Resources
What is DKIM?
DKIM signs outgoing mail with a key whose public half lives in your DNS. The signature survives forwarding.
The sending server signs selected headers and the body. The receiver fetches the public key from <selector>._domainkey.yourdomain and verifies it.
The selector lets you run several keys at once, which is what makes a rotation possible without a gap.
Unlike SPF, a DKIM signature stays valid when a message is forwarded, as long as the content is not modified in transit.
A DKIM record that exists but does not match the key in use is worse than none — it fails instead of being absent, so verify after every change.