DKIM selector checker.
Look up a DKIM record. Enter the signing domain and the selector from the s= tag of a message's DKIM-Signature header, and the check reads the public key published at selector._domainkey.domain.
What this check can tell you
With a selector, the result shows the TXT record at that name and what it says about the key: a revoked (empty) key, the key type, an estimated RSA key size, and test mode. Without one, the checker probes eight common selector names and reports the ones that exist. Enter the domain from the d= tag, which can differ from the visible From address.
Limit: Common-selector probing is discovery-only. A probe miss does not prove that your domain has no DKIM record or that a live email failed DKIM.
How to read the DKIM result
Each selector that resolves gets its own block with the record as published and graded findings.
- DKIM record found
- A TXT record exists at
selector._domainkeyand looks like a DKIM key. It is shown in full. With several selectors found, each is listed. - No DKIM record
- Nothing resolved. For a selector you entered, the name or the provider's record is wrong. For probing, only eight common names were tried, so a miss proves nothing about other selectors.
- RSA key size
- Estimated from the length of the
p=value and rounded to a common size. Below 2048 bits warns. Rotate to a 2048-bit key. - Ed25519 key
k=ed25519passes. Publish an RSA selector as well, because not every receiver supports Ed25519.- Empty public key
- Fail. An empty
p=marks the key as revoked, and signatures made with it fail. - Test mode
- Warning when the record has
t=y. Receivers may ignore failures for a selector flagged as testing. Remove the flag once the key is in production.
Find the selector in a real message
Send a message from the service you want to check to an inbox you control, then open its raw source (Gmail calls it Show original). Find the line that starts with DKIM-Signature. Read s=, the selector, and d=, the signing domain. Enter d= as the domain and s= as the selector. A message can carry several signatures, one per signing domain, so check each.
Many services sign with their own domain by default. That passes DKIM but does not align with your From domain, so DMARC cannot use it. Turn on signing with your own domain, then confirm the result with the DMARC checker and a fresh message header.
An annotated DKIM record
A signature with s=mail and d=example.com points receivers at the TXT record below.
mail._domainkey.example.com. TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...IDAQAB"What each part does
mail._domainkey- The selector (
mail), the fixed_domainkeylabel, then the signing domain. v=DKIM1- The version tag. Keep it as the first tag when present.
k=rsa- The key type. RSA is the default when the tag is missing; the other common value is
ed25519. p=- The base64 public key. Receivers use it to verify the signature. Empty means revoked.
t=y- Optional. Not in this example. It flags the selector as testing.
Common DKIM problems and fixes
- No record at the selector
- Copy s= and d= from a real message and check the exact name. Some DNS panels append your domain on their own, so a full name pasted in becomes
mail._domainkey.example.com.example.com. Enter only the part before your domain. - The provider gave you a CNAME
- Some services host the key and ask for a CNAME at the selector. The lookup follows it. Publish the record type the provider gives you.
- Key cut off or malformed
- A 2048-bit key is longer than one 255-character TXT string, so DNS panels split it. Paste the value exactly as given, with no added quotes or line breaks. The checker joins the strings before it reads the key.
- Key under 2048 bits
- Publish a new 2048-bit key under a new selector, switch your sender to it, and retire the old selector after in-flight mail has cleared.
- Record found but mail still fails DKIM
- DNS is only half of DKIM. Confirm the service is signing and uses this selector and domain, then read the Authentication-Results header on a fresh message. The email authentication checker shows SPF and DMARC for the same domain.