Provider
Google Workspace DKIM selectors
A miss is not proof
DKIM selectors cannot be listed through DNS. If none of the selectors below answers on a domain, that does not prove the domain has no DKIM or does not use Google Workspace: the selector may be custom, rotated or retired. A signed message shows the real one.
Google Workspace publishes its DKIM key as a TXT record. The default prefix selector is google and Google recommends it for Workspace, so the key is usually at google._domainkey.<domain>. If the domain already has a DKIM key under google, the admin enters a different prefix when generating the new key, so the selector is a default rather than a fixed name.
A super administrator generates the key in the Admin console, and each domain needs its own key. The console offers a 2048-bit key for DNS hosts that support it and a 1024-bit key for those that do not. The TXT value starts with v=DKIM1. Once the record is in place and working, the status on the Authenticate email page reads “Authenticating email with DKIM”.
dkim.fyi’s discovery tries google first when the domain’s MX or SPF record points at google.com or googlemail.com. Google notes that sending yourself a test message does not show whether DKIM is on. The dkim.fyi email check gives you a throwaway address and shows every signature on a message sent to it, including the selector in s=.
- Usual selector
google, unless the admin chose another prefix- Record type
- TXT
- Dataset confidence
- highHow sure the dataset is that Google Workspace uses these names, not that a key found under one is theirs.
Selectors
| Selector | Source | Status | Note |
|---|---|---|---|
google | Vendor documentation | current | The default prefix selector, recommended for Google Workspace. |
<prefix> | Vendor documentation | current | Any other prefix the admin enters, for example because google is already taken on the domain. |
20161025 | Observed elsewhere | legacy | Third-party selector lists record it on Google-operated signing domains. Google’s current documentation does not list it. |
Record forms
| Name | Type | Value | Note |
|---|---|---|---|
google._domainkey.<domain> | TXT | Not given in the sources | The key from the Admin console, starting v=DKIM1. Google’s example host name is google._domainkey. |
<prefix>._domainkey.<domain> | TXT | Not given in the sources | The same record under the prefix the admin chose. |
Where sources disagree
- Third-party selector lists attribute
20161025to Google. Neither Google page cited here mentions it, and the dataset lists it for Google-operated signing domains, not for Workspace customer domains.
Check it live
What goes wrong
- Key generated too soon
- After Gmail is turned on for an organisation, the DKIM key is not available in the Admin console for 24 to 72 hours. Trying earlier can give an error that the DKIM record was not created.
- The console still asks for a DNS update
- DKIM can take up to 48 hours to start working after the key is added, and for up to 48 hours the Authenticate email page may keep showing “You must update the DNS records for this domain” even when the record is correct.
- A 2048-bit key that does not fit
- Some DNS hosts limit TXT record length, and a 2048-bit key cannot be entered as a single string where the limit is 255 characters. Google offers the 1024-bit key for hosts that do not support 2048-bit keys.
- No record shown in the console
- If the DNS host name and TXT record values in the Admin console are blank, the domain has no DKIM record yet.
- More than five signatures
- Gmail checks only the first five signatures listed in the
Authentication-Resultsheader.