How DKIM works in one minute
When your mail server sends a message, it signs selected headers and the body with a private key and adds a DKIM-Signature header. That header names the signing domain (d=) and a selector (s=). The receiver looks up s._domainkey.d in DNS, gets the matching public key, and verifies the signature. If anything was altered in transit, or the key is missing, DKIM fails.
Finding your selector
Leave the selector empty and the checker tries common ones such as google, selector1/selector2 (Microsoft 365), k1, and s1. For a definitive result, open a message you sent, choose "Show original" in Gmail (or view the source in your mail client), and copy the s= value from the DKIM-Signature header:
DKIM-Signature: v=1; a=rsa-sha256; d=example.com; s=google; ...
What the results mean
- Revoked key (empty p=) — the selector exists but the key was withdrawn. Point your provider at a current selector.
- 1024-bit key — still valid, but upgrade to 2048-bit when your DNS host supports long TXT records.
- Key can't be parsed — usually a copy-paste problem: missing characters, extra quotes, or a line break inside the key.
- t=y — testing mode. Remove it once signatures verify.
DKIM passing isn't the end of the story. For DMARC, the d= domain has to match your From domain. Check that with the DMARC Checker, and make sure your SPF record is clean too.