Skip to content
emailrules.today
In forceAuthIn force 1 Sep 2011

An empty p= in a DKIM record is a revoked key, not a published one

What does an empty p= value mean in a DKIM DNS record?

Global

In one sentence

p= with nothing after it does not mean the key is missing.

Plain English

p= with nothing after it does not mean the key is missing. It means somebody revoked it and said so in public. The record answers, so most tools tick the box, and the mail still fails.

Why it matters. p= with nothing after it does not mean the key is missing.

Dotted words open definitions. See how email actually works.

What to do

Your move — not a lecture

Part platform, part you

The platform covers the mechanical bit. The judgement is still yours.

Your platform generates and publishes the key material and will rotate it. It cannot see what else is sitting under _domainkey on your domain.

Your part: Removing revoked and wildcard records from your own . A leftover empty key is yours, and so is the decision to delete rather than keep it for tidiness.

What to do first

Run dig TXT <selector>._domainkey.yourdomain.com for every selector you know about, and read what comes back rather than whether something came back. Any record whose p= is empty is a revoked key that should be deleted. Then probe a selector you invented — if that answers too, you have a wildcard under _domainkey and no selector check on this domain means anything until it is gone.

You can skip this if: You have never rotated a key and publish exactly the selectors your platform gave you.

Who this applies to

Any domain where a selector was rotated, retired or revoked and the empty record was left behind — including the wildcard case, where a record under _domainkey answers every selector name and makes probing meaningless.

Checklist

  • 01Treat an answering selector as inconclusive until you have read the p= value.
  • 02Delete revoked records rather than leaving them; they are indistinguishable from a working key to most tooling.
  • 03Probe an impossible selector to rule out a wildcard before trusting any selector result.
  • 04Confirm on a real message: =pass with header.d matching your is the only proof that survives.

That’s enough to act. The exact wording, the enforcement record and the primary source sit under Proof & sources, for counsel, bosses, or AI tools that need a citation. Not legal advice.

Proof

Exact position, enforcement, sources

For records and people who will check you. Skip if Monday’s move is already clear.

The exact position

RFC 6376 is explicit: an empty value in the p= tag means the public key has been revoked, and verifiers should return an error for any signature referencing it. The record still resolves, so a checker that only asks whether a selector exists reports as present. It is not present. Anything signed with that selector fails, and a domain relying on for loses it silently, because the answer looks healthy from the outside.

What happens if you do not

None, in the regulatory sense. The failure is mechanical: verifiers error on the signature, is lost, and a domain at p=reject that has no aligned path has its own mail rejected.

Source

  • RFC 6376 § 3.6.1, Textual Representation of DKIM Key Records
    Published 1 Sep 2011Read primary source

History of this page

  • Added. The domain check has probed an impossible selector and required real base64 after p= since it shipped; neither behaviour had a page explaining why.

Related

Take this with you

GET https://emailrules.today/rules/empty-dkim-p-value-is-a-revoked-key?format=json

Same URL, same answer, every field including the ones behind the Proof tab. An Accept: application/json header on the plain URL does the same thing. All the endpoints.

FAQ

Awkward questions

Who is this actually for?

People who ship email and are too busy to re-read every PDF: week-one marketers, lifecycle/CRM, deliverability, multi-country ops, DTC brands, agencies — on Klaviyo, Mailchimp, Braze, HubSpot, SFMC, or something else. Pick your tool and geos so product-specific pages only appear when they match. EU and UK are first-class filters. Not for people who sell tools about email and need a fake score to demo.

Why only ~40 rules? Isn’t that… thin?

On purpose. A wall of 400 undated “best practices” is how you look busy and still get burned. Every page needs a primary source we actually read. Thin and checkable beats fat and folklore. Europe, bulk inbox rules, measurement honesty, and protocol topics like BIMI/DMARC policy are on the shelf when we can cite them — not every Member State and not every vendor myth. Coverage map lists what we still refuse to invent.

Is this legal advice?

No. If it were, you’d have a billable hour and a longer PDF. This is a dated operator reference written by an email geek. Confirm anything high-stakes with counsel who knows your facts. Same for “will this make me compliant?” — no tool does that. Lawyers and judges do. We say what the sources say and what to do first on Monday.

Why no trust score out of 100?

Because we refuse to invent a number you can’t audit. Fake scores sell seed tests and panic. You get findings, dates, and links. If that feels less exciting than a red dial, good — you’re not the red-dial customer.

Why should I trust you more than my ESP’s blog?

ESPs sell seats. Seed-score vendors sell fear. AI invents citations when nobody watches. We sell nothing today — no pixels, no placement scores, no affiliate — so we can say when a tool is the problem. A human verifies, dates, and corrects in public. Tools may help draft; they do not ship unsourced claims. Check the primary links. Fail that test and leave.

Do I need an account?

No. Filters live in this browser and the URL. Share the link. That’s it. Accounts come later only if they earn it — not so we can nurture you about email.

I’m an agency. Where’s multi-client mode?

We tried a client-name CRM on the setup card. It made the product feel like work before it felt useful. Role filters + copy link + one-page brief (optional PDF title) is enough for now. Complexity comes back when the free shelf is habit, not before.

Is the quiet changelog a bug?

No. Quiet means nothing material moved. We don’t invent urgency so the homepage looks “alive.” Sticky risks still show what usually needs a person when the market is still.