When an email is sent, the sending server generates a unique DKIM signature using a private key and attaches it to the email header. The receiving server retrieves the public key by querying the DNS records of the sender's domain. If the keys match, the email is considered authenticated. This ensures that the content of the email has not been altered during transit.