How DKIM works
DKIM signs each outgoing message with a private key held by your mail server. The matching public key sits in DNS at selector._domainkey.yourdomain. The receiver fetches it and checks the signature, which proves the message came through a server you trust and was not changed on the way.
The selector lets a domain have several keys at once: one per provider, or a new one during a key change. That is why you need the selector to find a key; DNS has no way to list them all.