DKIM Record Checker
Inspect the public key a domain publishes for signing its email. Enter the domain and, if you know it, the selector; the checker reads the record from DNS, decodes the key and tells you whether it is usable and strong enough.
- Encrypted connection
- No sign-up
- Free to use
How to use DKIM Record Checker
- Enter the domain that signs the mail (the d= value of the DKIM signature).
- Enter the selector if you know it, or leave the field empty to try the selectors of popular mail services.
- Select Check DKIM.
- Review each key that was found: its type, length, flags and any problems.
DKIM Record Checker features
Real key analysis
The public key is decoded to report its true type and length, not just the length of the text.
Selector discovery
Tries the selectors used by Google, Microsoft 365, Zoho, Proton, Fastmail, Mailchimp and other services.
Revoked key detection
Recognises records with an empty key, which mark a selector as withdrawn.
Flag explanations
Explains testing mode (t=y), strict domain matching (t=s) and hash restrictions.
Follows delegation
Works with selectors that are CNAME records pointing to a mail provider.
Honest about guessing
When no selector is given, the result states which ones were tried and that others may exist.
When to use DKIM Record Checker
- Confirming that the DKIM record your email provider asked you to add is visible and correct.
- Checking whether a domain still uses a 1024-bit key that should be rotated.
- Investigating messages that arrive with “dkim=fail” or “dkim=permerror”.
- Verifying both selectors after a provider rotates keys.
DKIM Record Checker FAQ
What is DKIM?
DomainKeys Identified Mail adds a digital signature to each outgoing message. The sending server signs selected headers and the body with a private key; the matching public key is published in DNS. A receiver that can verify the signature knows that the domain vouches for the message and that it was not altered on the way.
What is a selector and where do I find it?
A selector is a label that lets a domain publish several keys at once, for different services or for key rotation. The key lives at selector._domainkey.domain. To find the selector, open the full headers of a message sent from the domain and look at the DKIM-Signature header: the s= tag is the selector and d= is the domain.
Why can the tool not list all selectors of a domain?
DNS has no way to enumerate the names under _domainkey. A selector can be any string, so a checker can only ask for specific names. Leaving the field empty tries a list of well-known ones, which finds many but never proves that no other key exists.
Is a 1024-bit key still acceptable?
It still verifies at most receivers, but it is considered weak, and the standards recommend at least 2048 bits. Keys shorter than 1024 bits are rejected outright by large mailbox providers. Rotating to 2048 bits is a quick improvement.
What does an empty p= tag mean?
It means the key has been revoked. The owner removed the key material on purpose, usually after rotating to a new selector. Messages still signed with the old selector fail verification.
What does t=y mean?
It marks the domain as testing DKIM. Receivers are asked not to treat mail differently when a signature fails. It should be removed once signing works reliably, because it weakens the value of the signature.
How DKIM records work
A DKIM record is a TXT record made of tags separated by semicolons. The essential one is p, which carries the public key in Base64. The k tag names the algorithm, rsa by default or ed25519 for the newer elliptic-curve option, and v=DKIM1 identifies the record type. Because a 2048-bit key does not fit into a single 255-character DNS string, the record is stored as several quoted strings that DNS software joins together; a missing or misplaced quote at this point is the most frequent cause of an unreadable key.
Many organisations never publish the key themselves. Their mail provider asks them to create a CNAME record such as selector1._domainkey pointing to a name the provider controls. The provider can then rotate the key without any further DNS change on the customer's side. From the outside the result looks the same, and this checker follows the alias to the actual key.
DKIM matters more than it used to because of DMARC. A message passes DMARC when either SPF or DKIM succeeds for a domain that matches the visible From address. SPF breaks when mail is forwarded, while a DKIM signature travels with the message, so a working, aligned DKIM signature is what keeps legitimate forwarded mail from being rejected under a strict policy.
Good practice is short: use 2048-bit RSA keys, give each sending service its own selector so that one can be revoked without affecting the others, rotate keys periodically, and remove the testing flag once everything verifies.