DKIM configuration

    Verify the DKIM public key and signature configuration.

    Use DKIM Validator β†’
  2. 2

    Analyze email headers

    Inspect the full email headers to see DKIM verification results and trace modifications.

    Use Email Headers β†’
  3. 3

    Check TXT records

    Verify the DKIM DNS record is correct.

    Use TXT Record Lookup β†’
  4. 4

    Identify modification point

    Determine which hop in the delivery chain is modifying the body content.

  5. 5

    Configure body length limit

    Consider using the l= tag in DKIM signatures to sign only a portion of the body, allowing appended content.

Recommended Diagnostic Tools

Monitor DKIM Integrity

Track DKIM validation results and detect body hash failures.

Frequently Asked Questions