dkimpy
DKIM (DomainKeys Identified Mail), ARC (Authenticated Receive Chain), and TLSRPT (TLS Report) email signing and verification
Decision gist · record as of 2026-08-14
Yes, if you need DKIM/ARC email authentication and can accept dormant maintenance. The library is production-stable with no known vulnerabilities and permissive licensing. However, high install friction (manual setup.py incantation for scripts) and 771-day release gap mean you should verify it works with your Python version and DNS resolver before production use.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires dnspython or py3dns for DNS lookups; ed25519 signing requires PyNaCl; async verification requires aiodns and Python 3.5+.
- Scripts installation requires: python3 setup.py install --single-version-externally-managed --record=/dev/null
- High install friction: the package requires manual setup.py incantation for scripts and man pages installation.
License · maintenance · safety
BSD-like (permissive) — BSD-like permissive license allows commercial and private use with minimal restrictions, typical of email infrastructure libraries.
last release 2024-07-04 (771 days)
0 known vulnerabilities (OSV.dev, 2026-08-14) · 830,584 downloads/mo, #4,946 on PyPI
Alternatives
Verify before relying
pip install dkimpy
# Sign a message
message = b'From: sender@example.com\nTo: recipient@example.com\nSubject: Test\n\nBody'
signature = sign(message, b'selector', b'example.com', open('private.key', 'rb').read())
# Verify a message
result = verify(message)- Whether dnspython or py3dns is automatically installed or must be manually selected
- Current compatibility with Python versions beyond 3.5 (minimum stated requirement)
- Whether ed25519, ARC, and asyncio extras are actively maintained alongside core functionality
- Whether the library correctly handles non-ASCII and non-UTF-8 content as documented
What it is and what it does
dkimpy is a cryptographic email authentication library that signs and verifies DKIM signatures on RFC822-formatted messages. It implements the core DKIM standard (RFC 6376) plus modern extensions: ed25519-sha256 signing (RFC 8463), ARC chain validation (RFC 8617), and TLSRPT service type support (RFC 8460). The library provides both a programmatic API and command-line tools (dknewkey, dkimsign, dkimverify). It requires DNS lookups to validate public keys, which can be performed synchronously or asynchronously.
The package is designed for mail transport agents, filters, and email infrastructure that need to cryptographically authenticate sender identity. It handles RSA keys (minimum 1024 bits per RFC 8301) and ed25519 keys, with optional support for ARC multi-hop authentication chains. The library is stable and production-ready but dormant: the last release was 771 days ago, so active maintenance and security updates are not expected.
Use it for
- Sign outgoing mail in a mail transport agent or filter to prove sender domain ownership
- Verify DKIM signatures on incoming messages to detect spoofing and validate sender authentication
- Validate ARC chains on forwarded messages to trace authentication through multiple hops
- Generate ed25519 key pairs for modern DKIM deployments requiring new cryptographic algorithms
- Implement async verification in high-throughput mail processing pipelines
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need DKIM/ARC email authentication and can accept dormant maintenance.
The library is production-stable with no known vulnerabilities and permissive licensing. However, high install friction (manual setup.py incantation for scripts) and 771-day release gap mean you should verify it works with your Python version and DNS resolver before production use.
Install
dkimpy on PyPI
Before you install
High install friction: the package requires manual setup.py incantation for scripts and man pages installation. Dormant maintenance status (771 days since last release) means bug fixes and security updates are unlikely, though the library has been stable since its early releases.
Requires dnspython or py3dns for DNS lookups; ed25519 signing requires PyNaCl; async verification requires aiodns and Python 3.5+. Scripts installation requires: python3 setup.py install --single-version-externally-managed --record=/dev/null
License in practice
BSD-like permissive license allows commercial and private use with minimal restrictions, typical of email infrastructure libraries.
Quickstart
pip install dkimpy
# Sign a message
message = b'From: sender@example.com\nTo: recipient@example.com\nSubject: Test\n\nBody'
signature = sign(message, b'selector', b'example.com', open('private.key', 'rb').read())
# Verify a message
result = verify(message)
Verify before relying
- Whether dnspython or py3dns is automatically installed or must be manually selected
- Current compatibility with Python versions beyond 3.5 (minimum stated requirement)
- Whether ed25519, ARC, and asyncio extras are actively maintained alongside core functionality
- Whether the library correctly handles non-ASCII and non-UTF-8 content as documented
Package facts
| License | BSD-like permissive |
| Python support | Not specified |
| Install friction | High. Source build required |
| Runtime dependencies | None |
| Maintenance | Dormant 771 days since the last release |
| First released | |
| Downloads | 830,584 / month, #4,946 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableEnvironment :: No Input/Output (Daemon)Intended Audience :: DevelopersLicense :: DFSG approvedNatural Language :: EnglishOperating System :: OS IndependentProgramming Language :: Python :: 3Topic :: Communications :: Email :: FiltersTopic :: Communications :: Email :: Mail Transport AgentsTopic :: Internet :: Name Service (DNS)Topic :: Software Development :: Libraries :: Python Modules |
Evidence: dkimpy-1.1.8.tar.gz
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “DKIM email signing verification”
- dkimpyImplements DKIM (DomainKeys Identified Mail) email signing and…
- mailsuitemailsuite retrieves, parses, and sends emails through a unified…
- authheadersGenerates and validates email authentication headers (DKIM, SPF,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Python Modules packages
Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.
Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.
Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.
PyYAML parses and emits YAML 1.1 data format, enabling serialization and deserialization of configuration files and Python objects to and from human-readable YAML text.
Pydantic validates Python data structures against type hints, coercing and checking input at runtime to ensure it matches a declared schema.
Provides reusable metadata objects for use with PEP-593 `typing.Annotated` to express common constraints like bounds, collection sizes, and predicates on types.
Install it if you use or build libraries that need to express type constraints in a standardized, inspectable way—or if you want to annotate your own types with…
Provides runtime tools to inspect and introspect Python type annotations, enabling programmatic examination of type hints at execution time.
See also authheaders · mailsuite · emails · validate_email · service-identity · ed25519-blake2b-fork · eip712 · cursive · parsedmarc · truelayer-signing