Look up the DKIM record for any domain and selector, validate it against current standards, and see exactly what to fix so receiving servers can verify your signatures.
Enter your domain and DKIM selector — or scan the most common selectors.
We query public DNS for the selector and domain you enter. Your input is used only to run this check and is never stored.
The selector is the s= value in the DKIM-Signature header of mail you send. Not sure? Run the common-selector scan instead.
We look up the TXT record at <selector>._domainkey.<domain> and parse it tag by tag against RFC 6376, catching duplicates, bad versions, and revoked keys.
For RSA keys we decode the published key and report its size, flagging anything below the RFC 8301 minimum. Ed25519 keys are validated per RFC 8463.
Validate your SPF record, follow includes, and stay under the 10-lookup limit.
Open toolGenerate a new DKIM key pair in your browser and format the DNS record to publish.
Open toolA DKIM record is a DNS TXT record published at <selector>._domainkey.<yourdomain>. It contains the public key that receiving mail servers use to verify the DKIM signatures your sending service adds to outgoing email, as defined in RFC 6376.
Open a message you sent and view its full headers — the selector is the s= value in the DKIM-Signature header. Your email provider's setup documentation also lists it. If you cannot find it, use this tool's common-selector scan to probe the names most providers use.
The most common causes are a wrong or mistyped selector, a record that has not finished DNS propagation, or a provider that signs with its own domain instead of yours. Confirm the exact selector and hostname your provider shows in its DKIM setup screen.
RFC 8301 requires at least 1024-bit RSA and recommends 2048-bit RSA; keys below 1024 bits must be treated as invalid. Ed25519 (RFC 8463) is a modern alternative where your provider supports it. SHA-1 signing is prohibited.
No. This tool confirms the public key is correctly published in DNS. Your sending service must still attach a DKIM signature to each message, and only a message-level check can confirm that is happening.
An empty p= tag revokes the key for that selector (RFC 6376 §3.6.1). It is how a domain publicly announces the selector is no longer in use — messages signed with it will fail verification.
Automate Sales Outreach & Get Booked!
Start Free Trial(14 Day Free Trial, No CC Required)