Look up the DKIM public key published for a domain and selector. Check the record syntax, key type and strength, and common DNS configuration issues.
Loading tool access...
Every check turns the published key record into a structured report
Check whether the selector resolves to a DKIM TXT record and show the exact hostname, TTL, and DNS response.
Parse the record tags, identify the key type, decode the public key, and calculate the RSA key length where applicable.
Detect missing or malformed tags, unsupported key types, weak RSA keys, multiple records, revoked keys, and DNS lookup failures.
Confirm that the provider’s selector and public key have been published under the correct domain.
Check that the new selector resolves correctly before the sending system begins using its private key.
Look for a missing selector, invalid public key, DNS error, revoked key, or incorrect signing-domain configuration.
For each legitimate signing domain that is intended to align with the visible From domain, confirm that its sending service publishes a usable DKIM key.
The selector tells receivers which public key to fetch when checking a DKIM signature.
The record can reveal invalid or revoked keys, unsupported key types, and weak RSA keys.
The DNS path may show whether the domain hosts the key or delegates it to an email provider.
Check DKIM records with our API.
The sender signs the message body and selected headers with its private key.
DKIM-Signature gives the domain (d=) and selector (s=) for the public key.
The receiver fetches the public key from DNS to verify the signed message is unchanged.
Check DKIM key settings that affect DNS resolution and email delivery.
Use 2048-bit RSA keys for DKIM signing. The minimum allowed RSA key length is 1024 bits.
A new selector lets you publish a replacement public key while existing messages continue to verify.
Remove the selector record or empty its p= value to stop the key from verifying signatures.
The public key may be published under a different selector than the one used to sign outgoing messages
The selector may return NXDOMAIN, an empty answer, a broken CNAME target, or a temporary DNS failure.
The p= value may be malformed, incompatible with the key type, or too short for current security standards.
Changes to signed headers or the message body after signing will cause DKIM verification to fail.
Automate end-to-end email testing with our APIs.