DIAGNOSTIC PLAYBOOK
Rotate DKIM keys without breaking queued mail
A DKIM rotation needs to account for messages signed with the old key but verified later. A new selector lets old and new public keys coexist while the sending service moves to the new private key.
HealthCheck Email editorial team · · Examples are illustrative
How to investigate
- Publish and verify the new selector before configuring the signer to use it.
- Send samples from every sending path and confirm that new messages use the new selector successfully.
- Retain the old public key for an appropriate queue and verification window, then retire it using your provider's guidance.
What this looks like
ILLUSTRATIVE EXAMPLE
DNS for a new selector is ready, but one queue still holds messages signed with the previous selector. Leaving the old public key available lets those messages be checked.
A mistake to avoid
There is no universal retirement delay for every system. Queue behavior, replay verification and a compromised key can require different decisions.
Keep the result in context
A DKIM investigation needs a real signed message and the public key for its selector and signing domain. DNS alone cannot prove that a service is signing outgoing mail. Preserve the raw source when comparing messages so your own copy process does not change the bytes being checked.
Take the next step
Use the related check to gather evidence, then compare it with the affected message or service. Keep the result and time with your notes so a later change can be distinguished from the original problem.
Sources and further reading
The protocol references below explain the underlying behavior. Your sending or DNS provider supplies the account-specific settings for its service.