DKIM adds a digital signature to the headers of an email. This signature is generated using a private key that is kept secure by the sender. The recipient's email server uses the public key, published in the sender's DNS records, to verify the signature. If the signature is valid, it confirms that the email has not been tampered with and is indeed from the claimed sender.