Provider

Mailgun DKIM selectors

A miss is not proof

DKIM selectors cannot be listed through DNS. If none of the selectors below answers on a domain, that does not prove the domain has no DKIM or does not use Mailgun: the selector may be custom, rotated or retired. A signed message shows the real one.

Mailgun has two ways to publish DKIM. With Automatic Sender Security you add two CNAME records, pdk1._domainkey and pdk2._domainkey, that point at hosts Mailgun runs. Mailgun generates 2048-bit keys behind them and rotates them every 120 days by default. With a manual key you choose the selector and publish the key as a TXT record yourself.

Manual keys have no fixed default name. Mailgun asks for a selector that is unique to the sending domain. The API can set it when a domain is created, and PUT /v3/domains/{name}/dkim_selector changes it later; it has to differ from the selectors of the domain’s other keys. The key length is your choice of 1024 or 2048 bits.

A domain can sign with up to three DKIM keys. When more than one is active, Mailgun picks a signing key at random for each message, so messages from one domain can carry different selectors.

The automatic rotation interval can be no shorter than 5 days, and keys can be force-rotated at any time. Mailgun’s rotation article says best practice is to rotate at least every 6 months.

When a CNAME in the chain points under mailgun.com, mailgun.net, mailgun.org or mgsend.org, dkim.fyi names Mailgun as the provider.

Usual selector
pdk1 and pdk2 with Automatic Sender Security; otherwise a selector the sender chose
Record type
TXT or CNAME
Dataset confidence
mediumHow sure the dataset is that Mailgun uses these names, not that a key found under one is theirs.

Selectors

Mailgun selectors by source and status
SelectorSourceStatusNote
pdk1Vendor documentationcurrentAutomatic Sender Security, CNAME.
pdk2Vendor documentationcurrentAutomatic Sender Security, CNAME.
smtpObserved elsewherecurrentThis and the names below come from third-party selector lists only.
k1Observed elsewherecurrent
picObserved elsewherecurrent
mailoObserved elsewherecurrent
mgObserved elsewherecurrent
mailgunObserved elsewherecurrent
krsObserved elsewherecurrent
mtaObserved elsewherecurrent

Record forms

Mailgun DNS record forms
NameTypeValueNote
pdk1._domainkey.<domain>CNAMEpdk1._domainkey.<account-label>.dkim1.mailgun.comAutomatic Sender Security. The documentation’s example label, 9d876, did not resolve on 2026-10-10.
pdk2._domainkey.<domain>CNAMEpdk2._domainkey.<account-label>.dkim1.mailgun.com
<selector>._domainkey.<domain>TXTNot given in the sourcesManual key, 1024 or 2048 bits, at the selector you set.

Where sources disagree

  • Mailgun’s DKIM Security page says Automatic Sender Security “generates two 2048 bit DKIM selector records via TXT records”, but the same page lists pdk1 and pdk2 as CNAMEs, and Mailgun’s other pages say the records are CNAMEs delegated back to Mailgun. On your domain they are CNAMEs; the TXT key sits at the end of the chain, on Mailgun’s side.
  • The selector dataset gives dkim9.eu.mgsend.org as the target for EU accounts. The Mailgun pages listed here do not: they show only a dkim1.mailgun.com example, and mention the EU only as a separate API address, api.eu.mailgun.net. On 2026-10-10 a pdk1 host under an account label in dkim9.eu.mgsend.org answered with a DKIM key, so an EU target there is observed, not documented.
  • Third-party selector lists name smtp, k1, pic and five other names for Mailgun. The Mailgun pages listed here name only pdk1 and pdk2 and otherwise leave the selector to the sender, so none of them is a documented default.

Check it live

What goes wrong

Keys shown as Unverified
Mailgun may list several DKIM keys for a domain, some of them Unverified. Only the key the domain’s configuration uses has to be published correctly.
Switching to Automatic Sender Security
Until the pdk1 and pdk2 CNAMEs are in place, Mailgun keeps signing with the existing TXT record. Once the CNAMEs verify, active manual keys are deactivated and can no longer be switched on.
More than one active key
Any active key can sign the next message, so each one needs a valid record.
Records not yet visible
Mailgun says DNS changes can take 24 to 48 hours to propagate fully.

Sources

  1. DKIM Security
  2. How can I rotate my DKIM key?
  3. Update a DKIM selector
  4. Create a domain
  5. Domain Verification
  6. DKIM Automatic Sender Security