Skip to content

DKIM management properties

Key Generation

Signing Algorithms

List of signing algorithms to use when generating new DKIM keys.

A list. Each one: one of: DKIM1 (Ed25519 SHA-256) (Dkim1Ed25519Sha256), DKIM1 (RSA SHA-256) (Dkim1RsaSha256), DKIM2 (Ed25519 SHA-256) (Dkim2Ed25519Sha256), DKIM2 (RSA SHA-256) (Dkim2RsaSha256). Default: DKIM1 (Ed25519 SHA-256), DKIM1 (RSA SHA-256). Name in the API: algorithms.

Selector Template

Template for generating DKIM selectors during key rotation. Supported variables: - {algorithm}: signing algorithm in lowercase (rsa, ed25519) - {hash}: hash algorithm (sha256) - {version}: DKIM version number (1) - {date-<fmt>}: current UTC date formatted with chrono strftime (e.g. {date-%Y%m%d}) - {epoch}: current UTC unix timestamp - {random}: random 8-character alphanumeric string.

Text. Default: v{version}-{algorithm}-{date-%Y%m%d}. Name in the API: selectorTemplate.

Key Rotation

Rotate After

How often to rotate DKIM keys. Requires automatic DNS management to be enabled for the domain.

A length of time. Default: 90d. Name in the API: rotateAfter.

Retire After

How long to keep the old key's DNS record published after rotation before removing it. Requires automatic DNS management.

A length of time. Default: 7d. Name in the API: retireAfter.

Delete After

How long to retain old DKIM keys on the server after rotation before deleting them permanently. Requires automatic DNS management.

A length of time. Default: 30d. Name in the API: deleteAfter.