To resume, if the SubDomains option could also works with signing/key tables, this would avoid to enter additional entries for subdomains such as: etc/opendkim/SigningTable .example.tld .example.tld:@example.tld etc/opendkim/Keytable .example.tld .example.tld:mail:/etc/opendkim/keys/.example.tld/mail.private