Glossary · Authentication

DKIM selector

A DKIM selector is the label that tells receivers which of a domain's DKIM keys signed a message, found at selector._domainkey.domain.

Every DKIM signature carries s= (the selector) and d= (the domain). The receiver fetches the public key from selector._domainkey.domain. Selectors let one domain hold several keys at once: one per sending service, and a new one during key rotation.

Providers have their own conventions, such as google for Google Workspace and selector1/selector2 for Microsoft 365. Because DNS can't list every name under a domain, there's no way to discover all of a domain's selectors from outside; tools can only probe the well-known ones.

Business email that lands in the inbox.

Every domain you run in one inbox, from $3 a mailbox. 14 days free, no card.