Free toolAPI available

DKIM record checker

Look up the DKIM public key published for a domain and selector. Check the record syntax, key type and strength, and common DNS configuration issues.

Loading tool access...

interacjohnsoncontrolsapolloverorbimercksalesforceworkdayatlassianpbstoyotaadobemediumcartaoptimizelysapxeroxassabloyenvatophilipstransunioninteracjohnsoncontrolsapolloverorbimercksalesforceworkdayatlassianpbstoyotaadobemediumcartaoptimizelysapxeroxassabloyenvatophilipstransunion

What the DKIM checker analyzes

Every check turns the published key record into a structured report

DNS publication

Check whether the selector resolves to a DKIM TXT record and show the exact hostname, TTL, and DNS response.

Public-key

Parse the record tags, identify the key type, decode the public key, and calculate the RSA key length where applicable.

Configuration issues

Detect missing or malformed tags, unsupported key types, weak RSA keys, multiple records, revoked keys, and DNS lookup failures.

When to check a DKIM record

When enabling a sending service

Confirm that the provider’s selector and public key have been published under the correct domain.

After rotating a DKIM key

Check that the new selector resolves correctly before the sending system begins using its private key.

When DKIM authentication fails

Look for a missing selector, invalid public key, DNS error, revoked key, or incorrect signing-domain configuration.

Before enforcing DMARC

For each legitimate signing domain that is intended to align with the visible From domain, confirm that its sending service publishes a usable DKIM key.

What a DKIM record can tell you

Which key is published

The selector tells receivers which public key to fetch when checking a DKIM signature.

Whether the key is usable

The record can reveal invalid or revoked keys, unsupported key types, and weak RSA keys.

Who manages the selector

The DNS path may show whether the domain hosts the key or delegates it to an email provider.

Get started

Check DKIM records with our API.

How DKIM authentication works

1. The sender signs the email

The sender signs the message body and selected headers with its private key.

2. The signature identifies a key

DKIM-Signature gives the domain (d=) and selector (s=) for the public key.

3. The receiver verifies the signature

The receiver fetches the public key from DNS to verify the signed message is unchanged.

DKIM key security

Check DKIM key settings that affect DNS resolution and email delivery.

Use sufficiently strong keys

Use 2048-bit RSA keys for DKIM signing. The minimum allowed RSA key length is 1024 bits.

Rotate keys with selectors

A new selector lets you publish a replacement public key while existing messages continue to verify.

Revoke compromised keys

Remove the selector record or empty its p= value to stop the key from verifying signatures.

Common DKIM issues

Incorrect selector

The public key may be published under a different selector than the one used to sign outgoing messages

Missing or broken DNS record

The selector may return NXDOMAIN, an empty answer, a broken CNAME target, or a temporary DNS failure.

Invalid or weak public key

The p= value may be malformed, incompatible with the key type, or too short for current security standards.

Message changed after signing

Changes to signed headers or the message body after signing will cause DKIM verification to fail.

Signup for testmail.app

Automate end-to-end email testing with our APIs.

FAQ

What is a DKIM checker?

A DKIM checker looks up and analyzes the public key published for a domain and selector. It checks whether the DNS record exists, whether its tags and key can be parsed, whether the key meets current strength requirements, and whether the record contains errors or warnings. It does not verify a particular email unless the signed message is also analyzed.

How do I check a DKIM record?

Enter the DKIM signing domain and selector into the checker. The tool will query the corresponding selector._domainkey.domain hostname and display the published record, key type, key strength, parsed tags, DNS details, and any configuration issues.

What is a DKIM selector, and where do I find it?

A DKIM selector is a name used to identify the public key for a particular signature. It appears as the s= value in an email’s DKIM-Signature header, while the d= value contains the signing domain. You may also find the selector in your email provider’s domain-authentication settings.

What makes a DKIM record valid?

A valid DKIM record must be published at the correct selector hostname, follow the DKIM key-record format, contain a usable public key, and use a supported key type. An RSA key must be at least 1024 bits, although 2048 bits is recommended. An empty p= value means the key has been revoked.

Why is my DKIM record not found or failing?

A DKIM record may not be found because the selector is incorrect, the record was published under the wrong domain, a DNS change has not appeared yet, or a required CNAME target is missing or broken. DKIM can also fail when the public key is malformed, revoked, unsupported, or different from the key used to sign the email.

How can I check a DKIM record manually?

You can check a DKIM record manually by querying the TXT or CNAME record at selector._domainkey.example.com. Use your DNS provider’s control panel or run a command such as dig TXT selector._domainkey.example.com or nslookup -type=TXT selector._domainkey.example.com. You must know the signing domain and selector before running the lookup.

Does a valid DKIM record mean an email will pass DKIM?

No, a valid DKIM record only confirms that the public key is published and can be interpreted. A particular email can still fail if it uses a different selector, contains an invalid signature, was changed after signing, or cannot be matched to the published key. Verifying an actual message requires its DKIM-Signature header, signed headers, body content, and public key.