What Discover checks
Every selector below comes from public provider documentation or observed signing behaviour. It is a wordlist, not a registry: providers add, rotate and retire selectors.
| Company | Selectors | Mode | Confidence | Status | Sources |
|---|---|---|---|---|---|
| AcousticAcoustic Campaign · Silverpop · IBM Watson Campaign |
| current and legacy | medium | current or observed | |
| ActiveCampaignActiveCampaign Marketing Automation · Campaign Email |
| current and observed | medium | current or observed | |
| AdobeAdobe Campaign |
| observed common | medium | current or observed | |
| AdobeMarketo Engage |
customer-specific/custom selector | custom with common candidates | medium | current or observed | |
| Amazon Web ServicesAmazon SES Bring Your Own DKIM (BYODKIM) |
customer-supplied selector Officially the customer supplies the selector; listed values are common probe candidates, not guaranteed defaults. | custom with common candidates | medium | current or observed | |
| Amazon Web ServicesAmazon Simple Email Service (SES) Easy DKIM | three AWS-generated opaque DKIM tokens per identity Do not brute-force: obtain the tokens from SES/API or a DKIM-Signature header. | generated unguessable | high | current or observed | |
| AppleiCloud provider-operated mail |
| provider domain observed | medium | current or observed | |
| AppleiCloud+ Custom Email Domain |
Apple supplies a domain-specific CNAME target. | fixed default | high | current or observed | |
| ArubaAruba.it Mail |
| fixed or common | medium | current or observed | |
| AtlassianJira Cloud · Confluence Cloud custom sender domains |
two tenant-specific DKIM CNAME records supplied during setup Atlassian documents two CNAME records for rotation but exact labels may be tenant-specific. | tenant specific with probe candidates | medium | current or observed | |
| AtlassianStatuspage custom sender domains | multiple provider-specific records shown in Statuspage DNS configuration Statuspage can use multiple delivery partners; copy selectors from its DNS configuration page. | tenant and transport specific | high | current or observed | |
| AutomatticWordPress.com · Jetpack Email |
| observed common | medium | current or observed | |
| AWeberAWeber email marketing |
| fixed rotation set | medium | current or observed | |
| Barracuda NetworksBarracuda Email Protection · Email Gateway Defense |
administrator-defined selector possible | custom with common candidates | medium | current or observed | |
| Benchmark EmailBenchmark Email |
CNAME to bmdeda._domainkey.bmsend.com, the same target on every account seen. Benchmark's help centre says to copy the records from the Domain Authentication page of the account. | fixed default | medium | current or observed | |
| BrazeBraze customer engagement · Braze Email |
customer/account-specific selectors possible | observed common | medium | current or observed | |
| BrevoBrevo Marketing Platform · Brevo SMTP · Sendinblue |
account-generated DKIM 1 and DKIM 2 selector names Older accounts may show one TXT DKIM record; newer setups show two CNAME records, brevo1 and brevo2, pointing to b1/b2.<domain>.dkim.brevo.com. Copy exact names from Brevo. | generation dependent | medium | current or observed | |
| Campaign MonitorCampaign Monitor email marketing · CreateSend |
| current and observed | medium | current or observed | |
| CampaignerCampaigner |
CNAME to dkim.emailcampaigns.net. em is also listed for SMTP2GO. | fixed default | medium | current or observed | |
| CloudflareCloudflare Email Routing · Cloudflare Email Sending |
Email Routing publishes cf2024-1 and Email Sending publishes cf-bounce, both in the customer's own zone. The cf2024-1 public key was identical on the zones checked. | fixed default | high | current or observed | |
| Constant ContactConstant Contact email marketing |
customer-specific numeric selector Both modern fixed-looking and older per-customer numeric selectors are observed. | generation dependent | medium | current or observed | |
| ContactlabContactlab email marketing |
| common default | medium | current or observed | |
| CordialCordial marketing platform | customer-specific selector; scph####a-like values observed | generated customer specific | medium | current or observed | |
| Customer.ioCustomer.io Journeys · Customer.io Email |
| observed common | medium | current or observed | |
| DotdigitalDotdigital customer engagement · Dotmailer |
| historic or common | medium | current or observed | |
| DreamHostDreamHost email |
DreamHost publishes dreamhost._domainkey for domains whose DNS and mail it hosts. dh is only seen on dreamhost.com itself. | fixed default | medium | current or observed | |
| DripDrip ecommerce marketing email |
| observed common | medium | current or observed | |
| Elastic EmailElastic Email API · Elastic Email Marketing |
| observed common | medium | current or observed | |
| EmmaEmma email marketing |
| current and observed | medium | current or observed | |
| EverlyticEverlytic email marketing |
| current and legacy | medium | current or observed | |
| FastmailFastmail custom domains |
| fixed rotation set | high | current or observed | |
| FastmailFastmail legacy/provider signing |
| legacy observed | medium | legacy or observed | |
| FreshworksFreshdesk · Freshservice · Freshworks email notifications |
account-specific random labels on freshemail.io white-label CNAMEs (e.g. 1s3, zkons) Freshdesk's classic DKIM setup publishes CNAMEs at fdm._domainkey, fd._domainkey and fd2._domainkey pointing to <id>.domainkey.freshdesk.com. Newer accounts get account-specific labels on freshemail.io targets, which cannot be guessed. fd1, freshdesk and fw were removed: their only evidence was the wildcard on freshworks.com. | current and observed | medium | current or observed | |
| FrontFront customer operations · Front email |
| observed common | medium | current or observed | |
| GandiGandi Mail |
CNAMEs to gmN.gandimail.net, needed when the domain does not use Gandi LiveDNS; all three are needed for key rollover. | fixed rotation set | medium | current or observed | |
| GetResponseGetResponse email marketing | customer-specific alphanumeric selector (example format: 61715esc) | generated customer specific | medium | current or observed | |
| GitHubGitHub notification email · GitHub provider-operated domains |
| provider domain observed | medium | current or observed | |
| GoDaddyGoDaddy Email Marketing · Mad Mimi |
| current and observed | medium | current or observed | |
| GoogleGoogle Workspace · Gmail custom-domain signing |
administrator-defined custom selector Google documents 'google' as the recommended default; administrators can choose another unused selector. | default but customizable | high | current or observed | |
| GoogleGoogle-operated/legacy signing domains |
Historic dated Google selector; not the normal Workspace customer default. | historic or provider domain | medium | historical observed | |
| Help ScoutHelp Scout custom-domain email |
CNAMEs to strongN._domainkey.helpscout.net. | fixed rotation pair | medium | current or observed | |
| HornetsecurityHornetsecurity 365 Total Protection outbound signing |
CNAMEs to hseN._domainkey.hornetsecurity.com. Documented only by a third-party guide; no customer zone was found. | fixed rotation pair | medium | current or observed | |
| HostingerHostinger Email |
CNAMEs to hostingermail-X.dkim.mail.hostinger.com. Keys b and c can resolve to an empty p= while they are unused rotation slots. | fixed rotation set | high | current or observed | |
| HubSpotMarketing Hub · HubSpot marketing email |
hs1-<hub_id> hs2-<hub_id> Newer accounts may embed the Hub ID in the selector; exact values should come from HubSpot. | generation dependent | medium | current or observed | |
| IntercomIntercom customer messaging · Intercom outbound email |
| observed common | medium | current or observed | |
| Intuit MailchimpMailchimp Transactional · Mandrill |
mte1/mte2 are useful current candidates; mandrill is a strong legacy candidate. | current and legacy | medium | current or observed | |
| IONOSIONOS Mail · 1&1 Mail |
s<account digits> (a third per-account CNAME, e.g. s42582890) CNAMEs to s1.dkim.ionos.com, s2.dkim.ionos.com and s<account digits>.dkim.ionos.com. The per-account selector cannot be guessed. | fixed rotation set | high | current or observed | |
| IterableIterable cross-channel marketing · Iterable Email |
| observed common | medium | current or observed | |
| KitKit creator marketing · ConvertKit |
| current and legacy | medium | current or observed | |
| KlaviyoKlaviyo Marketing Automation · Klaviyo Email |
| generation dependent | medium | current or observed | |
| LettermintLettermint transactional email API |
CNAMEs to lm1/lm2.<account id>.dkim.lmta.net so Lettermint can rotate keys. The lettermint selector exists only on lettermint's own domain. | fixed rotation pair | medium | current or observed | |
| ListrakListrak marketing automation |
| common default | medium | current or observed | |
| MagNewsMagNews · Diennea email marketing | mn<customer/date-like digits> | generated customer specific | medium | current or observed | |
| mailbox.orgmailbox.org custom domains |
CNAMEs to MBO000N._domainkey.mailbox.org; mailbox.org writes the names in upper case, DNS is case-insensitive. Older guides describe a TXT record instead. | fixed rotation set | medium | current or observed | |
| MailchimpMailchimp Email Marketing |
Current UI supplies two exact CNAMEs; selector generations vary by account and era. | common rotation set | medium | current or observed | |
| MailerLiteMailerLite email marketing |
| observed common | medium | current or observed | |
| MailjetMailjet Email API · Mailjet Marketing |
| common default | medium | current or observed | |
| MailPoetMailPoet Sending Service |
| fixed rotation pair | medium | current or observed | |
| MailtrapMailtrap Email Sending |
CNAMEs to rwmt1/rwmt2.dkim.smtp.mailtrap.live. | fixed rotation pair | medium | current or observed | |
| MailUpMailUp email marketing |
| fixed rotation pair | medium | current or observed | |
| MappMapp Digital · Mapp Engage |
| common default | medium | current or observed | |
| MaropostMaropost Marketing Cloud |
| common default | medium | current or observed | |
| MDaemon TechnologiesMDaemon Email Server |
MDaemon creates a default selector named MDaemon on startup; administrators can add others. DNS is case-insensitive. | administrator defined with defaults | medium | current or observed | |
| MessageBirdSparkPost legacy/current email delivery |
scph<deployment/date-like suffix> Corporate ownership/name may vary by product era. | generated or dated | medium | current or observed | |
| MicrosoftDynamics 365 marketing/customer insights email |
| observed common | medium | current or observed | |
| MicrosoftMicrosoft 365 · Exchange Online · Defender for Office 365 outbound DKIM |
Both CNAMEs are required; Microsoft alternates active selectors during rotation. | fixed rotation pair | high | current or observed | |
| MicrosoftAzure Communication Services Email |
Both CNAMEs point to <selector>._domainkey.azurecomm.net. Distinct from Microsoft 365, which uses selector1 and selector2. | fixed rotation pair | medium | current or observed | |
| MigaduMigadu |
CNAMEs to keyN.<domain>._domainkey.migadu.com. key1 and key2 are also common generic selectors. No vendor guide was reachable; evidence is customer zones. | fixed rotation set | medium | current or observed | |
| MimecastMimecast Email Security · Cloud Integrated |
tenant-specific selector | custom with common candidates | medium | current or observed | |
| MoosendMoosend |
TXT at ms._domainkey. moosend.com and mailendo.com answer every label under _domainkey, so only customer domains are evidence. | fixed default | medium | current or observed | |
| NamecheapNamecheap Private Email |
TXT at privateemail._domainkey for subscriptions bought on or after 2 June 2026; earlier subscriptions use default._domainkey. | fixed default | medium | current or observed | |
| NetcoreNetcore Cloud · Smartech |
| common default | medium | current or observed | |
| OmnisendOmnisend ecommerce marketing email |
| current and observed | medium | current or observed | |
| OngageOngage email marketing |
| observed common | medium | current or observed | |
| OpenDKIM ProjectOpenDKIM self-hosted signer |
arbitrary administrator-defined selector | administrator defined with defaults | medium | current or observed | |
| OracleOracle Eloqua Marketing Automation |
| observed common | medium | current or observed | |
| OracleOracle platform/provider-operated mail |
| observed common | medium | current or observed | |
| OracleOracle Responsys Campaign Management |
| observed common | medium | current or observed | |
| OVHcloudOVHcloud Email Pro · OVHcloud Exchange · OVHcloud MX Plan and Zimbra | ovhemp<id>-selector1 and -selector2 (Email Pro) ovhex<id>-selector1 and -selector2 (Exchange) ovhmo<id>-selector1 and -selector2 (MX Plan and Zimbra) CNAMEs to <selector>._domainkey.<n>.<xx>.dkim.mail.ovh.net with a per-service id, so there is no literal to probe. | generated customer specific | high | current or observed | |
| PostalPostal mail server | postal-<6 random letters> Postal names each domain's selector from the configurable dkim_identifier (default postal) and a random six-letter string, so there is no literal to probe. | generated unguessable | medium | current or observed | |
| PostmarkPostmark transactional email |
<timestamp-or-date>pm Postmark commonly supplies a unique selector such as 2023060112345pm; fixed candidates are useful but not exhaustive. | customer specific dated | high | current or observed | |
| PowerMTA / generic MTA deploymentsSelf-hosted and managed MTA deployments |
arbitrary administrator-defined selector date-based selectors These names are intentionally non-attributable and should be queried as generic candidates. | administrator defined generic | medium | current or observed | |
| ProofpointProofpoint Email Protection · Email Fraud Defense |
tenant-specific/custom selectors common | custom with common candidates | medium | current or observed | |
| ProtonProton Mail custom domains |
Proton asks customers to retain all three records for managed rotation. | fixed rotation set | high | current or observed | |
| PurelymailPurelymail |
CNAMEs to keyN.dkimroot.purelymail.com; the three keys rotate. | fixed rotation set | medium | current or observed | |
| Rackspace TechnologyRackspace Email · Hosted Email |
| observed common | medium | current or observed | |
| ResendResend Email API |
account/domain-generated values possible | common default or generated | medium | current or observed | |
| SailthruSailthru email marketing |
| observed common | medium | current or observed | |
| SalesforceAccount Engagement · Pardot |
customer-defined selector possible | custom with common candidates | medium | current or observed | |
| SalesforceMarketing Cloud · ExactTarget |
up to two customer-defined selectors | custom with common candidates | medium | current or observed | |
| SalesforceSalesforce platform email |
administrator-defined primary and alternate selector any customer-chosen label (e.g. a brand name, optionally numbered), as a CNAME to <label>.<6-character tenant id>.custdkim.salesforce.com Salesforce custom DKIM CNAMEs end in custdkim.salesforce.com with a per-key tenant id, so the target identifies Salesforce even when the label is unguessable. | custom with common candidates | medium | current or observed | |
| SAPSAP Emarsys Customer Engagement |
| common rotation pair | medium | current or observed | |
| SenderSender |
CNAME to dkim.sendersrv.com. | fixed default | medium | current or observed | |
| SendlaneSendlane email marketing |
| observed common | medium | current or observed | |
| SendySendy self-hosted newsletter application |
depends on configured delivery provider, commonly Amazon SES opaque tokens Sendy itself may defer DKIM to its configured transport. | application or provider dependent | low | current or observed | |
| ShopifyShopify Email |
| observed common | medium | current or observed | |
| ShopifyShopify platform email |
| observed common | medium | current or observed | |
| SinchMailgun |
customer-defined selector Mailgun supports creating and changing selectors, so no candidate is guaranteed. Automatic Sender Security uses the pdk1 and pdk2 CNAMEs to a per-account target on dkim1.mailgun.com (or dkim9.eu.mgsend.org for EU accounts). | custom with common candidates | medium | current or observed | |
| SMTP2GOSMTP2GO email delivery |
| observed common | medium | current or observed | |
| SparkPostSparkPost email delivery |
scph<deployment/date-like suffix> | generated or dated | medium | current or observed | |
| SquarespaceSquarespace Email Campaigns · Squarespace platform email |
| observed common | medium | current or observed | |
| StripeStripe platform email · Stripe customer email |
| observed common | medium | current or observed | |
| TitanTitan Business Email |
| observed common | medium | current or observed | |
| TurboSMTPturboSMTP email delivery |
| observed common | medium | current or observed | |
| TutaTuta Mail custom domains |
CNAMEs to s1.domainkey.tutanota.de and s2.domainkey.tutanota.de. s1 and s2 are also generic selectors. | fixed rotation pair | medium | current or observed | |
| TwilioSendGrid Email API · SendGrid Marketing Campaigns |
three-character customer-defined selector; resulting key labels may be derived s1/s2 are the automated-security defaults and support rotation; smtpapi and m1 are useful legacy probes. | default but customizable | high | current or observed | |
| TwilioSendGrid legacy/manual configurations |
| legacy observed | medium | legacy or observed | |
| YahooAOL Mail provider-operated domains |
| provider domain observed | medium | current or observed | |
| YahooYahoo Mail provider-operated domains |
| provider domain observed | medium | current or observed | |
| ZendeskZendesk Support outbound email |
| fixed rotation pair | high | current or observed | |
| ZohoZoho Mail custom domains |
customer-defined selector numeric/timestamp-like selector observed Zoho officially lets the administrator choose the selector; zoho is its documentation example, not a mandatory default. | custom with common examples | high | current or observed |
Generic selectors
Common names that are not tied to a single provider; tried for every domain.
defaultmaildkimdkim1dkim2smtpemailkeykey1key2s1s2k1k2selectorselector1selector2x202320242025202620230601
Limitations
- DKIM selectors are not enumerable through ordinary DNS. A miss against this list does not prove DKIM is absent.
- The authoritative selector is the s= value in a DKIM-Signature header paired with its d= signing domain.
- Some providers generate random, tenant-specific, account-ID, timestamp, or administrator-defined selectors that cannot be represented by a finite wordlist.
- Several selectors are historical or observed probe candidates rather than current contractual defaults. Use status, confidence, selector_mode, notes, and source_urls.
- Check for _domainkey wildcards before treating probe hits as real selectors. Resolve both TXT and CNAME chains and detect revoked keys with an empty p= value.
- A provider-operated-domain selector is not necessarily published on customer domains; consult customer_domain_applicability.