DKIM explained
DKIM (DomainKeys Identified Mail, RFC 6376) adds a cryptographic signature to every message you send. Your mail server signs the message with a private key; receivers fetch the matching public key from DNS and verify that the message really came from your domain and wasn't changed on the way. Unlike SPF, a DKIM signature usually survives forwarding.
Where DKIM keys live: the selector
Each signature carries a domain (d=) and a selector (s=). The public key is published as a TXT record at <selector>._domainkey.<domain>:
DKIM-Signature: v=1; a=rsa-sha256; d=example.com; s=s1; ...
s1._domainkey.example.com. TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkqh...IDAQAB"
v=DKIM1: version (optional but recommended).k=: key type,rsa(the default) ored25519(RFC 8463).p=: the base64 public key. An emptyp=means the key has been revoked.
Some providers (Microsoft 365, many email-marketing tools) have you add a CNAME at the selector name that points to a record they host and rotate for you.
How to find your DKIM selector
DNS has no way to list a domain's selectors, so every checker has to guess common names (google, selector1, s1, k1 and so on). The reliable way is to open a message you sent, view the original or raw headers, find the DKIM-Signature header and read its s= value. Then check it directly: enter your domain below and put the selector under Advanced, or call /api/check?domain=example.com&selector=s1.
Key length and rotation
- Use 2048-bit RSA keys. 1024-bit keys still verify but are considered weak, and keys under 1024 bits are not accepted by major receivers.
- A 2048-bit key is longer than 255 characters, so it is stored as several quoted strings inside one TXT record. Most DNS panels do this for you; if yours doesn't, the key will look truncated.
- Rotate keys periodically: publish a new selector, switch signing to it, then revoke the old one by publishing an empty
p=(or deleting it) once old mail has been delivered.
Common DKIM mistakes
- Signing turned off in the provider's admin panel even though the DNS record exists (common with Google Workspace until you click "Start authentication").
- A key pasted with quotes, line breaks or a missing chunk.
- Third-party senders signing with their own domain (
d=sendgrid.netand so on) instead of yours, so the signature doesn't align for DMARC. Set up a custom sending domain in each tool.
How DnsGuard scores DKIM (25 of 100 points)
20 points if at least one valid public key is found, and 5 more if every valid key is 2048-bit or larger (or ed25519). If only malformed (non-revoked invalid) keys are found, DKIM gets 5. Revoked-only keys score 0; revoked keys are still shown for information. If no key is found at the selectors we try, DKIM also scores 0 with a warning, because your mail may well be signed with a selector we couldn't guess. Pass your selector to get an accurate result.
Check your domain now
Free check of SPF, DKIM, DMARC, BIMI, MX, MTA-STS and TLS-RPT with a 0–100 score and plain-English fixes. No sign-up.
More guides: SPF · DMARC · BIMI · MTA-STS & TLS-RPT