Guide · DKIM
DKIM (DomainKeys Identified Mail) adds a digital signature to every email. Recipients verify it with a public key from your DNS and can tell whether the message really comes from you and was not altered on the way. Mailsecurity24 finds your DKIM keys automatically, checks them daily and shows in your DMARC reports which senders sign correctly with your domain.
Your mail server or mail service signs outgoing messages with a private key. The header states which domain signed (d=) and under which selector (s=) the matching public key is published – for example at selector1._domainkey.your-company.com. The recipient fetches this key and verifies the signature. For DMARC, the signing domain must also match your visible sender address.
Good to know: Many services sign with their own domain by default. That passes DKIM but does not count for DMARC – enable signing with your own domain in the service.
In Microsoft 365, Google Workspace, your mail server or newsletter service, enable DKIM for your domain. The service gives you the selector and key or the records you need.
Create the TXT or CNAME record at selector._domainkey.your-company.com. Some services use two records for key rotation.
Test with the domain check and watch in Mailsecurity24 whether messages from this service pass DKIM with your domain.
DKIM problems often only show up when the DMARC policy gets stricter and emails are suddenly rejected. Mailsecurity24 shows them beforehand:
Good to know: Unlike SPF, DKIM usually survives forwarding intact – which makes it especially important on the safe path to p=reject.
Free domain check
In seconds we check DMARC, SPF, DKIM, MX, MTA-STS, TLS reporting and BIMI for your domain – free and without signing up.
In the source of a sent email, it appears in the DKIM-Signature header after s=. Many services also name it in their documentation. Mailsecurity24 picks up selectors automatically from your DMARC reports and checks common selectors of major providers.
Yes. Each service uses its own selector, and one service can also have several keys in parallel – that is common during key rotation.
Usually the selector is unknown or the record sits under the wrong name. Check the exact name selector._domainkey.your-company.com and store your own selectors per domain in Mailsecurity24.
Many recommendations suggest every six to twelve months. Large services such as Microsoft 365 and Google Workspace provide their own rotation features with two selectors.
Try Mailsecurity24 free for 14 days. No payment details required.
