CHFI Application, Email and Cloud Forensics Practice Question
An analyst is investigating a possible data exfiltration via email. The analyst notices that the email headers contain a DKIM-Signature field that is invalid. Which of the following does a failed DKIM check indicate?
⚠ Common exam trap
EC-CHFI often tests the distinction between DKIM verification failure (integrity check) and domain alignment (DMARC), so candidates mistakenly choose the domain mismatch option when the question specifically asks about a failed DKIM check.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The email's content has been modified since it was signed
A failed DKIM check indicates that the email's content has been modified since it was signed by the sending domain's private key. DKIM uses an asymmetric cryptographic signature (typically RSA or ECDSA) to ensure the integrity of specific header fields and the body hash. When the signature verification fails, it means the hash computed from the received message does not match the decrypted hash from the signature, proving tampering or corruption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The email's content has been modified since it was signed
Why this is correct
DKIM signs specific header fields and the message body with a private key; verification uses the public key in DNS. A failed check means the signed content no longer matches the signature, indicating modification in transit or after signing.
- ✗
The email was sent through a proxy server
Why it's wrong here
DKIM validates a cryptographic signature over specified headers and the body using the selector's public key; relaying through a proxy does not by itself invalidate that signature, since the signing domain's key remains the verification reference. It is tempting because proxy routing can alter headers, but DKIM failure specifically indicates signature or body tampering.
- ✗
The email client does not support DKIM
Why it's wrong here
DKIM verification is performed by the receiving mail server against the DNS-published public key, not by the sending client; client capability is irrelevant because the signature is added by the signing infrastructure. It is tempting because client support affects other features, but a failed check indicates signature mismatch or key lookup failure, not client limitations.
- ✗
The email was sent from a different domain than the one in the From field
Why it's wrong here
A failed DKIM check means the cryptographic signature did not verify against the signing domain's published key, indicating the message was altered in transit or signed by an unauthorised key; it does not compare the From domain with the sending domain, which is SPF or DMARC alignment. It is tempting because domain mismatch is a common phishing indicator, but that is a separate check.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.