How DKIM works
DKIM (DomainKeys Identified Mail) adds a digital signature to every message. The mail server signs the message with a private key, and the public key is published in DNS as a TXT record named selector._domainkey.domain. The receiver verifies the signature and confirms that the message really came from your domain and was not altered in transit.
How to find your selector
Open any message sent from the domain and view its headers (in Gmail — “Show original”). In the DKIM-Signature header the selector is given in the s= parameter and the domain in d=. A domain can have several selectors — for example, separate ones for corporate mail and a newsletter service.
Recommendations
- Use 2048-bit RSA keys — 1024-bit keys are already considered weak.
- Rotate the key every year or two: create a new selector, switch to it and delete the old record.
- DKIM works best together with SPF and DMARC.
On MEVCORE email hosting DKIM signing is configured automatically.