A safe DKIM key rotation is an overlap between two selector names, not an in-place replacement of one DNS value. Publish and verify the new public key first, switch one outbound mail stream to the matching private key, and keep the old selector available until no message ...