MailAuthWatch

DKIM selector names by provider

A DKIM public key is published at selector._domainkey.yourdomain.com. Each sending service picks its own selector. To check or monitor DKIM you need to know it. This list covers the defaults; several providers let you choose a custom selector during setup, in which case use the one you chose.

ProviderDefault selector(s)Record type
Google WorkspacegoogleTXT, 2048-bit recommended
Microsoft 365 / Exchange Onlineselector1, selector2CNAME to selector1-yourdomain-com._domainkey.yourtenant.onmicrosoft.com
Mailchimpk1, k2, k3CNAME to dkim.mcsv.net
SendGrids1, s2 (also smtpapi, em)CNAME
HubSpoths1, hs2CNAME
Zendeskzendesk1, zendesk2CNAME
Mandrill / Mailchimp Transactionalmandrill (also mte1, mte2)TXT / CNAME
Postmarkpm or a numeric selector like 20240101pmTXT
Amazon SESThree random selectors (Easy DKIM) or ses/custom (BYODKIM)CNAME
Mailgunmailo, k1, smtpTXT
Zoho Mailzmail or numericTXT
Proton Mailprotonmail, protonmail2, protonmail3CNAME
Fastmailfm1, fm2, fm3CNAME
Klaviyokl, kl2CNAME
Brevo (Sendinblue)mailTXT
Mimecastmimecast20190301 or customTXT

Find the selector for a specific message by opening its headers and reading the s= tag in the DKIM-Signature line.

Check a selector now

Run a check and add ?selectors=name1,name2 to the report URL, or add selectors to a monitored domain so they are verified every day and you are alerted when one disappears.

← All guides and tools