Short answer: The selector is the s= value in the DKIM-Signature header of a message the domain sent; the public key then lives at <selector>._domainkey.<d= domain>. Without a message, try the platform defaults: default on cPanel, x on DirectAdmin, google on Google Workspace, and selector1/selector2 on Microsoft 365. DNS cannot list selectors, so guessing only works for known defaults.
We ran the DNS, Exim and key checks below on our lab servers (AlmaLinux 9.8 with cPanel & WHM 11.138, and DirectAdmin 1.712, Exim 4.100.1) on 6 October 2026. Microsoft 365 and Google Workspace defaults were checked against their official documentation the same day.
Table of Contents
Find the selector in a message header
Open the full source of a message sent by the domain (Gmail: Show original; Outlook: View message source; Thunderbird: View Source). Find each DKIM-Signature header. Two tags matter:
d=: the signing domain.s=: the selector.
The key is published at s + ._domainkey. + d. For d=example.com; s=default that is default._domainkey.example.com. If you saved the message as a file, this pulls out both tags, including from headers folded over several lines:
grep -i -A5 '^DKIM-Signature:' message.eml | grep -o -E '\b[ds]=[^;[:space:]]+'
A message can carry several signatures, for example one from your newsletter provider (d= their domain) and one for your own domain. For DMARC, the one that matters is the signature whose d= matches, or shares the organizational domain of, the From address. Do not confuse DKIM-Signature with ARC-Message-Signature, which also has an s= tag but belongs to a forwarding hop.
Our Email Header Analyzer lists every signature with its domain, selector and result if you paste the headers.
Default selectors by platform
| Platform | Default selector | DNS record type | Where we checked |
|---|---|---|---|
| cPanel & WHM (Exim) | default | TXT | dkim_selector = default in /etc/exim.conf on our lab |
| DirectAdmin (Exim) | x | TXT | dkim_selector = x in /etc/exim.dkim.conf on our lab |
| Google Workspace | google (you can choose another prefix) | TXT | Google Workspace Admin Help |
| Microsoft 365 (custom domains) | selector1 and selector2 | CNAME to a Microsoft-hosted key | Microsoft Learn |
Microsoft 365 creates two key pairs per custom domain. Only one selector signs at a time; the other is used after the next key rotation. Both CNAMEs must exist. Get the exact targets for your tenant from the Defender portal or with Get-DkimSigningConfig -Identity contoso.com | Format-List Name,Enabled,Status,Selector1CNAME,Selector2CNAME in Exchange Online PowerShell, since Microsoft says the values in its articles are examples only.
Newsletter and transactional services use their own selector names, which change between providers and sometimes per account. Take them from the provider’s DNS setup page or from a real message, not from lists on the web.
Find the selector and key on the server
cPanel
Exim on cPanel signs every domain that has DKIM enabled with selector default. The keys are stored per domain:
grep -n -E "dkim_(selector|private_key)" /etc/exim.conf
ls /var/cpanel/domain_keys/public/ /var/cpanel/domain_keys/private/
On our lab the first command printed dkim_selector = default and dkim_private_key = "/var/cpanel/domain_keys/private/${dkim_domain}". Never copy or paste the private key anywhere; you only need the public one.
DirectAdmin
DirectAdmin keeps the DKIM settings in a separate include file and the keys in each domain’s virtual folder:
grep -E "dkim_(selector|private_key)" /etc/exim.dkim.conf
ls -l /etc/virtual/example.com/dkim.public.key
On our lab: dkim_selector = x, and the private key path is /etc/virtual/$dkim_domain/dkim.private.key. If the key files do not exist, DKIM is not enabled for that domain. DirectAdmin’s /usr/local/directadmin/scripts/dkim_create.sh creates a 2048-bit key pair and queues the DNS update.
Guess common selectors with dig
DNS has no way to list the names under _domainkey, so tools that “find” a selector without a message are trying a list of common names. You can do the same:
for s in default x google selector1 selector2; do
r=$(dig +short TXT "$s._domainkey.example.com" | cut -c1-40)
[ -n "$r" ] && echo "$s: $r..."
done
Against one of our cPanel lab domains this found only default: "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BA.... dig follows CNAMEs, so the Microsoft 365 selectors show the key text too. No result proves nothing: the domain may use a selector that is not on your list. Our DKIM Checker checks a selector you give it.
Check the key behind the selector
A healthy DKIM TXT record has v=DKIM1 (optional but usual), k=rsa (the default), and a non-empty p=. An empty p= means the key has been revoked under RFC 6376. To see the key length:
dig +short TXT default._domainkey.example.com | sed -e 's/" "//g' -e 's/"//g' -e 's/.*p=//' -e 's/;.*//' | tr -d '[:space:]' | base64 -d | openssl pkey -pubin -inform DER -noout -text | head -1
On our cPanel lab this printed Public-Key: (2048 bit). Use the DirectAdmin selector x in place of default where needed. Gmail requires at least 1024 bits for personal Gmail recipients and recommends 2048.
To prove that the published key matches the one Exim signs with on cPanel, compare DNS with the stored public key:
D=example.com
a=$(grep -v -- ----- /var/cpanel/domain_keys/public/$D | tr -d '\n')
b=$(dig +short TXT default._domainkey.$D | sed -e 's/" "//g' -e 's/"//g' -e 's/.*p=//' -e 's/;.*//' | tr -d '[:space:]')
[ "$a" = "$b" ] && echo MATCH || echo DIFFERENT
On our lab this printed MATCH. On DirectAdmin use /etc/virtual/$D/dkim.public.key and selector x. If you use external DNS such as Cloudflare, query it (drop the @ server option) so you compare against what receivers see.
Common problems
- DKIM fails with “no key for signature”. The selector in
s=has no record ats._domainkey.d. Common after moving DNS to Cloudflare or another provider without copying the DKIM record. - DKIM fails with “signature did not verify” or “body hash did not verify”. The key exists but does not match (key regenerated on the server, old key still in DNS), or a gateway changed the message after signing.
- Key split incorrectly. 2048-bit keys are longer than 255 characters and must be stored as several strings in one TXT record. A missing chunk of the key, or a literal quote or backslash pasted into
p=, breaks it. - Two TXT records at the same selector. Remove the stale one.
- Signed with the server hostname. If
d=is the server’s hostname instead of the customer domain, DKIM passes but does not align with the From address, so DMARC still fails.
Official documentation: RFC 6376: DKIM Signatures · Microsoft Learn: set up DKIM for Microsoft 365 · Google Workspace: set up DKIM
Related: DKIM Checker · Email Header Analyzer · SPF, DKIM and DMARC in cPanel DNS: Setup and Checks · Microsoft 365 SPF DKIM DMARC: Secure Exchange Online Setup · MailBaby DKIM transport signing explained: why some mail shows “via mailbaby.net”
See also: Split a 2048-bit DKIM TXT Record Over 255 Characters · DKIM Key Generator: 2048-bit Key Pair and DNS Record · DNS TXT Record Splitter: Split Long Values Into 255-Byte Strings
Frequently asked questions
What is a DKIM selector?
A name chosen by the sender that tells receivers where to find the public key. The key is published at selector._domainkey.domain, so one domain can have several keys at once.
How do I find the DKIM selector for a domain?
Read the s= tag in the DKIM-Signature header of a message the domain sent. Without a message you can only try known defaults such as default, x, google, selector1 and selector2.
What is the cPanel DKIM selector?
default. Exim on cPanel uses dkim_selector = default and reads keys from /var/cpanel/domain_keys/private/.
What is the DirectAdmin DKIM selector?
x. DirectAdmin’s Exim configuration uses dkim_selector = x with the key at /etc/virtual/DOMAIN/dkim.private.key.
What selector does Microsoft 365 use?
selector1 and selector2 for custom domains, published as CNAME records that point to keys Microsoft hosts. Only one is active at a time.
Can I list all DKIM selectors of a domain?
No. DNS does not allow listing the names under _domainkey, so any tool that claims to find all selectors is only guessing common names.