Blog

Email Deliverability articles

How to Find Your DKIM Selector

Four reliable ways to find your DKIM selector: message headers, provider settings, DMARC reports and known defaults, plus how to verify the record exists.

4 min read Email Deliverability

Many email tools ask for a DKIM selector before they can check your DKIM record, and most people have no idea what theirs is. That is understandable, because you rarely type it yourself; your email provider picks it. The good news is that it is easy to find once you know where to look, and there is one place where it is always written down: in the headers of every message you send.

What a DKIM selector is

DKIM signs outgoing mail with a private key, and receivers verify the signature using a public key published in DNS. Because a domain may use several keys at once, one for each sending service, or an old and a new key during rotation, each key is given a name. That name is the selector. The public key lives at:

<selector>._domainkey.<domain>

So a selector of google on example.com means the key is published at google._domainkey.example.com. Without the selector, nobody, including a checking tool, knows which name to look up.

One important point: there is no DNS query that lists all the selectors a domain uses. DNS does not offer that kind of enumeration. You have to find each selector from the sending side.

When you need to know your selector

You will typically be asked for it when testing DKIM with an online checker, when a deliverability consultant or IT provider reviews your setup, when moving DNS to a new provider (so you can confirm every DKIM record came across), and when retiring an old email service (so you can remove the right record and nothing else). Knowing which selector belongs to which service also makes key rotation much less nerve-racking.

Method 1: Read it from an email's headers (most reliable)

Send a message from the account or service you want to check to any external mailbox, then view the full headers:

  • Gmail: open the message, click the three-dot menu, choose "Show original".
  • Outlook on the web: open the message, use the "..." menu, then View, then "View message source" (or "View message details").
  • Apple Mail: View, Message, All Headers or Raw Source.
  • Thunderbird: View, Message Source.

Find the line beginning DKIM-Signature:. It looks like this:

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=example.com; s=google;
        h=from:to:subject:date:message-id:mime-version;
        bh=47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=;
        b=Wk3Fz...

The value after s= is the selector, and the value after d= is the signing domain. Here, the selector is google and the domain is example.com.

Check the d= value too

If d= shows your provider's domain rather than yours, the service is signing with its own key, not a key for your domain. That message has DKIM, but not DKIM that helps your domain's DMARC alignment. You will need to set up custom-domain DKIM in that service.

Some messages carry more than one DKIM-Signature header, for example one for your domain and one for the platform's. Look for the one whose d= matches your domain.

Method 2: Look in the provider's admin settings

Every service that supports custom DKIM shows the record it wants you to publish, and the host name contains the selector.

ServiceWhere to lookTypical selector(s)
Google WorkspaceAdmin console, Gmail, Authenticate emailgoogle by default (you can choose another prefix)
Microsoft 365Defender portal, Email authentication settings, DKIMselector1 and selector2
MailchimpDomain authentication settingsk1
SendGridSender authentication, domain authentications1 and s2
Amazon SESVerified identities, DKIM sectionThree generated random strings

Providers do change their defaults over time, and many let you customise them, so treat this table as a hint and confirm in your own account.

Method 3: Check your DNS zone

If you have access to the DNS control panel, look for TXT or CNAME records whose names contain ._domainkey. The part before ._domainkey is the selector. You may find several, including some for services you no longer use, which is a good prompt to tidy up.

Method 4: Use your DMARC reports

If you receive DMARC aggregate reports, the auth_results section of each record often includes the DKIM selector used, alongside the domain and result:

<dkim>
  <domain>example.com</domain>
  <selector>s1</selector>
  <result>pass</result>
</dkim>

This is a convenient way to discover selectors used by services you did not know were sending as your domain.

Verify the selector's record

Once you know the selector, check that the public key is published and valid:

dig google._domainkey.example.com TXT +short
nslookup -type=TXT google._domainkey.example.com

Or enter the domain and selector in our SPF, DKIM and DMARC checker. You should see a value beginning v=DKIM1 with a long p= key. If the selector is a CNAME, the lookup follows it to the provider's hosted key; the DNS lookup tool shows each step.

An empty p= value (p=;) means the key has been deliberately revoked. A missing record means either the selector is wrong or the record was never published.

Key takeaways

  • The DKIM selector is the label that tells receivers where to find the public key: selector._domainkey.domain.
  • The fastest way to find it is the s= tag in a sent message's DKIM-Signature header.
  • Check d= as well: it should be your domain, not the provider's.
  • DNS cannot list all selectors, so gather them from each sending service, your zone and DMARC reports.

Need help with this?

Netifi helps businesses around the world with Email Deliverability. Tell us what you are working on.