# Redacted (redacted.zk.email) > Prove an email is authentic (valid DKIM signature from its sender's domain) while hiding any parts of it, using zero-knowledge proofs. The original email never leaves the prover's device. ## For AI agents There is an installable agent skill, **redacted-email-proof**, that runs the whole flow locally from a terminal. It uses the same Noir circuits and Barretenberg prover as this website. - Instructions (SKILL.md): https://redacted.zk.email/skills/redacted-email-proof/SKILL.md - One-line install (Node 20+): `curl -fsSL https://redacted.zk.email/skills/redacted-email-proof/install.sh | sh` - Source: https://github.com/zkemail/Redacted/tree/main/skills/redacted-email-proof Flow: 1. Get the raw email. Gmail MCP: call `get_message` with `messageFormat: "RAW"`. Gmail API: `format=raw`. Browser: Gmail "Show original" → "Download original". 2. `node ~/.redacted-prover/redacted.mjs inspect email.eml` checks DKIM and shows the signed, canonical content. 3. `... prove email.eml --dry-run [--only-headers from,subject,date] [--hide-body --reveal "text"] [--hide "secret"]` previews exactly what becomes public. Confirm it with the user. 4. `... prove email.eml --publish` proves locally and uploads only the proof and its public outputs. It prints `https://redacted.zk.email/verify?id=`. Size limits: canonical body up to 200,704 bytes and signed header up to 4,096 bytes. Bodies over 8,448 bytes use the CLI-only "large" tier (~1 min, ~7 GB RAM), and bodies over 48,000 bytes the CLI-only "xl" tier (~2–4 min, ~14 GB RAM, needs a 16 GB+ machine), and bodies over 100,352 bytes the CLI-only "xxl" tier (~2–3 min, ~23 GB RAM, needs a 32 GB+ machine). 5. `... verify ` checks a proof locally and checks that its DKIM key hashes (modulus and redc) match the sender's DNS key (or archive.zk.email). Exit code 4 flags a legacy v1 proof, made before the 2026 soundness fixes. Don't rely on it. Privacy: the .eml is never sent anywhere. The published proof contains only the bytes you left unmasked. By default the values of to/cc/bcc/reply-to/list-post/list-unsubscribe are hidden, along with DKIM bh=. ## For humans - Prove an email in the browser: https://redacted.zk.email/generate-proof - Verify a proof: open its https://redacted.zk.email/verify?id=… link and press "Verify Proof". - Code: https://github.com/zkemail/Redacted