Provider

Amazon SES DKIM selectors

A miss is not proof

DKIM selectors cannot be listed through DNS. If none of the selectors below answers on a domain, that does not prove the domain has no DKIM or does not use Amazon SES: the selector may be custom, rotated or retired. A signed message shows the real one.

Amazon SES has two DKIM methods. With Easy DKIM, SES generates three tokens per identity and you publish three CNAME records named after them. With Bring Your Own DKIM (BYODKIM), you publish one TXT record under a selector you choose.

Neither method has a fixed selector name, so a list of common selectors cannot find them reliably. Read them from the Publish DNS records table in the SES console, from the Tokens that GetEmailIdentity returns, or from the s= tag of a signed message. A BYODKIM identity shows SigningAttributesOrigin as EXTERNAL.

Each Easy DKIM CNAME points at the token followed by the identity’s signing hosted zone. AWS gives token.dkim.us-west-2.amazonses.com as an example and says the zone varies by AWS Region and can differ between identities, so build the value from SigningHostedZone. dkim.fyi attributes a CNAME to Amazon SES when its target ends in amazonses.com, which covers Region-qualified zones like that one.

The records differ for each Region, and each Region needs its own identity and verification. With Deterministic Easy DKIM (DEED), replica identities in other Regions use the parent identity’s DNS records; the parent must use Easy DKIM, and BYODKIM identities cannot be replicated.

Easy DKIM uses a 2048-bit key unless 1024 is requested. A BYODKIM key must be 1024 to 2048 bits, and you can rotate it as often as you like. The key length cannot change more than once in 24 hours, except for a first downgrade to 1024.

Usual selector
Three generated tokens (Easy DKIM), or a selector you choose (BYODKIM)
Record type
TXT or CNAME
Dataset confidence
highHow sure the dataset is that Amazon SES uses these names, not that a key found under one is theirs.

Selectors

Amazon SES selectors by source and status
SelectorSourceStatusNote
<token>Vendor documentationcurrentEasy DKIM. Three per identity, generated by SES.
<selector>Vendor documentationcurrentBYODKIM. A unique name that identifies the key; no default. It is also entered in the identity (DomainSigningSelector).
sesObserved elsewherecurrentThird-party selector lists give it for BYODKIM. No AWS page cited here names it.
amazonsesObserved elsewherecurrentAlso from third-party selector lists only.

Record forms

Amazon SES DNS record forms
NameTypeValueNote
<token>._domainkey.<domain>CNAME<token>.<SigningHostedZone>Easy DKIM, three records. In the AWS example the zone is dkim.us-west-2.amazonses.com; it varies by Region and identity.
<selector>._domainkey.<domain>TXTNot given in the sourcesBYODKIM, one record holding your public key.

Where sources disagree

  • The DkimAttributes API reference illustrates SigningHostedZone with selector1._domainkey.yourdomain.com CNAME selector1.<SigningHostedZone>, up to selector3. The console guide says the names are generated tokens, so these are placeholders, not SES selectors.
  • Third-party selector lists give ses and amazonses for BYODKIM; the AWS guide names no default.

Check it live

What goes wrong

Domain appended twice
AWS says to check that the DNS provider did not append the domain to the Name value you entered.
An underscore before the token
The record name starts with the token itself. AWS lists _abc123._domainkey.domain.com as an incorrect name.
A hosted zone copied from somewhere else
A value from another identity or Region can name the wrong zone. Use that identity’s own Tokens and SigningHostedZone.
Status FAILED
SES looks for the records for up to 72 hours; FAILED usually means it did not find them. Easy DKIM needs three unique CNAME records.
Unsigned mail while switching methods
Moving between Easy DKIM and BYODKIM can mean SES sends mail without a DKIM signature while the new status is pending.

Sources

  1. Authenticating Email with DKIM in Amazon SES
  2. Easy DKIM in Amazon SES
  3. Provide your own DKIM authentication token (BYODKIM) in Amazon SES
  4. Creating and verifying identities in Amazon SES
  5. Managing Easy DKIM and BYODKIM
  6. Using Deterministic Easy DKIM (DEED) in Amazon SES
  7. DkimAttributes - Amazon Simple Email Service