Blog
What is DKIM?
Reviewed by the Free Domain Mail editorial team · Updated
DKIM uses a DNS-published public key to let receiving systems verify that a message was signed by an authorised sender.
Selectors are normal
DKIM signs outgoing messages. Your mail provider gives a selector and a DNS record, normally a CNAME or TXT record.
A passing DKIM record is useful only if the provider actually signs each message it sends.
How to check it
Copy the selector exactly as supplied by your provider. A name like selector1._domainkey.example.com uses selector1 as the selector.
After publishing DNS, send a test message and inspect authentication headers to confirm the signature passes.
Common mistakes to avoid
- Putting the full domain in the Name field when the DNS provider appends it automatically.
- Checking a selector that does not match the sending provider.
- Assuming the DNS record alone proves messages are being signed.
Frequently asked questions
Why are there three DKIM CNAME records?
Some providers, including SES, create multiple selectors to rotate keys safely.
Can I remove an old selector?
Only after confirming no active provider still signs with it.
Technical references
Primary specifications and provider documentation relevant to this guide: