← All installation guides Email authentication and DNS

Find your DKIM selector

Find the exact selector used to sign your email and enter it correctly in an Email Sender Verification application.

s=
Recommended methodEmail DNS and seal setup
Email authentication setup

Configure email DNS and find the selector

  1. 1

    Check your email-provider settings

    Open the DKIM or email-authentication page at the service that sends your mail. Look for Selector, Prefix, Host, Record name or a value ending in ._domainkey. The selector is the part immediately before ._domainkey.

  2. 2

    Confirm it from a real message

    Send a new message from the sender address to an external mailbox. Open the full or original message headers and find the DKIM-Signature whose d= value matches your sender domain. Its s= value is the active selector.

  3. 3

    Choose the correct signature

    A message can contain several DKIM-Signature lines. Ignore signatures added by forwarding, marketing or security services unless their d= domain is the domain being verified.

  4. 4

    Enter only the selector

    If the record is google._domainkey.example.com, enter google. Do not enter the domain, ._domainkey, quotation marks or the public key. If an earlier value was wrong, open the customer order or issued seal, choose Change DKIM selector, then save it to restart the email DNS check.

Open Google Workspace DKIM and selector guidance ↗
Email Sender Verification Seal

Complete authentication before installing the seal

The sender domain must continue to publish a valid SPF record, the selected DKIM key and a DMARC policy. VerifySeal automatically rechecks these records according to the administrator schedule. For High Security messages, DKIM must cover the final Message-ID, VEM header and completed body.

  • SPF authorizes sending services
  • DKIM verifies the signed message domain
  • DMARC publishes the domain policy
Testing checklist

Confirm the installation is working

01

SPF

The sender domain has one valid SPF record containing every authorized sending service.

02

DKIM

A new external message reports DKIM pass and its matching signature contains the selector entered in VerifySeal.

03

DMARC

A DMARC record is published at _dmarc and its policy matches the organization’s approved rollout.

04

VerifySeal

The customer order reports SPF, DKIM and DMARC as verified before the Email Sender Seal is issued.

Platform notes
  • Selectors are case-sensitive in a message header. Copy the s= value exactly as shown.
  • Services can rotate between selectors. Use the selector on a newly sent message and keep every provider-required DKIM record published.