Free DKIM Record Checker

Look up the DKIM record for any domain and selector, validate it against current standards, and see exactly what to fix so receiving servers can verify your signatures.

Check a DKIM record

Enter your domain and DKIM selector — or scan the most common selectors.

The selector is the s= value in the DKIM-Signature header of a message you have sent — your email provider's documentation also lists it.

We query public DNS for the selector and domain you enter. Your input is used only to run this check and is never stored.

How the DKIM checker works

Enter a domain and selector

The selector is the s= value in the DKIM-Signature header of mail you send. Not sure? Run the common-selector scan instead.

We query public DNS

We look up the TXT record at <selector>._domainkey.<domain> and parse it tag by tag against RFC 6376, catching duplicates, bad versions, and revoked keys.

We inspect the public key

For RSA keys we decode the published key and report its size, flagging anything below the RFC 8301 minimum. Ed25519 keys are validated per RFC 8463.

What this tool does and does not tell you

  • This tool validates the DNS record and public key — it does not verify the signature on an actual message.
  • A valid record does not prove your sending service is signing mail; check a sent message's Authentication-Results header for that.
  • The common-selector scan covers only the most frequently used selector names. Finding nothing there is not proof that DKIM is absent — your provider may use a custom selector.
  • Results reflect public DNS at the moment of the check; recent changes may not have propagated yet.
  • A correct DKIM setup improves authentication but does not guarantee inbox placement.

Related free tools

SPF Record Checker

Validate your SPF record, follow includes, and stay under the 10-lookup limit.

Open tool

DMARC Record Checker

Check your DMARC policy, alignment modes, and reporting configuration.

Open tool

DKIM Record Generator

Generate a new DKIM key pair in your browser and format the DNS record to publish.

Open tool

Frequently Asked Questions

What is a DKIM record?

A DKIM record is a DNS TXT record published at <selector>._domainkey.<yourdomain>. It contains the public key that receiving mail servers use to verify the DKIM signatures your sending service adds to outgoing email, as defined in RFC 6376.

How do I find my DKIM selector?

Open a message you sent and view its full headers — the selector is the s= value in the DKIM-Signature header. Your email provider's setup documentation also lists it. If you cannot find it, use this tool's common-selector scan to probe the names most providers use.

The checker found no record, but my provider says DKIM is enabled. Why?

The most common causes are a wrong or mistyped selector, a record that has not finished DNS propagation, or a provider that signs with its own domain instead of yours. Confirm the exact selector and hostname your provider shows in its DKIM setup screen.

What DKIM key size should I use?

RFC 8301 requires at least 1024-bit RSA and recommends 2048-bit RSA; keys below 1024 bits must be treated as invalid. Ed25519 (RFC 8463) is a modern alternative where your provider supports it. SHA-1 signing is prohibited.

Does a valid DKIM record mean my emails are being signed?

No. This tool confirms the public key is correctly published in DNS. Your sending service must still attach a DKIM signature to each message, and only a message-level check can confirm that is happening.

What does an empty p= value mean?

An empty p= tag revokes the key for that selector (RFC 6376 §3.6.1). It is how a domain publicly announces the selector is no longer in use — messages signed with it will fail verification.

Increase Your Sales Right Now

Automate Sales Outreach & Get Booked!

Start Free Trial

(14 Day Free Trial, No CC Required)