DKIM adds a digital signature to the email header, which is created using a private key. The recipient's mail server uses the corresponding public key (published in the domain's DNS records) to verify the signature. If the signature is valid, it confirms that the email has not been tampered with and is from the stated domain.