v=spf1 include:_spf.google.com mx a:h2Jammy.yushei.net a:mail.h2jammy.yushei.net ~all

v=spf1 include:_spf.google.com ~all

v=DKIM1; h=sha256; k=rsa; t=y; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA04DhjXmwTr2p2EB6VowA55f3Y33ugO0DwyJeHu5EZT7eNNjfbfQZMcXtHB9e15kQ34YJjZVhv2iOBryaotpx0TWtPzbXekpq/jZdMaopcf/HGbN6A53b5l/AsgvSGG+Gd2bwiF2RGBHL/lEo0JpX/hUvpL5NNtFHaILAWc9w6c1FTS1bqyF3NkqljcGuCBnLpa3p5q3IeoBcVNzM2Qhzm5VuVI7+IZzWp4/rRznG8gqd2jYqkjWI4D7JjdN/JGE/LTtHXm5VVm4Aq9NEptMPGidvoSOdvdCq6s3h1Ix8kp6JqNiIU2Nyo1KgP0uQySMUFu0iewiHGNp2cqj5a7IL5wIDAQAB

v=1; a=rsa-sha256; d=example.com; s=big-email; h=from:to:subject; bh=uMixy0BsCqhbru4fqPZQdeZY5Pq865sNAnOAxNgUS0s=; b=LiIvJeRyqMo0gngiCygwpiKphJjYezb5kXBKCNj8DqRVcCk7obK6OUg4o+EufEbB tRYQfQhgIkx5m70IqA6dP+DBZUcsJyS9C+vm2xRK7qyHi2hUFpYS5pkeiNVoQk/Wk4w ZG4tu/g+OA49mS7VX+64FXr79MPwOMRRmJ3lNwJU=

The digital signature (b=) allows the receiving server to 1. authenticate the sending server and 2. ensure integrity — that the email has not been tampered with.

The receiving server does this by taking the same content that is listed in h= plus the body hash (bh=) and using the public key from the DKIM record to check if the digital signature is valid. If the correct private key was used and if the content (headers and body) has not been altered, the email passes the DKIM check.