What DKIM does
DKIM (DomainKeys Identified Mail) publishes a public key in DNS at <selector>._domainkey.yourdomain.com. Your mail server signs each message with the matching private key; receivers fetch the public key to verify the signature.
Why selectors matter
DKIM keys live under a selector name chosen by your mail provider — for example google, selector1 or s1. There is no way to enumerate every selector, so Nattvakt probes the most common ones.
A "not detected" result does not always mean DKIM is missing — your provider may use a custom selector. Check the selector name in your mail admin console.
Getting DKIM right
Enable DKIM in your mail provider's admin console, publish the DNS record they give you, and confirm with a test message. Rotate keys periodically and remove retired selectors.
Frequently asked questions
What is a DKIM selector?
A label (such as google or selector1) that identifies which DKIM public key to look up at selector._domainkey.<domain>.
Why does the checker say DKIM is not detected?
It probes common selectors only. If your provider uses a custom selector, DKIM may still be active — check the selector name in your mail admin console.
Does DKIM stop spoofing on its own?
No. DKIM proves a message was not altered and is paired with DMARC to enforce a policy. Use SPF, DKIM and DMARC together.