What a DKIM selector is
← All help articles · DKIM
A domain can publish multiple DKIM keys simultaneously (e.g. one per sending platform, or during key rotation), each under its own selector — an arbitrary label chosen by whoever configured signing (common examples: google, selector1, k1). The signature header's s= tag names which one to check, and the receiver looks up <selector>._domainkey.yourdomain.com as a TXT record to get that key.
This tool's DKIM-selector health check merges selectors from config with ones already observed in that domain's actual reports, since there's no way to enumerate every valid selector from DNS alone — see why full coverage can't be guaranteed.
References
- RFC 6376 §3.1