Provider

SendGrid DKIM selectors

A miss is not proof

DKIM selectors cannot be listed through DNS. If none of the selectors below answers on a domain, that does not prove the domain has no DKIM or does not use SendGrid: the selector may be custom, rotated or retired. A signed message shows the real one.

Twilio SendGrid uses two selectors by default, s1 and s2. Twilio says it uses them interchangeably, rotates them when necessary and activates only one of them for signing at any given time.

The records you publish depend on automated security, which SendGrid turns on by default. With it on, SendGrid generates three CNAME records; the two DKIM ones point s1._domainkey and s2._domainkey at hosts under sendgrid.net, and SendGrid manages the keys and their rotation. With it off, SendGrid generates three records, two of them TXT, and the DKIM key sits in a TXT record on your domain.

A custom selector replaces s1 and s2. SendGrid offers it for authenticating one domain more than once, for example on a second account or subuser, without the records conflicting. The option is under Advanced Settings when you first set up Domain Authentication, and the setup page gives org and 001 as examples.

A domain used by both global and EU subusers has to be authenticated separately in each region. The pages under Sources give no separate DKIM target for EU-pinned domains.

When a CNAME in the chain points under sendgrid.net, dkim.fyi names SendGrid as the provider, whatever the selector is called.

Usual selector
s1 and s2, unless a custom selector was set
Record type
CNAME
Dataset confidence
highHow sure the dataset is that SendGrid uses these names, not that a key found under one is theirs.

Selectors

SendGrid selectors by source and status
SelectorSourceStatusNote
s1Vendor documentationcurrentDefault. With automated security, a CNAME to s1.domainkey.u<account>.wl<n>.sendgrid.net.
s2Vendor documentationcurrentDefault, the other half of the pair.
m1Vendor documentationlegacyIn the dataset’s legacy record. SendGrid’s DKIM page still uses it in its TXT example for automated security off.
smtpapiObserved elsewherelegacyNot in SendGrid’s current documentation. On 2026-10-10 it answered with a TXT key on sendgrid.net.
sgObserved elsewherelegacyNot in SendGrid’s current documentation; third-party selector lists only.

Record forms

SendGrid DNS record forms
NameTypeValueNote
s1._domainkey.<domain>CNAMEs1.domainkey.u<account-id>.wl<n>.sendgrid.netAutomated security on (the default).
s2._domainkey.<domain>CNAMEs2.domainkey.u<account-id>.wl<n>.sendgrid.net
<selector>._domainkey.<domain>TXTk=rsa; t=s; p=<public key>Automated security off. SendGrid’s example uses the selector m1.

Where sources disagree

  • SendGrid’s pages disagree on the length of a custom selector. The API reference says it “accepts three letters or numbers” and the setup page asks for three; the support article says “any combination of one to three letters or numbers”. A three-character selector matches both.
  • The selector dataset keeps m1 in its legacy record. SendGrid’s DKIM page still uses it, printed as m1._example.com, and does not call it legacy. On 2026-10-10, m1._domainkey.sendgrid.net did not exist.

Check it live

What goes wrong

The DNS host rejects underscores
SendGrid requires underscores in the record names. If your DNS provider does not accept underscores in CNAME records, automated security cannot be used.
The domain is added twice
Some DNS hosts add your domain to the end of every record you create. The record has to answer at s1._domainkey.<domain>, not at a name with the domain twice.
A split TXT record
With automated security off, a TXT record that has been split up fails with “Error validating domain: Expected TXT record at”.
An empty answer
An empty ANSWER section from dig means the record does not exist or has not propagated yet. SendGrid says verification can take up to 48 hours after the records are added.
A subdomain sends
Subdomains do not inherit authentication from their parent domain.
One domain, two accounts
Two accounts or subusers authenticating the same domain would both use s1 and s2. A custom selector on one of them avoids the conflict.

Sources

  1. Verify message integrity with DKIM
  2. Configure domain authentication
  3. Authenticate a domain
  4. Troubleshooting Sender Authentication
  5. Use a Custom DKIM Selector for Authentication
  6. FAQ on Data Residency for EU