Provider
Amazon SES DKIM selectors
A miss is not proof
DKIM selectors cannot be listed through DNS. If none of the selectors below answers on a domain, that does not prove the domain has no DKIM or does not use Amazon SES: the selector may be custom, rotated or retired. A signed message shows the real one.
Amazon SES has two DKIM methods. With Easy DKIM, SES generates three tokens per identity and you publish three CNAME records named after them. With Bring Your Own DKIM (BYODKIM), you publish one TXT record under a selector you choose.
Neither method has a fixed selector name, so a list of common selectors cannot find them reliably. Read them from the Publish DNS records table in the SES console, from the Tokens that GetEmailIdentity returns, or from the s= tag of a signed message. A BYODKIM identity shows SigningAttributesOrigin as EXTERNAL.
Each Easy DKIM CNAME points at the token followed by the identity’s signing hosted zone. AWS gives token.dkim.us-west-2.amazonses.com as an example and says the zone varies by AWS Region and can differ between identities, so build the value from SigningHostedZone. dkim.fyi attributes a CNAME to Amazon SES when its target ends in amazonses.com, which covers Region-qualified zones like that one.
The records differ for each Region, and each Region needs its own identity and verification. With Deterministic Easy DKIM (DEED), replica identities in other Regions use the parent identity’s DNS records; the parent must use Easy DKIM, and BYODKIM identities cannot be replicated.
Easy DKIM uses a 2048-bit key unless 1024 is requested. A BYODKIM key must be 1024 to 2048 bits, and you can rotate it as often as you like. The key length cannot change more than once in 24 hours, except for a first downgrade to 1024.
- Usual selector
- Three generated tokens (Easy DKIM), or a selector you choose (BYODKIM)
- Record type
- TXT or CNAME
- Dataset confidence
- highHow sure the dataset is that Amazon SES uses these names, not that a key found under one is theirs.
Selectors
| Selector | Source | Status | Note |
|---|---|---|---|
<token> | Vendor documentation | current | Easy DKIM. Three per identity, generated by SES. |
<selector> | Vendor documentation | current | BYODKIM. A unique name that identifies the key; no default. It is also entered in the identity (DomainSigningSelector). |
ses | Observed elsewhere | current | Third-party selector lists give it for BYODKIM. No AWS page cited here names it. |
amazonses | Observed elsewhere | current | Also from third-party selector lists only. |
Record forms
| Name | Type | Value | Note |
|---|---|---|---|
<token>._domainkey.<domain> | CNAME | <token>.<SigningHostedZone> | Easy DKIM, three records. In the AWS example the zone is dkim.us-west-2.amazonses.com; it varies by Region and identity. |
<selector>._domainkey.<domain> | TXT | Not given in the sources | BYODKIM, one record holding your public key. |
Where sources disagree
- The DkimAttributes API reference illustrates
SigningHostedZonewithselector1._domainkey.yourdomain.comCNAMEselector1.<SigningHostedZone>, up to selector3. The console guide says the names are generated tokens, so these are placeholders, not SES selectors. - Third-party selector lists give
sesandamazonsesfor BYODKIM; the AWS guide names no default.
Check it live
What goes wrong
- Domain appended twice
- AWS says to check that the DNS provider did not append the domain to the Name value you entered.
- An underscore before the token
- The record name starts with the token itself. AWS lists
_abc123._domainkey.domain.comas an incorrect name. - A hosted zone copied from somewhere else
- A value from another identity or Region can name the wrong zone. Use that identity’s own
TokensandSigningHostedZone. - Status FAILED
- SES looks for the records for up to 72 hours;
FAILEDusually means it did not find them. Easy DKIM needs three unique CNAME records. - Unsigned mail while switching methods
- Moving between Easy DKIM and BYODKIM can mean SES sends mail without a DKIM signature while the new status is pending.
Sources
- Authenticating Email with DKIM in Amazon SES
- Easy DKIM in Amazon SES
- Provide your own DKIM authentication token (BYODKIM) in Amazon SES
- Creating and verifying identities in Amazon SES
- Managing Easy DKIM and BYODKIM
- Using Deterministic Easy DKIM (DEED) in Amazon SES
- DkimAttributes - Amazon Simple Email Service