DKIM for iCloud+ Custom Email Domain

iCloud+ Custom Email Domain uses the selector sig1. Enter your domain and sig1 below to check the key is published.

  • Free
  • No Sign-Up
  • Live Lookup

Examples:

DKIM Checker

iCloud+ Custom Email Domain DKIM

Selectorsig1
Record Namesig1._domainkey.yourdomain
Check From a Terminaldig +short TXT sig1._domainkey.example.com
SPF and Set-Upfrabs.net/tools/spf-checker/icloud-mail/

Mail from iCloud+ Custom Email Domain carries a DKIM-Signature header with s=sig1 (or another selector the provider shows for your domain). Receivers fetch the public key from sig1._domainkey on your domain to check it.

If the record is a CNAME, the provider hosts the key and can rotate it for you; keep the CNAME exactly as given.

Questions

What is the DKIM selector for iCloud+ Custom Email Domain?
sig1, unless your admin panel shows a different one for your domain.
Why does DKIM still fail?
Signing must also be switched on in the provider's settings, and the record must be published exactly, without extra quotes or spaces.

Your customers' VMs sending spam?

Frabs spots outbound spam from any VM within seconds and stops it, before your IPs end up on a blocklist.