DKIM Record Checker

Enter a domain and, if you know it, the DKIM selector. We'll fetch the public key, check its length and settings, and tell you what needs fixing.

Bahasa Indonesia

Advertisement

How DKIM works in one minute

When your mail server sends a message, it signs selected headers and the body with a private key and adds a DKIM-Signature header. That header names the signing domain (d=) and a selector (s=). The receiver looks up s._domainkey.d in DNS, gets the matching public key, and verifies the signature. If anything was altered in transit, or the key is missing, DKIM fails.

Finding your selector

Leave the selector empty and the checker tries common ones such as google, selector1/selector2 (Microsoft 365), k1, and s1. For a definitive result, open a message you sent, choose "Show original" in Gmail (or view the source in your mail client), and copy the s= value from the DKIM-Signature header:

DKIM-Signature: v=1; a=rsa-sha256; d=example.com; s=google; ...

What the results mean

  • Revoked key (empty p=) — the selector exists but the key was withdrawn. Point your provider at a current selector.
  • 1024-bit key — still valid, but upgrade to 2048-bit when your DNS host supports long TXT records.
  • Key can't be parsed — usually a copy-paste problem: missing characters, extra quotes, or a line break inside the key.
  • t=y — testing mode. Remove it once signatures verify.

DKIM passing isn't the end of the story. For DMARC, the d= domain has to match your From domain. Check that with the DMARC Checker, and make sure your SPF record is clean too.

Frequently asked questions

A selector is a label that points to one public key, published at selector._domainkey.yourdomain.com. It lets you run several keys at once — one per email service — and rotate them without downtime.

Open any email you sent, view the original message, and find the DKIM-Signature header. The value after s= is the selector and d= is the signing domain. Your email provider's DNS setup page also lists it.

It still validates, but 2048-bit is the current recommendation. If your DNS host supports long TXT records, rotate to a 2048-bit key.

Without a selector the checker can only try common names. Many services use random or account-specific selectors, so enter yours to get a definitive answer.

Only if the d= domain in the signature aligns with your visible From domain. A provider that signs with its own domain passes DKIM but doesn't help DMARC.
Ad
Advertisement
Ad
Advertisement