Most people don't know their DKIM selector — we automatically try the most common ones, and you can add your own if you know it.
DKIM verifies email integrity using public-key cryptography. The sender signs outgoing emails with a private key, and recipients verify it against the public key published in DNS.
Selectors allow a single domain to support multiple email providers simultaneously (e.g. google._domainkey for Google Workspace and s1._domainkey for transactional mail).
Check the DKIM-Signature header in any sent email (the s= parameter) or your email delivery provider dashboard.
Common causes include typos in the DNS TXT record, outdated RSA key sizes (<1024 bits), or ongoing DNS propagation.
DKIM is just one piece. SPF, DMARC, headers: check it all free in a minute.