Any benefit to individual keys for subdomains?

From: Steve Jenkins <>
Date: Thu, 25 Apr 2013 08:53:15 -0700

Background: I'm working on some "best practices" docs for OpenDKIM, so I'm
re-thinking from scratch some of the stuff I'm doing.

If I have two servers that send mail:

Is there any benefit to having separate keys and DNS TXT records for each

I currently have my SigningTable set up like this on server 1:


and this on server 2:


and both servers have a local copy of the same private key.

I've tested this setup and it works fine, mail gets signed on my end and
verified on the other.

But I'm just wondering if there is any benefit to breaking it out separately


