DKIM for SendGrid

SendGrid uses the selector s1. Enter your domain and s1 below to check the key is published.

  • Free
  • No Sign-Up
  • Live Lookup

Examples:

DKIM Checker

SendGrid DKIM

Selectors1
Record Names1._domainkey.yourdomain
Check From a Terminaldig +short TXT s1._domainkey.example.com
SPF and Set-Upfrabs.net/tools/spf-checker/sendgrid/

Mail from SendGrid carries a DKIM-Signature header with s=s1 (or another selector the provider shows for your domain). Receivers fetch the public key from s1._domainkey on your domain to check it.

If the record is a CNAME, the provider hosts the key and can rotate it for you; keep the CNAME exactly as given.

Questions

What is the DKIM selector for SendGrid?
s1, unless your admin panel shows a different one for your domain.
Why does DKIM still fail?
Signing must also be switched on in the provider's settings, and the record must be published exactly, without extra quotes or spaces.

Your customers' VMs sending spam?

Frabs spots outbound spam from any VM within seconds and stops it, before your IPs end up on a blocklist.