How to Check if DKIM Signature Contains b= Tag During Verification
Verify if your DKIM signature includes the b= tag during email verification. Ensure alignment, prevent deliverability issues, and validate your email.
Why the b= tag in DKIM signatures matters for deliverability
You sent an email that passed SPF and DMARC, but it still landed in the spam folder. Why? Because DKIM — the signature that confirms your message wasn’t tampered with — depends on a single, often overlooked tag: b=.
Imagine your email as a sealed envelope. SPF and DMARC check the sender’s identity. DKIM is the seal. If the b= tag—containing the actual signature—is missing or corrupted, the seal is broken. No matter how legitimate the sender looks, email providers flag it as unreliable.
Understanding how to check if a DKIM signature contains the b= tag during verification isn’t a technical curiosity. It’s a deliverability checkpoint. A single malformed or absent b= tag can sink your entire campaign, even if everything else checks out.
Key takeaways
- The
b=tag in a DKIM signature holds the cryptographic hash of the email’s body, making it essential for content integrity verification. - A missing or malformed
b=tag breaks DKIM validation, which can lead to inbox rejection even if SPF and DMARC pass. - Verifying DKIM signatures during email validation must include checking for the presence and correctness of the
b=tag to ensure end-to-end deliverability.
What does the b= tag in a DKIM signature actually do?
The b= tag contains the actual digital signature of the email’s body and selected headers, computed using a private key and encoded in base64. Receiving servers use the public key from DNS to verify that the signature matches the message, ensuring it wasn’t altered in transit. Without a valid b= tag, DKIM fails—no matter how clean the alignment or key size is.
How the b= tag is generated and validated
When you send an email with DKIM, the signing server takes the selected headers and message body, applies a hashing algorithm (typically SHA-256), and signs the resulting hash with a private key. That signed hash appears in the b= tag. The recipient’s mail server downloads the public key from the sender’s DNS records and uses it to recompute the hash and check the signature. If the hashes don’t match, the email fails DKIM.
Let’s be clear: DKIM isn’t just about key length or header alignment. It’s about proving the content hasn’t changed. Even if the d= (domain) and s= (selector) match, a missing or invalid b= tag still kills the signature. That’s why checking for its presence and correctness is essential during verification.
Why the b= tag matters in inbox placement and deliverability
Email providers like Gmail and Microsoft use DKIM as one of several signals to assess sender trust. A failed or missing b= tag often leads to the email being marked as suspicious or blocked outright. While some systems may accept emails with incomplete DKIM, they are usually filtered into low-priority folders or flagged as spam.
You can validate DKIM signatures—and check for the presence and integrity of the b= tag—using tools like MailTester’s Inbox Placement Test, which simulates real-world delivery conditions and checks for common deliverability issues, including DKIM validation. The test evaluates not just the signature structure but how inbox providers respond in practice.
For detailed technical insight, the original DKIM specification is defined in RFC 6376, which outlines how the b= tag is constructed, signed, and verified using DNS-published keys.
How to check if DKIM signature contains b= tag during verification
You can verify if a DKIM signature contains the b= tag by examining the raw email header. Look for the DKIM-Signature header, ensure it includes a non-empty b= parameter, confirm the value is valid base64, and validate that the body hash matches the signed content. Tools like MailTester’s email checker parse the full header structure and can automatically assess this during verification.
- Extract the DKIM-Signature header from the email’s raw source. This header contains the cryptographic signature and metadata. You can view this in most email clients by selecting “Show original” or similar, or use a tool like MXToolbox to analyze headers.
- Check for the b= parameter within the DKIM-Signature header. It must be present and not empty. The absence of b= indicates an invalid or improperly formatted DKIM signature, which will cause verification failures.
- Validate the base64 encoding of the value after b=. If it’s malformed or not valid base64, the signature is invalid. Base64 must decode cleanly into binary data without padding errors or invalid characters.
- Verify the body hash match by computing the hash of the message body using the same algorithm specified (typically SHA-256). Compare it with the value in the d= tag or the signature’s body hash parameter. Any mismatch means the message was altered after signing.
- Use a full parser, not just detection. Basic tools may only check for header existence. A tool like MailTester’s email checker parses the entire DKIM-Signature field, including the b= tag and body canonicalization, to assess validity accurately.
Why b= is critical
The b= tag holds the actual cryptographic signature. Without a correct, non-empty value, DKIM cannot authenticate the message. Even if other parameters are present, the absence of a valid b= means the message fails verification at the receiver’s end. According to RFC 6376, this is the core of the DKIM validation process.
Common pitfalls to avoid
- Don’t assume a signature exists just because the header is present.
- Don’t skip body hash validation — it’s essential for detecting tampering.
- Don’t rely on tools that only flag “DKIM signed” without checking b= and its integrity.
DKIM relies on cryptographic integrity: the b= tag is not optional. Without it, the signature is meaningless.
For automated, reliable verification at scale, use a service like MailTester’s bulk verification or API, which test signatures as part of a full email health assessment — including b= tag validation, base64 integrity, and body hash consistency.
Common reasons why b= tag is missing or invalid
You're checking DKIM verification and seeing missing or invalid b= tags because the signature wasn't properly generated—often due to misconfigured email providers, incomplete signing, or header manipulation during transit. Let’s break down the most common technical causes and how to fix them.
ESP or signing tool misconfiguration
- Many email service providers (ESPs) like SendGrid or Mailchimp handle DKIM signing automatically—but if the domain or key is misconfigured, the
b=tag may be omitted entirely. Double-check your ESP’s DNS settings and ensure the public key is published correctly. - If your signing software doesn’t compute the body hash—often a default behavior in some open-source tools—the
b=tag won’t appear. This is especially common when using custom scripts or older versions of libraries like OpenDKIM. - Some ESPs apply default signing keys or placeholder values during testing. If you’re using a test key with
q=orph=placeholders instead of actual signed data, theb=tag will be missing or invalid. Always verify that keys are active and fully generated before sending.
Transit issues and manual edits
- Email servers or intermediaries (e.g., forwarding services, email gateways) can strip or alter headers during delivery. If the
DKIM-Signatureheader is modified, even slightly, theb=tag becomes invalid. Use a tool that checks the full header chain via RFC 6376 for accurate results. - Manual edits to the email body or headers—such as adding or removing whitespace, changing line breaks, or editing in a rich-text editor—will invalidate the body hash. The
b=tag is calculated from the canonicalized body, so any deviation breaks the signature. - Some systems insert tracking pixels or automatically add footers, which modify the body content. These changes can break DKIM unless the signing engine replays the full message with all modifications in place. Always test your message flow with realistic delivery scenarios.
Use MailTester’s email checker to validate the full DKIM signature, including the b= tag, before sending to high-volume campaigns. It checks real-time DNS, header integrity, and signature structure—no guesswork.
How MailTester helps verify DKIM b= tag presence and correctness
You can check if a DKIM signature contains the b= tag during verification by testing the full email header with a tool that parses DKIM signatures in real-time. MailTester performs this validation automatically during inbox placement tests, confirming whether the b= tag is present, correctly formatted in base64, and aligned with required parameters like v=, a=, d=, s=, and bh=. The result isn’t just a yes/no—it’s granular feedback on what’s missing or malformed.
Full DKIM header parsing in real send flows
When you run an inbox placement test with MailTester, we don’t just check if an email reaches the inbox—we examine the raw headers as they’ll appear in the recipient’s mail server. This includes full parsing of the DKIM-Signature header, which means we detect whether the b= tag is present and properly structured. If a signature lacks b= or uses invalid base64 encoding, we flag it immediately.
Digital signatures rely on precise formatting. The b= tag holds the cryptographic signature itself and must be valid base64. Invalid or missing b= tags are a frequent cause of delivery failures. According to RFC 6376, the DKIM-Signature header must include specific fields: v= (version), a= (algorithm), d= (domain), s= (selector), bh= (body hash), and b= (signature). MailTester verifies all required fields are present and correctly formatted.
Granular feedback and real-world integration
If a DKIM signature fails, MailTester doesn’t just say “invalid.” It tells you exactly why—whether it's a missing b= tag, a malformed base64 string, or a missing required parameter. You get actionable insights to fix your setup before sending to real users.
These checks aren't theoretical. MailTester integrates directly with sending platforms like SendGrid, Mailchimp, and Klaviyo. This means you can test DKIM correctly configured in your actual send flows—before your campaign goes live. You can run an inbox placement test on a sample of your list to see how DKIM signatures are interpreted during real delivery.
For automated verification in production, you can use our real-time verification API, which also validates DKIM structure at scale. Whether you're checking one address or a list of thousands, the same header-level logic applies. No guesswork. No false positives. Just clear, technical validation.
DKIM parameter reference: what each tag does
You can check if a DKIM signature contains the b= tag by examining the raw DKIM-Signature header in an email’s source. The b= tag holds the base64-encoded digital signature of the canonicalized message body and headers, derived from the public key published in DNS. It’s the final component that recipients use to verify the message’s integrity. If it’s missing, the signature is invalid. For real-time validation, use a DKIM checker tool or test via MailTester’s email checker.
DNS record structure and tag meaning
The DKIM-Signature header uses a set of tagged values. Each tag has a defined purpose. The structure follows the standard outlined in RFC 6376, the official specification for DKIM.
| Tag | Meaning | Required Value | Example |
|---|---|---|---|
v= |
Version tag | Must be 1 |
v=1 |
a= |
Signing algorithm | Commonly rsa-sha256 |
a=rsa-sha256 |
d= |
Signing domain | The domain that owns the DKIM key | d=example.com |
s= |
Selector | Locates the public key in DNS | s=mail (e.g., mail._domainkey.example.com) |
bh= |
Body hash | Base64-encoded hash of the canonicalized body | bh=9nZ3q8yRvT6tUoXWqZkPZQ== |
b= |
Digital signature | Base64-encoded signature of canonicalized headers and body | b=3KJXh1c3Kp1mYQ6x1cQrZ8vFg4Tn1vPmOq... |
Why the b= tag matters in verification
The b= tag is the final piece that proves authenticity. Without it, no verification can succeed. It’s the cryptographic proof that the message hasn’t been altered since signing. If it’s absent, malformed, or fails validation against the public key in DNS, the message is rejected or marked as suspicious.
When you’re doing email list verification, it’s useful to test whether a sender consistently signs with a valid b= value. Tools like MailTester’s bulk verification check DKIM presence and validity during email validation, helping you identify risky or untrusted senders before sending.
How to fix a missing or invalid b= tag in DKIM
If your DKIM signature lacks the b= tag, it means the email body hash wasn’t included during signing—common with misconfigured email systems. This breaks DKIM validation and harms deliverability. Fix it by reviewing your signing setup, ensuring the body hash is computed and included, the private key is correctly applied, and testing with a valid message template. Use MailTester’s real-time API to catch issues before sending.
Check the DKIM signing configuration
- Review your email provider's DKIM setup—whether it's SendGrid, Amazon SES, or an in-house mail server. Look for settings that control what parts of the email are signed (headers vs. body).
- Ensure the signing process includes the
body-hashand outputs theb=tag. This tag is required by RFC 6376 to confirm the message body hasn’t been altered. - Check if your system skips hashing the body—some tools default to signing only headers, which fails DKIM validation.
Verify the signing process and test
- Confirm the private key used for signing is properly installed and matches the public key published in DNS. A mismatch invalidates DKIM, even with correct tags.
- Use a known good email template—like a standard newsletter or welcome message—to test the signing process. This isolates whether the issue is with content or configuration.
- Test the output manually by sending to a mailbox that shows raw headers (e.g., Gmail or ProtonMail). Look for the
b=tag and confirm it’s not empty or missing. - Use MailTester’s real-time verification API to validate DKIM output before sending. It checks not just syntax but also whether the
b=tag is properly generated and aligned with the body hash. You can test individual messages or integrate the API into your workflow: test DKIM and deliverability live.
The b= tag is not optional—it's required for full DKIM validation. Skipping it means your message fails at the receiving end, even with valid headers.DKIM is a foundational email authentication method. A missing b= tag is a common but fixable error. Addressing it early keeps your sender reputation intact and ensures inbox placement. For teams managing bulk sends, regular validation with tools like MailTester helps prevent issues before they affect delivery.
Why checking the b= tag should be part of your email verification process
You should check for the b= tag in DKIM signatures during email verification because a missing or malformed b= tag breaks authentication, even if the email address itself is valid. Without a properly formatted b= tag, messages fail DKIM validation, which triggers spam filters, lowers inbox placement, and damages your sender reputation. Let’s go over why this check isn’t just technical—it’s essential.
Authentication fails even with a valid address
Many tools confirm an address is syntactically correct but miss the underlying authentication health. An email might be valid in format but still fail due to a broken DKIM signature—especially if the b= tag is missing or incorrectly formatted. This means your message gets blocked or marked as spam, even though the recipient exists.
Prevent bulk campaigns from failing before they launch
Checking for a valid b= tag during list verification helps catch domain misconfigurations before you send to thousands. If your domain's DKIM setup is broken—say, the selector or private key doesn’t match the public record—then any recipient with that domain will see a failed signature. This isn’t just a one-off issue; it can trigger ongoing delivery problems across large campaigns.
Malformed or missing b= tags are one of the most common reasons email providers reject messages, even when the delivery path is technically sound. Tools like MailTester’s bulk email verification include this check as a standard part of its process, identifying invalid signatures early. According to the DMARC adoption report by dmarc.org, a significant fraction of email failure cases stem from cryptographic issues in DKIM—not invalid addresses.
Reputational damage from repeated delivery failures is harder to recover from than a single bounce. A single failed DKIM check can trigger blacklisting, especially if the domain consistently fails authentication. That’s why real-time verification with proper DKIM checks—not just syntax—matters.
When you verify a list at scale, you're not just checking if someone exists—you're verifying whether their email provider will accept your message. The b= tag is part of that promise. Without it, your message never gets past the gatekeeper. So yes—check the b= tag. It should be part of any serious email verification process.
Real-world impact of unverified DKIM b= tags on inbox placement
DMARC policies depend on DKIM signature alignment. When a DKIM signature lacks the required b= tag, the signature fails validation, leading to policy rejection by receiving servers.
Inbox providers such as Gmail and Outlook treat messages with missing or malformed b= tags as low trust. This reduces inbox placement and increases the risk of messages being routed to spam or rejected outright.
Even with a high-quality email list, unverified DKIM signatures result in high bounce rates and poor engagement. High-volume senders with broken DKIM are at risk of blacklisting or temporary suspension from major inboxes.
Sources
- DMARC adoption among top domains surged 75% between 2023 and 2025 — from 27.2% to 47.7% — in the wake of Google and Yahoo's bulk-sender authentication requirements. — EasyDMARC 2025 DMARC Adoption Report (2025)
- Since May 5, 2025, Microsoft Outlook requires SPF, DKIM, and DMARC from domains sending 5,000+ emails per day, rejecting non-compliant mail outright at the SMTP level with error 550 5.7.515. — Microsoft Outlook requirements (via MailOver bulk-sender requirements guide) (2025)
Keep reading
- Email authentication: SPF, DKIM, DMARC, BIMI and MTA-STS (complete guide)
- How to Fix SPF Softfail Despite Valid IP and No Include
- DMARC Report Fails to Parse Due to Invalid XML Namespace
- Fix SPF Record Malformed Syntax in DNS After Typo
- 550 5.7.1 DMARC Error Due to Malformed Report URI in Mailgun
Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.
Frequently asked questions
Can a DKIM signature pass without a b= tag?
No. The b= tag is required for a valid DKIM signature. Without it, the signature is incomplete and fails verification.
Does MailTester check if the DKIM b= tag is correctly formatted?
Yes. MailTester validates that the b= tag exists, is base64-encoded, and is properly structured within the full DKIM header.
What happens if the b= tag is present but invalid?
The DKIM signature fails during validation. Even with correct domain and selector, the message may be marked as tampered or untrusted.
Can a catch-all email address have a valid DKIM with a b= tag?
Yes — catch-all domains may have valid DKIM setups, but they often lack alignment. Always test individual sender domains.
How does MailTester integrate with SendGrid to verify DKIM b= tags?
MailTester connects via SendGrid’s API to test messages in real send environments, including DKIM header parsing and b= tag validation.
Does DKIM require both b= and bh= tags?
Yes. The bh= tag holds the body hash used to generate the b= signature. Both must be present and match during verification.
Is the b= tag case-sensitive?
Yes. The b= tag and its value are case-sensitive. Base64 encoding relies on correct character casing.
Can a valid DKIM signature pass without proper header canonicalization?
No. Canonicalization must match the signing process. Mismatches in header or body handling break the b= signature match.
Can a DKIM signature be valid without a public key in DNS?
No. Receiving servers use the DNS-published public key to verify the b= signature. Without it, verification fails.
How often should I verify DKIM b= tags during email campaigns?
Verify before each major send. Use MailTester’s API or inbox testing to catch issues early, especially after configuration changes.
What does a 'DKIM fail' mean in MailTester’s verification results?
It means a DKIM signature verification failure — possibly due to a missing or malformed b= tag, alignment issue, or key mismatch.
Can disposable email domains have valid DKIM with a b= tag?
Some do, but it’s rare. Most disposable domains have weak or no DKIM alignment. MailTester flags them as risky or invalid.