DnsGuard › Guides › DKIM

DKIM explained

DKIM (DomainKeys Identified Mail, RFC 6376) adds a cryptographic signature to every message you send. Your mail server signs the message with a private key; receivers fetch the matching public key from DNS and verify that the message really came from your domain and wasn't changed on the way. Unlike SPF, a DKIM signature usually survives forwarding.

Where DKIM keys live: the selector

Each signature carries a domain (d=) and a selector (s=). The public key is published as a TXT record at <selector>._domainkey.<domain>:

DKIM-Signature: v=1; a=rsa-sha256; d=example.com; s=s1; ...

s1._domainkey.example.com.  TXT  "v=DKIM1; k=rsa; p=MIIBIjANBgkqh...IDAQAB"

Some providers (Microsoft 365, many email-marketing tools) have you add a CNAME at the selector name that points to a record they host and rotate for you.

How to find your DKIM selector

DNS has no way to list a domain's selectors, so every checker has to guess common names (google, selector1, s1, k1 and so on). The reliable way is to open a message you sent, view the original or raw headers, find the DKIM-Signature header and read its s= value. Then check it directly: enter your domain below and put the selector under Advanced, or call /api/check?domain=example.com&selector=s1.

Key length and rotation

Common DKIM mistakes

How DnsGuard scores DKIM (25 of 100 points)

20 points if at least one valid public key is found, and 5 more if every valid key is 2048-bit or larger (or ed25519). If only malformed (non-revoked invalid) keys are found, DKIM gets 5. Revoked-only keys score 0; revoked keys are still shown for information. If no key is found at the selectors we try, DKIM also scores 0 with a warning, because your mail may well be signed with a selector we couldn't guess. Pass your selector to get an accurate result.

Check your domain now

Free check of SPF, DKIM, DMARC, BIMI, MX, MTA-STS and TLS-RPT with a 0–100 score and plain-English fixes. No sign-up.

More guides: SPF · DMARC · BIMI · MTA-STS & TLS-RPT