TROUBLESHOOTING NOTE
DKIM selector not found: use the selector from a real message
Updated
DKIM keys are published under selector._domainkey.signing-domain. A missing common selector does not prove that a domain has no DKIM.
Find the exact lookup
Open a recent legitimate message's headers and locate DKIM-Signature. Use s= as the selector and d= as the domain. A message may contain more than one signature; inspect the sender's signature.
Compare with your provider
Check the exact selector in LabPuff and compare it with your email provider's DNS instructions. Preserve the complete TXT value or provider-required CNAME. An empty p= marks a revoked key and may be intentional for an old selector.
Test a real message
A public-key pass does not authenticate email. Send a test through the actual sending service and examine the receiver's Authentication-Results. Keep private signing keys with your provider; never paste them into a diagnostic tool.
Reference and scope
IETF RFC 6376: DKIM selectors and keys
This guide explains a diagnostic workflow. Provider-specific configuration and actual messages or browser behavior require separate verification. The linked tools report bounded observations, not a complete audit.