Provider
SendGrid DKIM selectors
A miss is not proof
DKIM selectors cannot be listed through DNS. If none of the selectors below answers on a domain, that does not prove the domain has no DKIM or does not use SendGrid: the selector may be custom, rotated or retired. A signed message shows the real one.
Twilio SendGrid uses two selectors by default, s1 and s2. Twilio says it uses them interchangeably, rotates them when necessary and activates only one of them for signing at any given time.
The records you publish depend on automated security, which SendGrid turns on by default. With it on, SendGrid generates three CNAME records; the two DKIM ones point s1._domainkey and s2._domainkey at hosts under sendgrid.net, and SendGrid manages the keys and their rotation. With it off, SendGrid generates three records, two of them TXT, and the DKIM key sits in a TXT record on your domain.
A custom selector replaces s1 and s2. SendGrid offers it for authenticating one domain more than once, for example on a second account or subuser, without the records conflicting. The option is under Advanced Settings when you first set up Domain Authentication, and the setup page gives org and 001 as examples.
A domain used by both global and EU subusers has to be authenticated separately in each region. The pages under Sources give no separate DKIM target for EU-pinned domains.
When a CNAME in the chain points under sendgrid.net, dkim.fyi names SendGrid as the provider, whatever the selector is called.
- Usual selector
s1ands2, unless a custom selector was set- Record type
- CNAME
- Dataset confidence
- highHow sure the dataset is that SendGrid uses these names, not that a key found under one is theirs.
Selectors
| Selector | Source | Status | Note |
|---|---|---|---|
s1 | Vendor documentation | current | Default. With automated security, a CNAME to s1.domainkey.u<account>.wl<n>.sendgrid.net. |
s2 | Vendor documentation | current | Default, the other half of the pair. |
m1 | Vendor documentation | legacy | In the dataset’s legacy record. SendGrid’s DKIM page still uses it in its TXT example for automated security off. |
smtpapi | Observed elsewhere | legacy | Not in SendGrid’s current documentation. On 2026-10-10 it answered with a TXT key on sendgrid.net. |
sg | Observed elsewhere | legacy | Not in SendGrid’s current documentation; third-party selector lists only. |
Record forms
| Name | Type | Value | Note |
|---|---|---|---|
s1._domainkey.<domain> | CNAME | s1.domainkey.u<account-id>.wl<n>.sendgrid.net | Automated security on (the default). |
s2._domainkey.<domain> | CNAME | s2.domainkey.u<account-id>.wl<n>.sendgrid.net | |
<selector>._domainkey.<domain> | TXT | k=rsa; t=s; p=<public key> | Automated security off. SendGrid’s example uses the selector m1. |
Where sources disagree
- SendGrid’s pages disagree on the length of a custom selector. The API reference says it “accepts three letters or numbers” and the setup page asks for three; the support article says “any combination of one to three letters or numbers”. A three-character selector matches both.
- The selector dataset keeps
m1in its legacy record. SendGrid’s DKIM page still uses it, printed asm1._example.com, and does not call it legacy. On 2026-10-10,m1._domainkey.sendgrid.netdid not exist.
Check it live
What goes wrong
- The DNS host rejects underscores
- SendGrid requires underscores in the record names. If your DNS provider does not accept underscores in CNAME records, automated security cannot be used.
- The domain is added twice
- Some DNS hosts add your domain to the end of every record you create. The record has to answer at
s1._domainkey.<domain>, not at a name with the domain twice. - A split TXT record
- With automated security off, a TXT record that has been split up fails with “Error validating domain: Expected TXT record at”.
- An empty answer
- An empty ANSWER section from dig means the record does not exist or has not propagated yet. SendGrid says verification can take up to 48 hours after the records are added.
- A subdomain sends
- Subdomains do not inherit authentication from their parent domain.
- One domain, two accounts
- Two accounts or subusers authenticating the same domain would both use
s1ands2. A custom selector on one of them avoids the conflict.