Solo ads sellers / Blog / DKIM selector

Solo ads blog

Ask which selector signed the solo ad

Answer Ask which DKIM selector will sign the live solo ad. RFC 5863 is the operations document for DKIM. The selector is the name that points receivers at a public key. A test signed by a different selector is a test of a different key. Get the name before you pay, and match it on a message you receive.

Cream stationery and a teal accent on a dark navy desk
The selector is a name. Ask for the name.

The note that started this: RFC 5863, DKIM Development, Deployment, and Operations, RFC 5863.

Selectors sound like an engineer is trying to leave the room. They are a single DNS label. In the signature they show up as the s= value. In DNS the public key is published at that name under the domain. You do not need to compute the signature to read the name. You need the seller to say the name out loud and then use it on the day. Buy solo ads from a shop that knows which key is in production.

The operations RFC talks about how to deploy this without painting yourself into a corner. Keys rotate. Selectors let you publish a new key beside the old one, move traffic, and retire the old name. That is good hygiene. It is also how a sloppy shop shows you a test from selector test1 and then broadcasts with selector oldmail, or with the platform's selector, and calls it the same setup. The names are the audit.

What is a DKIM selector?

It is the name that tells a receiver which public key to fetch for a signature. RFC 5863 discusses selectors as part of operating DKIM. The signature carries the selector. The key lives in DNS under that name.

Two selectors can both be valid for one domain at the same time. Validity is not sameness. One key might be the platform. One might be a tool you turned off. One might be short-lived for a test. A receiver that verifies the signature will accept any of them if the math works and the key is published. Your quote is narrower. You want the selector that belongs to the platform and the domain you hired. Extra valid keys are an operations question. An unexpected key on your test is a stop.

This note does not give you a key length to demand. Length arguments go stale, and a buyer quoting a bit count from memory is how orders pick up fake precision. Ask for the selector name. If you want a second question, ask when that key was last rotated, and who can create a new selector. A shop that answers both has an operator. A shop that answers with a screenshot of the word pass has a screenshot.

Why should a solo ad buyer ask for the selector?

A test message can be signed with a different selector than the broadcast. Ask which selector will sign the drop you are paying for, and check that the test you receive uses that selector.

The test is the whole point of sending yourself a copy. Open the authentication result and read the selector and the domain. If the seller said s1 and the header says google or a platform default you did not agree to, the test did not test the identity in the quote. Do not let them tell you it is close enough. Close enough signs someone else's reputation onto your creative, or signs a key they do not watch.

Rotation is a legitimate reason for a name to change. The legitimate version tells you before the send. We are moving from s1 to s2 on Thursday. The test you get Wednesday still shows s1. The test you get Friday shows s2. An illegitimate version changes the name in the gap between your approval and the broadcast and hopes you do not look. Looking is the job.

Does the right selector guarantee inbox placement?

No. It tells you which key signed. Placement still depends on the domain's reputation, the list, and the receiver. A matching selector only means the test and the send used the same name.

A correct selector on a tired domain is a correctly named problem. You have identified the key. You have not repaired the complaints, the list, or the offer. Do not let the seller end the call on the selector as if the audit were finished. End it on the list and the refund line, with the selector written down so the audit can be repeated after the drop.

RFC 5863 is for operators. You are borrowing one question from it. Which selector signs the live message? A seller who can answer is operating the domain. A seller who cannot is renting a button they do not understand. Rent the operator.