Engineering capabilities
- Key generation and selector strategy per sending platform
- Signing enabled on tenant, gateway and application senders
- Verification against real message headers
- Scheduled key rotation
Security & DNS
Cryptographic signing of outbound mail so recipients can verify that a message really came from your domain and was not altered in transit.
Outbound mail is signed at the platform; receivers fetch the public key from your DNS and verify the signature before applying policy.
One selector per sending platform so keys can be rotated independently.
Every legitimate sender signs; unsigned senders are either fixed or retired.
Old selectors are cleaned out of the zone once traffic has moved.
Verified against real message headers rather than assumed to be working.
Annually is a reasonable baseline for most organisations, and immediately if a signing platform is suspected of compromise. Rotation is planned so both selectors are valid during the change.
Usually yes, which is why it matters. As long as the signed headers and body are not altered, the signature validates after a forward where SPF would fail.
Yes, and it normally should u2014 a separate selector for the mail tenant, the marketing platform and any application relay.
Send the environment details and get an engineered proposal with assumptions, risks and a rollback path.