DKIM record at {selector} cannot be read
CODE REDWhat it means
The record at selector1._domainkey.example.com has no usable public key, either the p= tag is absent or the key data does not decode. Verifiers reject every signature that points here.
How to fix it
Republish the key exactly as your provider issued it, on one line, with no spaces inserted by the DNS panel.
Check your own domain
This page describes the condition. To find out whether your domain has it, run the DKIM test or the full checkup, which examines every record at once.
Understand it properly
This page covers one condition. For the whole picture, What is DKIM, selectors and key strength, or start at the Health Library.
Where this comes from
We judge this against RFC 6376 section 3.6.1. Every finding on this site cites the specification behind it so you can check the work rather than take our word for it.
Other DKIM conditions
DKIM_RECORD_BROKEN
Every fix on this site is yours to implement. If you would rather someone did it, I take this work directly.