Provider
Mailgun DKIM selectors
A miss is not proof
DKIM selectors cannot be listed through DNS. If none of the selectors below answers on a domain, that does not prove the domain has no DKIM or does not use Mailgun: the selector may be custom, rotated or retired. A signed message shows the real one.
Mailgun has two ways to publish DKIM. With Automatic Sender Security you add two CNAME records, pdk1._domainkey and pdk2._domainkey, that point at hosts Mailgun runs. Mailgun generates 2048-bit keys behind them and rotates them every 120 days by default. With a manual key you choose the selector and publish the key as a TXT record yourself.
Manual keys have no fixed default name. Mailgun asks for a selector that is unique to the sending domain. The API can set it when a domain is created, and PUT /v3/domains/{name}/dkim_selector changes it later; it has to differ from the selectors of the domain’s other keys. The key length is your choice of 1024 or 2048 bits.
A domain can sign with up to three DKIM keys. When more than one is active, Mailgun picks a signing key at random for each message, so messages from one domain can carry different selectors.
The automatic rotation interval can be no shorter than 5 days, and keys can be force-rotated at any time. Mailgun’s rotation article says best practice is to rotate at least every 6 months.
When a CNAME in the chain points under mailgun.com, mailgun.net, mailgun.org or mgsend.org, dkim.fyi names Mailgun as the provider.
- Usual selector
pdk1andpdk2with Automatic Sender Security; otherwise a selector the sender chose- Record type
- TXT or CNAME
- Dataset confidence
- mediumHow sure the dataset is that Mailgun uses these names, not that a key found under one is theirs.
Selectors
| Selector | Source | Status | Note |
|---|---|---|---|
pdk1 | Vendor documentation | current | Automatic Sender Security, CNAME. |
pdk2 | Vendor documentation | current | Automatic Sender Security, CNAME. |
smtp | Observed elsewhere | current | This and the names below come from third-party selector lists only. |
k1 | Observed elsewhere | current | |
pic | Observed elsewhere | current | |
mailo | Observed elsewhere | current | |
mg | Observed elsewhere | current | |
mailgun | Observed elsewhere | current | |
krs | Observed elsewhere | current | |
mta | Observed elsewhere | current |
Record forms
| Name | Type | Value | Note |
|---|---|---|---|
pdk1._domainkey.<domain> | CNAME | pdk1._domainkey.<account-label>.dkim1.mailgun.com | Automatic Sender Security. The documentation’s example label, 9d876, did not resolve on 2026-10-10. |
pdk2._domainkey.<domain> | CNAME | pdk2._domainkey.<account-label>.dkim1.mailgun.com | |
<selector>._domainkey.<domain> | TXT | Not given in the sources | Manual key, 1024 or 2048 bits, at the selector you set. |
Where sources disagree
- Mailgun’s DKIM Security page says Automatic Sender Security “generates two 2048 bit DKIM selector records via TXT records”, but the same page lists
pdk1andpdk2as CNAMEs, and Mailgun’s other pages say the records are CNAMEs delegated back to Mailgun. On your domain they are CNAMEs; the TXT key sits at the end of the chain, on Mailgun’s side. - The selector dataset gives
dkim9.eu.mgsend.orgas the target for EU accounts. The Mailgun pages listed here do not: they show only a dkim1.mailgun.com example, and mention the EU only as a separate API address,api.eu.mailgun.net. On 2026-10-10 apdk1host under an account label in dkim9.eu.mgsend.org answered with a DKIM key, so an EU target there is observed, not documented. - Third-party selector lists name
smtp,k1,picand five other names for Mailgun. The Mailgun pages listed here name onlypdk1andpdk2and otherwise leave the selector to the sender, so none of them is a documented default.
Check it live
What goes wrong
- Keys shown as Unverified
- Mailgun may list several DKIM keys for a domain, some of them Unverified. Only the key the domain’s configuration uses has to be published correctly.
- Switching to Automatic Sender Security
- Until the pdk1 and pdk2 CNAMEs are in place, Mailgun keeps signing with the existing TXT record. Once the CNAMEs verify, active manual keys are deactivated and can no longer be switched on.
- More than one active key
- Any active key can sign the next message, so each one needs a valid record.
- Records not yet visible
- Mailgun says DNS changes can take 24 to 48 hours to propagate fully.