Skip to content
Free, no sign-up

DKIM record checker

Check a domain's DKIM keys. Enter a selector if you know it, or we'll look for the common ones used by Microsoft 365, Google Workspace and others.

What this checks

  • The key on your selector, or on common selectors when you don't give one
  • Key type and length: 2048-bit RSA is the standard, 1024-bit is weak
  • Revoked keys (an empty p=) and keys that can't be read
  • Which selectors were tried, so you know what wasn't

An example, explained

TXT record at selector1._domainkey.example.co.uk
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2a…
selector1
The selector: the sending service picks it and puts it in each signature.
k=rsa
The key type. RSA is near universal; ed25519 is newer and rarer.
p=
The public key. Empty means the key has been revoked.

Finding the selector, and what the result means

DKIM signs each email with a private key held by the sending service. Receivers fetch the matching public key from DNS at selector._domainkey. followed by the domain, and check the signature. A domain can have many keys, one per service, each under its own selector.

Finding a selector

There's no way to list every selector a domain has: DNS only answers for names you ask about. Without a selector, we try the common ones: selector1 and selector2 (Microsoft 365), google (Google Workspace), k1, s1, s2, default and mail. That finds most, not all. The surest way is to send one email to our free email test, which reads the selector straight from the signature. You can also open a sent email's headers and look for s= in the DKIM-Signature line.

Common problems

  • No key found: either DKIM isn't set up, or it uses a selector we didn't try. Check with the selector from a real email before assuming the worst.
  • 1024-bit key: still accepted, but 2048-bit is now recommended. Most providers let you rotate to a longer key from their admin page.
  • Revoked key: an empty p= tells receivers to reject signatures with that selector. Fine for an old key; a problem if a service still uses it.

DKIM is what keeps DMARC passing when email is forwarded, so it's worth getting right. More in DKIM explained.

Do this for every client, every day

  • All nine checks on every client domain, daily, graded A to F
  • Alerts by email or webhook when a grade drops or a record changes
  • A monthly report card for each client, with your logo on it
  • Hosted DMARC, SPF, DKIM and MTA-STS, so fixes don't wait for a DNS login

Start a free 28-day trial: up to 3 domains, no card needed.

Questions

How do I find my DKIM selector?

Look at the DKIM-Signature header of an email the domain sent: the selector is the s= value. Or send one email to our free email test, which reads it for you.

Why does the checker say no key was found when DKIM works?

Your service probably uses a selector we don't guess. Enter it in the selector box and check again.

Is a 1024-bit DKIM key safe?

It still works and most receivers accept it, but 2048-bit is now the recommendation. Rotate when your provider allows it.

Microsoft 365 shows CNAME records, not TXT. Is that right?

Yes. Microsoft 365 publishes selector1 and selector2 as CNAMEs pointing at keys Microsoft hosts. The checker follows them to the key.

Can you generate a DKIM key for me?

Not here. Keys come from the service that sends the email, which holds the private half. Hosted DKIM can publish and check the public keys for you.

Check every DKIM key, every day.

Start a free 28-day trial: up to 3 domains, no card needed.