Skip to content

DKIM key has been live for years, want to rotate without bouncing a single mail

DKIM rotation is safe with two selectors live in parallel: the old one keeps signing until the new one has propagated, then you switch. No mail pause, just patience for TTL spread.

Try this first

  1. 1In your mail platform (M365, Google, Mailgun, Postmark) generate a second selector (e.g. selector2 or 2024) and publish the matching TXT/CNAME next to the old one.
  2. 2Wait 1 to 4 hours until dig +short txt selector2._domainkey.yourdomain returns the record across multiple resolvers.
  3. 3Switch the active selector in the mail platform to the new one. From that moment the new key signs outgoing mail.
  4. 4Keep the old selector live in DNS for at least 7 days, because messages already sent can still be validated by late lookups.
  5. 5Remove the old selector after 14 days, check DMARC reports that alignment stayed at 100 percent.

When to bring us in

If you have many senders with their own DKIM (Mailgun, SendGrid plus M365 plus marketing tool) and do not know which one signs what, we can sort the rotation.

See also

None of the above fits?

Describe your situation below. We pass your input plus the steps you already saw to our AI and return tailored next-step advice. If it's too risky to DIY, we'll say so.

Who are you?

For the AI question we need your email and company, so we can follow up if the AI gets stuck, and to prevent abuse.

Limited to 2 questions per hour and 5 per day, kept lean so the AI stays useful. For more, contacting us directly works better for you and us.

Or skip the DIY entirely

Our Managed IT clients do not look these things up. One point of contact, a fixed monthly price, resolved within working hours.