DKIM management properties¶
Key Generation¶
Signing Algorithms¶
List of signing algorithms to use when generating new DKIM keys.
A list. Each one: one of: DKIM1 (Ed25519 SHA-256) (Dkim1Ed25519Sha256), DKIM1 (RSA SHA-256) (Dkim1RsaSha256), DKIM2 (Ed25519 SHA-256) (Dkim2Ed25519Sha256), DKIM2 (RSA SHA-256) (Dkim2RsaSha256). Default: DKIM1 (Ed25519 SHA-256), DKIM1 (RSA SHA-256). Name in the API: algorithms.
Selector Template¶
Template for generating DKIM selectors during key rotation. Supported variables:
- {algorithm}: signing algorithm in lowercase (rsa, ed25519)
- {hash}: hash algorithm (sha256)
- {version}: DKIM version number (1)
- {date-<fmt>}: current UTC date formatted with chrono strftime (e.g. {date-%Y%m%d})
- {epoch}: current UTC unix timestamp
- {random}: random 8-character alphanumeric string.
Text. Default: v{version}-{algorithm}-{date-%Y%m%d}. Name in the API: selectorTemplate.
Key Rotation¶
Rotate After¶
How often to rotate DKIM keys. Requires automatic DNS management to be enabled for the domain.
A length of time. Default: 90d. Name in the API: rotateAfter.
Retire After¶
How long to keep the old key's DNS record published after rotation before removing it. Requires automatic DNS management.
A length of time. Default: 7d. Name in the API: retireAfter.
Delete After¶
How long to retain old DKIM keys on the server after rotation before deleting them permanently. Requires automatic DNS management.
A length of time. Default: 30d. Name in the API: deleteAfter.