technical · sourced answer
What is a DKIM Selector?
A DKIM selector is a unique string used to identify a specific public key in a domain's DNS records. It allows a sender to use multiple DKIM keys for one domain, enabling key rotation and the use of different signing services without conflicting DNS entries.
Mechanical Function
The selector acts as a pointer in the DNS query. When a receiving server sees a DKIM signature in an email header, it looks for the selector value in the signature. It then constructs a DNS query for the record at selector._domainkey.example.com. This allows the receiver to retrieve the exact public key needed to verify the cryptographic signature of that specific message.
Importance for Senders
Selectors are critical for operational continuity. By using selectors, senders can rotate keys periodically to maintain security without causing authentication failures. If a key is compromised, a new selector can be deployed while the old one is phased out. This prevents downtime and ensures that legitimate mail continues to pass authentication checks during transitions.
Common Operational Mistakes
A frequent error is failing to match the selector used by the signing server with the selector published in the DNS record. If the signing tool uses selector1 but the DNS record is published under selector2, the verification will fail. Another common mistake is incorrect DNS propagation timing, where mail is sent using a new selector before the DNS record has reached all global resolvers.
Concrete Example
If a company uses two different services, they might use selector-marketing for their newsletter tool and selector-transact for their app notifications. The DNS records would be marketing._domainkey.example.com and transact._domainkey.example.com. You can verify these records using the free tools at https://sendhq.cc/tools to ensure the public keys are correctly published.
Key Rotation Strategy
Best practices involve generating a new key pair and publishing it under a new selector name. Once the new selector is propagated, the sending server is updated to sign with the new key. The old selector record is kept for a short period to allow receivers to verify messages that were sent just before the switch, then it is safely deleted.
Questions teams ask
Can a domain have more than one DKIM selector?
Yes, domains can have multiple selectors to support different sending services or to facilitate seamless key rotation.
Where is the selector located in an email?
The selector is found within the DKIM-Signature header of the email, specifically in the s= tag.
Does changing a selector affect SPF?
No, DKIM selectors are independent of SPF records and do not impact SPF configuration or verification.
What happens if a selector is missing from DNS?
The receiving server will be unable to find the public key, resulting in a DKIM permerror or fail status.
Primary sources
- RFC 6376: DomainKeys Identified Mail — RFC Editor
- Cloudflare DNS Documentation — Cloudflare