Free tool
DKIM record checker
Enter a domain and a selector to read its DKIM public key. Don’t know the selector? Leave it empty and we scan the ones Google Workspace, Microsoft 365 and common providers use.
Quick answer
What this tool checks
The key exists at the selector. We query <selector>._domainkey.<domain>, following CNAMEs the way receivers do, and show the record we find.
The key is not revoked. An empty p= tag means the key was revoked on purpose. Mail still signed with it fails DKIM.
Key strength. We estimate the RSA key size from the public key. 1024-bit keys still verify but are considered weak; 2048-bit is the standard.
Common selector scan. Without a selector, we try a short list of common ones in parallel: google, selector1, selector2, k1, s1, default and others.
Where providers publish DKIM
| Provider | Typical selector | Record type |
|---|---|---|
| Google Workspace | TXT | |
| Microsoft 365 | selector1, selector2 | CNAME to Microsoft |
| Mailchimp | k1, k2, k3 | CNAME |
| SendGrid | s1, s2 | CNAME |
| Amazon SES | Random tokens | 3 CNAMEs |
How to fix common issues
No key at the selector
Open an email you sent, view the original, and find s= and d= in the DKIM-Signature header. Check that exact selector and domain. If it is missing, copy the record your provider shows again: a common mistake is pasting the full name into a DNS host that already appends the domain.
Key revoked or empty
Your provider rotated keys or the record was cleared. Re-enable DKIM in the provider’s dashboard and publish the new record it gives you.
1024-bit key
Generate a 2048-bit key with your provider, publish it under a new selector, switch signing to it, then remove the old record after a few days.
DKIM passes but DMARC fails
DMARC needs DKIM aligned: the d= domain must match your From domain or its parent. Sign with your own domain instead of the provider’s default.
Frequently asked questions
How do I find my DKIM selector?
Open an email you sent, show the original message or headers, and look for the DKIM-Signature header. The s= value is the selector and d= is the signing domain.
Why does the scan find nothing when DKIM works?
Many providers use custom or random selectors, such as Amazon SES tokens. A scan only covers common names. Enter the selector from your DKIM-Signature header to check it directly.
Is a 1024-bit DKIM key still OK?
It still verifies at major mailbox providers, but it is considered weak. Use a 2048-bit RSA key when your DNS host supports long TXT records.
Can I have several DKIM keys?
Yes. Each sending service signs with its own selector, so a domain can publish many DKIM records side by side.
Does this tool contact my mail server?
No. It reads public TXT records from DNS only, with a timeout on each query.
Related tools and guides
- GlossaryWhat is DKIM?The signature that proves an email was not altered.
- GlossaryWhat is DMARC?The policy that ties SPF and DKIM to your From domain.
- DocsFix DKIMResolve missing or failing DKIM records.
- Free toolSPF checkerCount SPF lookups and flag weak policies.
- Free toolDMARC checkerRead the DMARC policy and what to tighten.
- Free toolMail testerSend a real email and get a score out of 10.
Authenticated sending, set up for you.
3,000 emails a month free. Unlimited subscribers on every plan. Campaigns, automations and transactional email on one domain.