You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于DKIM单个选择器能否配置多个公钥的技术问询

关于DKIM单个选择器能否配置多个公钥的技术问询

Awesome question—let’s break this down clearly and concisely.

First things first: No, you can’t have multiple distinct public keys associated with a single DKIM selector in one TXT record. Here’s the lowdown:

  • The DKIM standard (RFC 6376) explicitly ties each selector to exactly one public key. A valid DKIM TXT record uses a single p= tag to hold the base64-encoded public key. If you try to include multiple p= tags in the same record, DNS resolvers and DKIM verifiers will treat it as malformed and reject it—they have no way to pick which key to use.

That said, if you need to use multiple keys for your domain, there are perfectly valid, standard workarounds:

  • Use multiple selectors: This is the go-to approach. For example, you could set up marketing._domainkey.yourdomain.com and transactional._domainkey.yourdomain.com, each with their own unique public key. This lets you rotate keys smoothly, or use different keys for different email streams to boost security or organization.
  • Temporarily overlap keys during rotation: When you’re switching to a new key, you can keep the old selector’s TXT record active for a short while as you update all your sending systems to use the new selector. Once all emails are signed with the new key, you can safely remove the old record.

One common misconception to clear up: You also can’t have multiple separate TXT records for the same selector. DNS doesn’t allow duplicate fully qualified domain names (FQDNs) for DKIM records, and verifiers would just pick one at random—leading to inconsistent verification results.

So to wrap it up: Stick to one public key per selector, and use multiple selectors if you need to work with multiple keys.

备注:内容来源于stack exchange,提问作者SUNITA GUPTA

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.20 06:48:05