DKIM explained: selectors, keys and rotation
How DKIM signing works, how to find a domain's selectors, why 1024-bit keys get flagged, and how to change keys without a gap.
By the Domain Health Hub team · Updated
- DKIM adds a digital signature to each email, checked against a public key in the domain's DNS.
- Keys live at a selector, such as google._domainkey. A domain can have several.
- Use 2048-bit keys, and sign with the domain's own key so DMARC can align.
What DKIM does
DKIM (DomainKeys Identified Mail) has the sending server sign each message with a private key. The matching public key is published in DNS, so any receiver can check the message really came from someone holding the key and wasn't changed on the way.
Selectors and where keys live
A domain can have many keys, one per service, each at its own name called a selector. The key sits at selector._domainkey.domain:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...
- v=DKIM1
- Marks the record as a DKIM key.
- k=
- The key type: rsa, or ed25519 for newer keys.
- p=
- The public key itself. An empty p= means the key has been withdrawn.
Some providers publish a CNAME at the selector instead, pointing at a key they manage and rotate for you. Microsoft 365 works this way.
Key length
RSA keys shorter than 1024 bits are no longer accepted, and 2048 bits is the recommended length. Older set-ups often still use 1024-bit keys; they work today, but are worth replacing, and our checks flag them as something to improve.
Signing with the right domain
Many services sign with their own domain by default, such as a newsletter tool signing as itself. The signature passes, but it doesn't match the From domain, so it doesn't count for DMARC. Look for “custom domain” or “domain authentication” in each service's settings, and publish the records it gives you.
Changing keys without a gap
- Create the new key in the provider's settings, under a new selector.
- Publish it in DNS and wait for it to be visible everywhere, usually within an hour.
- Switch signing to the new selector.
- Leave the old key published for a week or so, since messages already sent may still be checked, then remove it.
Questions
How do I find a domain's DKIM selector?
Open the headers of an email the domain sent and find DKIM-Signature: the s= value is the selector and d= is the signing domain. Common ones include selector1 and selector2 (Microsoft 365) and google (Google Workspace).
Does forwarding break DKIM?
Usually not, which is why DKIM matters so much: the signature travels with the message. It breaks only if something along the way changes the signed content, such as a mailing list adding a footer.
Watch every client's domains, every day.
Reports read for you, and a monthly report card your clients will understand.