How DKIM works
The sending server signs each message with a private key and adds a DKIM-Signature header naming the signing domain (d=) and the selector (s=). The receiver fetches the public key from selector._domainkey.domain and checks that the signed headers and the body arrived unchanged. Because the signature travels with the message, DKIM survives forwarding, where SPF fails.
Finding the selector in a message
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=example.com; s=s1; t=1760140800;
h=from:to:subject:date:message-id;
bh=…; b=…Here the key lives at s1._domainkey.example.com. A message can carry several signatures — one from your domain and one from the provider that sent it; the one whose d= matches your From domain is the one DMARC counts.
Selectors of common providers
| Provider | Selector | How it is published |
|---|---|---|
| Google Workspace | TXT record with the key, generated in the admin console (the prefix can be changed) | |
| Microsoft 365 | selector1, selector2 | CNAME records to keys Microsoft hosts for the tenant |
| Amazon SES (Easy DKIM) | three generated names | CNAME records to dkim.amazonses.com |
| cPanel | default | TXT record, created with the domain |
A key published by CNAME stays with the provider, which can rotate it without you changing DNS; the check follows the CNAME and shows where it leads.
A key for your own server
With OpenDKIM, which most self-hosted setups use alongside Postfix, one command creates the key pair and the DNS record to publish:
opendkim-genkey -b 2048 -d example.com -s s1
cat s1.txt # the TXT record for s1._domainkey.example.com
# s1.private is the private key: keep it on the server, readable by opendkim onlyPick a new selector for every new key — a date works well, such as s202610 — so that old and new key can be published side by side while you switch over.
Frequently asked
What is a DKIM selector, and where do I find mine?
The name a domain publishes a DKIM key under: the key for selector s1 of example.com lives at s1._domainkey.example.com. Open the headers of a message you sent (Show original in Gmail, View source in most other programs) and find the DKIM-Signature line: s= is the selector, d= the signing domain.
Why does the check not find my DKIM key?
DNS has no way to list the selectors a domain uses, so without yours the check can only try common names — default, google, selector1, selector2, k1, mail, dkim, s1 and s2. Providers that rotate their keys often use dated selectors instead. Enter the s= value from one of your messages and the key is looked up directly.
What size should a DKIM key be?
2048-bit RSA is the usual choice today. 1024-bit keys still verify but are considered weak, and RFC 8301 tells receivers to reject keys under 1024 bits. A 2048-bit key is longer than one 255-character TXT string, so it is published as several strings in one record; this check joins them, as receivers do.
What does t=y in a DKIM record mean?
The domain is testing DKIM: receivers may treat signed mail as if it were unsigned. Remove the flag once signing works.
How do I rotate a DKIM key?
Publish the new key under a new selector, switch the mail server or provider to sign with it, and leave the old selector in DNS for a few days so that messages still in transit can be verified. Then revoke the old key by publishing it with an empty p= value, or delete the record.