Suped

Hosted DKIM. One delegation. Every selector.

Delegate _domainkey to Suped once. Add, update, rotate, and remove public DKIM records from the dashboard without another DNS ticket.
Get started
MoneyMe logoKnovos logo
DKIM record hosting

Delegate once,
manage every selector here

Your sending providers keep signing email. Suped hosts the public TXT and CNAME records receivers use to verify those signatures. Click a selector to see the DNS answer.

DKIM selectors
example.com
Add selector
DNS connected
Select a record to inspect it
Suped authoritative DNS
Serving _domainkey.example.com
Live
One-time delegation
Host
_domainkey.example.com
Type
NS
Value
example.com.dkim.dns.suped.com
Suped answers every selector lookup
Live DNS answer
google._domainkey.example.com
TXT
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0...
Change the dashboard record, not your DNS zone
Google Workspace, TXT, google

What is hosted DKIM?

Hosted DKIM moves the public DNS side of DKIM into Suped. Your sender still signs each message with its private key. Suped serves the matching public TXT record or provider CNAME that receivers use to verify the signature.

Instead of editing DNS for every new provider or key rotation, you delegate _domainkey once and manage each selector from one inventory.

  • One NS delegation for the entire _domainkey namespace
  • TXT public keys and CNAME selectors in the same dashboard
  • Add or update records without returning to your DNS provider
  • Keep private keys and signing with your existing email providers
  • Give teammates selector access without sharing DNS credentials
Your DNS provider
NS
_domainkey.example.com
To
example.com.dkim.dns.suped.com
Entire _domainkey namespace
Suped hosted zone
Authoritative
google._domainkeyTXT
selector1._domainkeyCNAME
s1._domainkeyCNAME

DKIM changes become controlled dashboard work

New senders and key rotations stop being risky DNS copy-and-paste jobs. Every public record has a name, selector, type, value, and update time in one place.
Safer rotation

Publish first. Switch the sender second.

Add a new selector before your provider starts signing with it. Keep the old key online during the overlap, then retire it when old signatures no longer need verification.

Safe key rotation
1
Publish new selector
s2
2
Switch the sender
s2
3
Retire old selector
s1
Delegated operations

Change selectors without sharing DNS credentials.

The DNS owner publishes one NS record. After that, the people responsible for email can manage public DKIM records in Suped while DNS access stays tightly held.

Access stays separated
DNS provider
One-time delegation
Locked down
Suped workspace
Selector changes
Team access
The migration step that matters

Bring every selector with you before you delegate

An NS record hands Suped the whole _domainkey namespace. A selector left only in the old DNS zone disappears from public lookup after the switch, so copy existing records first.
01
Inventory every selector
Collect all TXT and CNAME records currently below _domainkey.
02
Add them to Suped
Recreate every active selector before the delegation changes.
03
Publish the NS record
Delegate _domainkey only after the hosted inventory is complete.

Everything you need to host DKIM records

Focused DNS hosting for the public half of DKIM, with the controls needed to move safely and operate every selector afterward.
NS_domainkey.example.com
One DNS delegation
Publish one NS record for _domainkey. Future selector changes stay out of your primary DNS zone.
googleTXT
selector1CNAME
TXT and CNAME records
Host direct DKIM public keys and provider-managed CNAME selectors side by side.
Google Workspace
Microsoft 365
Marketing
Every selector in one list
Give each record a friendly name and see its selector, type, value, and latest update.
Safe key rotation
1
Publish new selector
s2
2
Switch the sender
s2
3
Retire old selector
s1
Controlled key rotation
Publish the replacement first, switch signing, and remove the old selector only when it is safe.
v=DKIM1; k=rsa; p=MIIB...
Valid DKIM record
Record validation
Suped checks DKIM TXT syntax and CNAME targets before publishing a change.
google._domainkey
Record found
Independent verification
Check the live public answer after setup or any selector change with the free DKIM checker.
Open the DKIM checker

Move DKIM changes out of DNS

Delegate once, bring every current selector across, and manage the next provider or key rotation from the dashboard.

Get started
DKIM selectors
example.com
Hosted
Google Workspace
google._domainkey
TXT
Microsoft 365
selector1._domainkey
CNAME
Marketing platform
s1._domainkey
CNAME

Hosted DKIM FAQs

You have questions about hosting DKIM records, we have answers.

Here's why customers love Suped for DMARC monitoring

MONEYME cover

How MONEYME proactively strengthens domain security and unlocks higher email engagement with Suped

See how MONEYME uses Suped
Jam Cyber cover

How cybersecurity specialist Jam Cyber delivers scalable DMARC protection with Suped

See how Jam Cyber uses Suped
Vision Australia cover

How Vision Australia maintains full DMARC enforcement across a large domain portfolio with Suped

See how Vision Australia uses Suped
The POP Team cover

How The POP Team turns domain checks and DMARC visibility into client ready delivery work

See how The POP Team uses Suped
DigiBean cover

How DigiBean simplified DMARC monitoring and improved email security for their MSP clients

See how DigiBean uses Suped
Alliance Group cover

How Alliance Group moved from reactive guesswork to proactive email management with Suped

See how Alliance Group uses Suped
G2 LeaderG2 Users Most Likely To RecommendG2 Easiest To Do Business WithG2 High PerformerG2 Best Estimated ROI
DMARC monitoring

Start monitoring your DMARC reports today

Suped DMARC platform dashboard
What you'll get with Suped
Real-time DMARC report monitoring and analysis
Automated alerts for authentication failures
Clear recommendations to improve email deliverability
Protection against phishing and domain spoofing