DKIM Selector and DKIM Generator: How DKIM Signing Works
DKIM is the part of email authentication that confuses people most, mainly because of one term: the selector. Here’s what it is and how the whole signing process actually works.
What DKIM does, in one sentence
DKIM (DomainKeys Identified Mail) attaches a cryptographic signature to outgoing email, generated with a private key, which receiving servers verify using a matching public key published in your DNS.
Why DKIM needs a “selector” at all
A domain might rotate its DKIM keys over time, or use different keys for different sending systems (e.g. one key for Google Workspace, another for a marketing tool). To support that, each DKIM public key is published at a distinct DNS location, identified by a selector:
selector._domainkey.yourdomain.com
The selector is just a label — often something short like google, s1, k1, or default. It has no fixed meaning; each provider picks its own convention.
Where the selector comes from
You don’t choose the selector yourself in most cases — your email provider assigns it when it generates your DKIM key pair. Common examples:
| Provider | Typical selector pattern |
|---|---|
| Google Workspace | google |
| Microsoft 365 | selector1, selector2 |
| Mailchimp | k1, k2, k3 |
| SendGrid | s1, s2 |
| Amazon SES | random hash, e.g. abcdef1234567890 |
What the DKIM DNS record actually contains
A DKIM TXT record at selector._domainkey.yourdomain.com typically looks like:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC...
v=DKIM1— identifies the record as DKIMk=rsa— the key algorithm (almost always RSA)p=— the actual public key, base64-encoded
If p= is empty (p=;), that’s a deliberate way to revoke a DKIM key without deleting the record — it signals “this selector is retired.”
Do you need a DKIM generator?
In most real-world setups, no. The generation flow looks like this:
- Your email provider (Google Workspace admin console, Microsoft 365, or your ESP’s dashboard) generates a public/private key pair internally.
- It gives you the DNS TXT record to publish, already formatted with the correct selector.
- You add that record to your DNS.
- The provider signs outgoing mail with the private key, which never leaves their infrastructure.
Standalone DKIM generator tools exist mainly for self-hosted mail servers (e.g. using OpenDKIM), where you’re running your own mail transfer agent and need to generate the key pair yourself with a tool like opendkim-genkey.
Finding your existing DKIM selector
If you’ve lost track of which selector your provider uses:
- Check your provider’s admin console — DKIM setup pages always display the exact selector and record.
- Look at a
DKIM-Signatureheader in an email you’ve already sent. It includes as=tag with the selector:DKIM-Signature: v=1; a=rsa-sha256; d=yourdomain.com; s=google; ... - Guess common selectors and check DNS. Try
google,default,selector1,selector2,k1,s1,mailagainst<selector>._domainkey.yourdomain.com.
Checking a DKIM record
Use the free SPF/DKIM/DMARC checker — enter the domain and the selector, and it validates the record’s syntax and confirms whether a public key is present.
Once your DKIM signing is confirmed working alongside SPF and DMARC, mailbox reputation and warm-up become the next lever for deliverability. MailPilot gradually warms up new mailboxes and tracks deliverability for cold email and sales outreach senders.