DKIM Selector and DKIM Generator: How DKIM Signing Works

By MXToolbox Team · August 22, 2026

DKIM is the part of email authentication that confuses people most, mainly because of one term: the selector. Here’s what it is and how the whole signing process actually works.

What DKIM does, in one sentence

DKIM (DomainKeys Identified Mail) attaches a cryptographic signature to outgoing email, generated with a private key, which receiving servers verify using a matching public key published in your DNS.

Why DKIM needs a “selector” at all

A domain might rotate its DKIM keys over time, or use different keys for different sending systems (e.g. one key for Google Workspace, another for a marketing tool). To support that, each DKIM public key is published at a distinct DNS location, identified by a selector:

selector._domainkey.yourdomain.com

The selector is just a label — often something short like google, s1, k1, or default. It has no fixed meaning; each provider picks its own convention.

Where the selector comes from

You don’t choose the selector yourself in most cases — your email provider assigns it when it generates your DKIM key pair. Common examples:

ProviderTypical selector pattern
Google Workspacegoogle
Microsoft 365selector1, selector2
Mailchimpk1, k2, k3
SendGrids1, s2
Amazon SESrandom hash, e.g. abcdef1234567890

What the DKIM DNS record actually contains

A DKIM TXT record at selector._domainkey.yourdomain.com typically looks like:

v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC...

If p= is empty (p=;), that’s a deliberate way to revoke a DKIM key without deleting the record — it signals “this selector is retired.”

Do you need a DKIM generator?

In most real-world setups, no. The generation flow looks like this:

  1. Your email provider (Google Workspace admin console, Microsoft 365, or your ESP’s dashboard) generates a public/private key pair internally.
  2. It gives you the DNS TXT record to publish, already formatted with the correct selector.
  3. You add that record to your DNS.
  4. The provider signs outgoing mail with the private key, which never leaves their infrastructure.

Standalone DKIM generator tools exist mainly for self-hosted mail servers (e.g. using OpenDKIM), where you’re running your own mail transfer agent and need to generate the key pair yourself with a tool like opendkim-genkey.

Finding your existing DKIM selector

If you’ve lost track of which selector your provider uses:

  1. Check your provider’s admin console — DKIM setup pages always display the exact selector and record.
  2. Look at a DKIM-Signature header in an email you’ve already sent. It includes a s= tag with the selector:
    DKIM-Signature: v=1; a=rsa-sha256; d=yourdomain.com; s=google; ...
    
  3. Guess common selectors and check DNS. Try google, default, selector1, selector2, k1, s1, mail against <selector>._domainkey.yourdomain.com.

Checking a DKIM record

Use the free SPF/DKIM/DMARC checker — enter the domain and the selector, and it validates the record’s syntax and confirms whether a public key is present.

Once your DKIM signing is confirmed working alongside SPF and DMARC, mailbox reputation and warm-up become the next lever for deliverability. MailPilot gradually warms up new mailboxes and tracks deliverability for cold email and sales outreach senders.