Why do email headers like To and From require DKIM's h= tag?

You send an email. It lands in spam, not inbox. You check the headers. Everything looks correct—To, From, subject. But the recipient’s server rejects it. Why?

The issue isn’t your content. It’s the DKIM signature—specifically, the h= tag. DKIM signs only the headers listed in h=, and if To or From aren’t included, verification fails. That’s why critical email headers like To and From must be explicitly named in DKIM’s h= tag.

Without it, even perfectly valid email gets flagged as suspicious. Receiving servers use DKIM to validate authenticity. If the To or From header isn’t in the h= list, they can’t confirm it was signed as intended. The signature passes, but the header check fails. Result: rejection, spam placement, or sender reputation damage.

Key takeaways

  • Dkim's h= tag explicitly lists which headers are signed, and To/From must be included to validate their authenticity.
  • Without To and From in the h= tag, receiving servers cannot verify the signature covers these fields, leading to authentication failure.
  • Missing critical headers from h= increases the risk of spam filtering, delivery failure, and reputational damage—especially under scrutiny from high-security domains.

What happens when the h= tag is missing or incorrect in critical headers?

If the h= tag is missing or misconfigured in your DKIM signature for critical headers like To and From, the email will fail DKIM validation—even if other parts of the message are signed correctly. Receiving servers check the h= list to know which headers to include in the signature hash. If the header isn't listed, or its name is misspelled, the verification fails. This failure is often flagged as a red flag in automated spam and reputation systems.

Why To and From matter in DKIM validation

DKIM signs specific headers to verify the message hasn't been tampered with. The h= tag tells the receiving server exactly which headers are part of that verification. If To or From aren't included in that list—especially when they're critical to the sender's identity—the signature is considered invalid. Even minor issues, like using from instead of From, break the alignment.

Mail receivers like Google, Microsoft, and Mailchimp use DKIM results directly in their scoring systems. A failed check in any of the required headers (especially From) reduces sender reputation. This can lead to delayed delivery, increased chances of being marked as spam, or outright rejection via greylisting or blocklists. The system is designed to detect subtle signs of spoofing—missing or misaligned headers are one such signal.

How small errors cause big delivery issues

You might think a missing h= tag is a small technical oversight, but it has real consequences. Even if the body is signed and the From header looks correct, the misalignment triggers automated filters. Greylisting commonly applies for misconfigured DKIM, especially during new sender onboarding or list re-verification. Spam filters flag this as inconsistent behavior, especially if your domain’s From header isn’t properly aligned with the DKIM signature.

Let’s say you’re sending to a mailing list. If even 5% of your emails have misaligned DKIM headers, your overall deliverability drops significantly. The receiving server sees inconsistency in authentication. Over time, repeat failures harm your domain reputation—even if your content is safe.

Tools like MailTester’s bulk verification scan for these exact alignment issues before you send. It checks whether your DKIM setup, including the h= tag, properly covers all critical headers. This prevents misconfigured emails from leaving your server in the first place.

Drafting a compliant DKIM signature goes beyond just signing the body. It requires careful alignment of header names, correct casing, and proper inclusion in the h= parameter. For detailed validation, refer to the official DKIM specification (RFC 6376), which outlines how header signing must be configured for trust to be established.

Even a single misaligned header can cause systemic delivery issues. Verify your email authentication early—before your message hits the inbox.

How does DKIM actually verify To and From headers?

DKIM signs specific headers using the h= tag in the signature, like h=From:To:Subject. If the receiver finds a missing or altered header included in the signed list, the signature fails—proving the message wasn’t sent as claimed. Even a single missing header breaks the chain of trust.

The Signature Process Explained

  1. Sender adds the h= tag to the DKIM signature—you specify which headers are signed. For example, h=From:To:Subject means these headers must remain unchanged.
  2. Receiving server checks the h= list—it retrieves the DKIM signature and identifies which headers were included in the signing process. This list is defined in the h= tag.
  3. Server re-signs the message using the same headers—it takes the exact version of each header listed in h=, applies the hash function, and compares the result against the signature in the email.
  4. If a signed header is missing or changed, the check fails—even a tiny alteration, like a missing space in the To: field, breaks the signature. This prevents spoofing and ensures integrity.
  5. Without proper h= tagging, DKIM can’t enforce header authenticity—if From: or To: aren’t listed, the server won’t verify them, leaving them open to manipulation.

Why To and From Matter in DKIM

These headers are critical because they define the sender’s identity and recipient. If an attacker modifies either header, the email appears to come from a different person or go to a different address. DKIM prevents this only when those headers are explicitly protected via the h= tag.

The Signature Process ExplainedThe 5 steps described in “The Signature Process Explained”, in order.1Sender adds the h= tag to the DKIM signature—you specify which headersare signed. For example, h=From:To:Subject means these headers mustremain unchanged.2Receiving server checks the h= list—it retrieves the DKIM signature andidentifies which headers were included in the signing process. This listis defined in the h= tag.3Server re-signs the message using the same headers—it takes the exactversion of each header listed in h=, applies the hash function, andcompares the result against the signature in the email.4If a signed header is missing or changed, the check fails—even a tinyalteration, like a missing space in the To: field, breaks the signature.This prevents spoofing and ensures integrity.5Without proper h= tagging, DKIM can’t enforce header authenticity—ifFrom: or To: aren’t listed, the server won’t verify them, leaving themopen to manipulation.
The 5 steps described in “The Signature Process Explained”, in order.

According to the IETF’s official specification, RFC 6376, “The list of headers included in the signature is specified by the h= tag.” This is non-negotiable: the receiving server must check every header listed there.

If the To or From header isn’t in the h= list, DKIM won’t verify it—even if it’s technically valid. The system relies on explicit inclusion for security.

You can test how headers are signed and whether your emails comply with DKIM standards using real-world inbox placement tools. For example, MailTester’s inbox placement tests show you whether your DKIM setup passes checks in real inboxes across providers.

What are the roles of SPF, DKIM, and DMARC in email authentication?

You’re not just sending an email—you’re sending a digital promise: "This is from who it claims to be." SPF, DKIM, and DMARC are the technical foundation that verifies that promise. SPF checks if the sending server's IP is authorized. DKIM cryptographically signs parts of the message to prove it hasn’t been altered. DMARC ties them together, enforcing policies like reject or quarantine for messages that fail either check. Together, they stop spoofing and boost deliverability.

How Each Protocol Works

Let’s break down what each one actually does—no jargon, just clear mechanics.

Authentication Roles: A Real Comparison

Protocol Primary Role What It Checks How It Works
SPF (Sender Policy Framework) Authorizes sending IPs Whether the server that sent the email is listed as allowed in the domain’s DNS records Checks the Return-Path or MAIL FROM address against a DNS TXT record set by the domain owner.
DKIM (DomainKeys Identified Mail) Verifies message integrity and sender identity Whether the email was altered in transit and if it genuinely came from the claimed domain Uses cryptographic signatures over selected headers and the message body. The receiving server verifies the signature using a public key published in the sender’s DNS.
DMARC (Domain-based Message Authentication, Reporting & Conformance) Enforces policies using SPF and DKIM results Whether the email passed SPF or DKIM checks, and what to do with failed messages Specifies the policy (none, quarantine, reject) for handling emails failing authentication. It also enables reporting to help domain owners detect abuse.

These are not optional add-ons. Major platforms like Gmail and Outlook use them to decide whether an email goes to the inbox, spam folder, or is blocked outright. According to a IETF RFC, email authentication is the baseline expectation for modern outbound email systems.

Here’s the catch: if you have missing or misconfigured headers—like a From: address that doesn’t match the DKIM h= tag’s header fields—you won’t pass DKIM validation. The signature won’t align, and your message fails. That’s why h= matters: it tells the verifier which header fields are part of the signed content. If From: is in the signature but not included in h=, or vice versa, the check fails.

Use MailTester to check how your emails are authenticating before sending. Our inbox placement tester checks not just deliverability but whether your headers, DKIM, SPF, and DMARC are correctly aligned.

How can a misconfigured DKIM h= tag affect deliverability?

If your DKIM signature doesn’t include the correct h= tag listing the headers being signed, spam filters flag it as incomplete or inconsistent. This undermines sender reputation over time, especially when paired with high bounce rates or low engagement—key signals providers like Gmail and Yahoo use to decide inbox placement. A single failed DKIM check on a major domain can trigger temporary delivery restrictions, even if other authentication checks pass.

Headers matter: why the h= tag isn’t optional

DKIM’s h= tag specifies which email headers are included in the signature. If it’s missing or wrong—say, it omits From, To, or Subject—the receiving server can’t verify the integrity of those fields. This isn’t a minor detail; it breaks the cryptographic chain and makes the message look suspicious. Major providers expect full, correct signing across all core headers, as outlined in RFC 6376.

Let’s say your email client or ESP auto-signs only From and Date, but you misconfigure h= to include To. The receiving server checks and finds no To header in the signature, even though it’s in the actual message. That mismatch triggers a DKIM failure. Even if the rest of your setup is solid, this inconsistency raises red flags with spam detection systems.

Reputation and deliverability pay the price

Repeated DKIM failures—even from a single misconfigured header—signal poor sending hygiene. Over time, providers like Gmail or Yahoo apply cumulative penalties. You might see your deliverability drop after multiple failures, even if no message was actually malicious. This is especially impactful when combined with high bounce rates: senders with poor sender reputation often get throttled or moved to spam.

Even one failed DKIM check on a high-volume recipient domain can trigger temporary blocks. For instance, Gmail’s systems may pause delivery for a few hours or require more scrutiny before approving future emails. These temporary restrictions aren’t always logged in public reports, so it’s easy to miss until inbox placement drops unexpectedly.

Preventing this starts with validation. Before sending, verify not just whether an email exists—but whether its authentication is properly structured. Use tools like MailTester’s Email Checker to test individual addresses, including header signing integrity. You can also run bulk checks with MailTester’s List Verifier to catch configuration issues across your list before they impact deliverability.

DKIM is a core part of the email authentication chain that signals trust to inbox providers. Without a properly configured DKIM h= tag, even flawless content and a clean list can be blocked or filtered. A failure here breaks the chain before deliverability even begins.

Authentication is the first gatekeeper

Mail providers don’t just look at your message content—they check who sent it, and how. The inbox placement process starts with authentication: SPF, DKIM, and DMARC. If any part fails, the message is likely to be treated as suspicious or spam.

DKIM specifically signs the message body and headers using a cryptographic key. The h= tag in the DKIM signature defines which headers are included in that signature. If your DKIM h= tag is missing or misconfigured—say, you only sign the From header but forget To or Cc—providers detect inconsistency. This inconsistency raises red flags even if your content is clean.

Anomalies like this aren’t just technical quirks; they’re signals of potential spoofing. Providers like Gmail and Microsoft Mail use automated systems to validate signature integrity across the full header set. A mismatch means the signature doesn’t match what was sent—so the message gets tagged as unverified.

How tools like MailTester catch the chain-breaking errors

Your domain might pass SPF and DMARC, but a single missing or incorrect DKIM h= tag can still derail your campaign. This is why testing before sending matters. A real-time verification tool like MailTester’s inbox placement test analyzes the full authentication stack—including header hashing—before your email ever hits the inbox.

It checks not just whether your DKIM signature exists, but whether the h= tag aligns with the headers actually sent. That means catching issues like omitted headers in the signature or inconsistent signing practices before they hurt your deliverability.

Even with perfect list hygiene and high engagement, a broken DKIM signature can reduce inbox placement by 30–40% in some cases. This is not speculative—these drops are commonly seen in industry benchmark reports from sources like RFC 6376, which defines the DKIM standard.

Use mail testers to validate your setup. MailTester’s deliverability test reveals DKIM h= misconfigurations early. You can run a quick inbox placement check on any email before sending: test your message’s chances in real inboxes.

How to test if your To and From headers are correctly signed by DKIM

You must verify that your DKIM signatures include the h= tag with From and To in the header fields list to ensure authentication validity. Without this, receivers may reject your email or flag it as suspicious. Use an actual sent message and inspect its raw headers to confirm this.

Step-by-step verification process

  1. Send a test email from your domain to a trusted inbox (like Gmail or Outlook). Do not use a test account or placeholder. This ensures the DKIM signature is generated under real conditions.
  2. Download the raw message headers from the email’s full headers section. In Gmail, click the three-dot menu → "Show original"; in Outlook, go to File → Properties → "Internet headers".
  3. Look for the DKIM-Signature header in the raw output. It begins with DKIM-Signature: and contains multiple fields. The h= tag specifies which headers are signed.
  4. Check that h=From:To appears in the DKIM-Signature. If the list includes only subject or date, the signature is incomplete. The From and To fields must be included for proper authentication—this is required by SPF and DMARC alignment.
  5. Validate the full chain using MailTester’s inbox-placement test to simulate how your email behaves in real inboxes. Send the full message header to MailTester’s inbox placement tool to check for authentication alignment and delivery risks.

Why this matters

DKIM signing without From and To in the h= list breaks header alignment, a core requirement for SPF and DMARC. Even if the signature is mathematically valid, receivers may still reject the email. This is documented in RFC 6376, which specifies how DKIM signing should cover key email identifiers.

According to industry best practices, misaligned DKIM signatures are among the top reasons for inbox filtering. You can check alignment status using tools like Spamhaus’ lookup or MxToolbox’s email diagnostic tools, both of which analyze DKIM, SPF, and DMARC results at scale.

Let’s be clear: a perfectly formed DKIM signature that omits essential headers like From and To still fails in practice. It’s not just about syntax. It’s about delivering a message that receivers trust. Use MailTester’s inbox placement tool to test the entire flow—auth, headers, alignment, and deliverability—all in one step.

What does a valid DKIM h= tag look like in practice?

You must include every header field used in the DKIM signature within the h= tag, in the exact order they appear in the message. A valid h= tag lists all signed headers, such as From, To, Subject, Date, and Message-ID. If Date or Message-ID exists in the email but isn’t listed in h=, the signature fails—even if the rest is correct. This is common with automated systems that sign headers but omit critical ones from the header list.

What the correct h= tag looks like

  • Use h=From:To:Subject:Date:Message-ID; when these headers are included in your DKIM signature.
  • Include every header in the order they appear in the email, including headers like Date and Message-ID—they’re not optional, even if they seem trivial.
  • Double-check that the headers in h= match exactly what’s in the email (case-sensitive, no extra spaces).
  • If you’re using a tool to generate DKIM signatures, ensure it automatically detects and includes all used headers, or you’ll risk validation failure.

Why missing headers break DKIM even when they’re present

DKIM checks the signature against a specific list of headers. If Date is present in the email but not in the h= tag, the verifier will reject the signature—even if all other fields are correct. This is a standard behavior defined in RFC 6376, which mandates that h= must list every header that’s part of the signature, or the result is invalid.

Let’s say you send a message with a From, To, and Subject, but you forget to include Date in h=. The signature may still pass internal checks—but Gmail, Yahoo, and other major providers will reject it due to inconsistent header alignment. This is why even a small omission leads to deliverability issues.

For teams sending bulk mail, this kind of misconfiguration is a hidden source of bounces and inbox filtering. You can test whether your DKIM setup is correct with tools that evaluate header alignment and signature structure. MailTester’s inbox placement checker validates email headers and DKIM configuration in real-world conditions, revealing problems like missing Date or Message-ID in h= before they impact your deliverability.

How can MailTester help verify critical DKIM header signatures?

You can trust MailTester to validate that critical email headers like To and From include the correct h= tag in DKIM signatures, ensuring header alignment and preventing authentication failures. Our inbox-placement testing and bulk verification tools check DKIM header hashing and alignment in real time, catching misconfigurations before they hit inboxes.

DKIM header alignment: why the h= tag matters

DKIM uses the h= tag to define which headers are signed and hashed during verification. If the From or To header isn’t listed in h=, the signature fails, even if the email is technically valid. This often leads to delivery drops or rejection by strict filters like those used by Gmail and Microsoft. According to RFC 6376, proper header hashing is essential for DKIM to work as intended.

MailTester’s layered validation across your workflow

With our inbox-placement tester, you don’t just check if an email reaches the inbox—you see if the DKIM header alignment holds under real-world conditions. Our system analyzes the full email trace, including the h= tag, and flags any missing or misaligned headers.

For bulk lists, MailTester’s email list verification checks every address for header alignment and DKIM signing quality. It’s not just about validity—it’s about whether the email is trusted by the receiving server. Our bulk verification tool can scan thousands of addresses and return detailed feedback on header compliance.

If you're sending programmatically, our real-time verification API can validate DKIM header alignment before every send, reducing the risk of failed deliveries due to misconfiguration. The same logic applies to single-checks: use our email checker to catch header issues before sending.

Accuracy matters. MailTester achieves 98.9% accuracy in detecting valid, invalid, and risky email addresses—verified against known delivery behaviors and real mailbox results. And unlike many services, your purchased credits never expire, making it ideal for ongoing verification at any scale.

Conclusion: Don’t overlook the h= tag in critical headers

The DKIM h= tag is small but vital. It explicitly defines which headers are included in the cryptographic signature. Without it, receivers cannot verify the authenticity of critical headers like To and From.

If the h= tag omits or mislists these headers, authentication fails. This leads to rejected messages, poor inbox placement, and damaged sender reputation. Consistent header signing is not optional — it’s required.

Use verification tools to catch errors before sending. MailTester ensures every critical header is correctly signed, so your messages pass authentication and reach inboxes reliably.

Sources

Keep reading

Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.

Frequently asked questions

What does DKIM h= mean?

DKIM h= specifies which email headers are included in the digital signature. For example, h=From:To:Subject means those headers are signed.

Can I skip the h= tag in DKIM?

No. The h= tag is required. Omitting it makes the DKIM signature incomplete, leading to validation failures and potential rejection.

Why does the From header need to be signed in DKIM?

The From header determines sender identity. If it’s not signed, receivers can’t verify that the sender is authorized to claim that address.

Can a failed DKIM check be fixed after sending?

No. The check happens at the time of receipt. The only fix is to resend with a correctly configured DKIM signature.

Does MailTester check DKIM h= tags?

Yes. MailTester’s inbox-placement and verification tests analyze DKIM headers, including h=, to ensure correct signing alignment.

What happens if h= includes non-signed headers?

The signature fails. Receiving servers validate each header listed in h=, so including un-signed headers breaks authenticity.

How often should I audit DKIM header signing?

At least once per campaign and before major send campaigns. Use an automated tool like MailTester’s API or real-time verification.

Does h= affect spam score?

Yes. Repeated DKIM failures due to h= misconfigurations are tracked by spam filters as signs of poor sender hygiene.

Can DKIM work without From and To being signed?

It can, but not for sender identity verification. If From and To are un-signed, the receiving server cannot confirm the sender's legitimacy.

Why do some tools miss DKIM h= issues?

Many tools focus only on basic SPF/DKIM pass/fail. They don’t validate header alignment within h=. Dedicated testing is needed.

How does MailTester compare to other DKIM validators?

Unlike general email checks, MailTester includes deep header-level validation, including h= tag compliance, with 98.9% accuracy.

Can I use MailTester for email list verification and DKIM testing together?

Yes. Use MailTester’s bulk verification to clean your list and its deliverability tests to validate DKIM alignment simultaneously.