Skip to content

Free tool

DKIM record checker

Enter a domain and a selector to read its DKIM public key. Don’t know the selector? Leave it empty and we scan the ones Google Workspace, Microsoft 365 and common providers use.

Leave the selector empty to scan common ones. Public DNS lookups only.

Quick answer

DKIM keys live at <selector>._domainkey.<domain> as TXT records. A working record has a non-empty p= public key, ideally RSA 2048-bit or Ed25519. The selector is in the s= tag of the DKIM-Signature header of any email you sent.

What this tool checks

The key exists at the selector. We query <selector>._domainkey.<domain>, following CNAMEs the way receivers do, and show the record we find.

The key is not revoked. An empty p= tag means the key was revoked on purpose. Mail still signed with it fails DKIM.

Key strength. We estimate the RSA key size from the public key. 1024-bit keys still verify but are considered weak; 2048-bit is the standard.

Common selector scan. Without a selector, we try a short list of common ones in parallel: google, selector1, selector2, k1, s1, default and others.

Where providers publish DKIM

Common DKIM selectors by provider
ProviderTypical selectorRecord type
Google WorkspacegoogleTXT
Microsoft 365selector1, selector2CNAME to Microsoft
Mailchimpk1, k2, k3CNAME
SendGrids1, s2CNAME
Amazon SESRandom tokens3 CNAMEs

How to fix common issues

No key at the selector

Open an email you sent, view the original, and find s= and d= in the DKIM-Signature header. Check that exact selector and domain. If it is missing, copy the record your provider shows again: a common mistake is pasting the full name into a DNS host that already appends the domain.

Key revoked or empty

Your provider rotated keys or the record was cleared. Re-enable DKIM in the provider’s dashboard and publish the new record it gives you.

1024-bit key

Generate a 2048-bit key with your provider, publish it under a new selector, switch signing to it, then remove the old record after a few days.

DKIM passes but DMARC fails

DMARC needs DKIM aligned: the d= domain must match your From domain or its parent. Sign with your own domain instead of the provider’s default.

Frequently asked questions

How do I find my DKIM selector?

Open an email you sent, show the original message or headers, and look for the DKIM-Signature header. The s= value is the selector and d= is the signing domain.

Why does the scan find nothing when DKIM works?

Many providers use custom or random selectors, such as Amazon SES tokens. A scan only covers common names. Enter the selector from your DKIM-Signature header to check it directly.

Is a 1024-bit DKIM key still OK?

It still verifies at major mailbox providers, but it is considered weak. Use a 2048-bit RSA key when your DNS host supports long TXT records.

Can I have several DKIM keys?

Yes. Each sending service signs with its own selector, so a domain can publish many DKIM records side by side.

Does this tool contact my mail server?

No. It reads public TXT records from DNS only, with a timeout on each query.

Related tools and guides

Authenticated sending, set up for you.

3,000 emails a month free. Unlimited subscribers on every plan. Campaigns, automations and transactional email on one domain.