In more detail
The sending server signs selected headers and the body; the DKIM-Signature header names the domain (d=) and selector (s=) to look up. A valid signature shows the message came through a server authorised by that domain and was not changed in transit. It is one leg of DMARC.