Skip to content
Free email tool

DKIM selector checker.

Look up a DKIM record. Enter the signing domain and the selector from the s= tag of a message's DKIM-Signature header, and the check reads the public key published at selector._domainkey.domain.

Leave it blank to discover common selectors. A miss does not prove your domain has no DKIM record.

What this check can tell you

With a selector, the result shows the TXT record at that name and what it says about the key: a revoked (empty) key, the key type, an estimated RSA key size, and test mode. Without one, the checker probes eight common selector names and reports the ones that exist. Enter the domain from the d= tag, which can differ from the visible From address.

Limit: Common-selector probing is discovery-only. A probe miss does not prove that your domain has no DKIM record or that a live email failed DKIM.

How to read the DKIM result

Each selector that resolves gets its own block with the record as published and graded findings.

DKIM record found
A TXT record exists at selector._domainkey and looks like a DKIM key. It is shown in full. With several selectors found, each is listed.
No DKIM record
Nothing resolved. For a selector you entered, the name or the provider's record is wrong. For probing, only eight common names were tried, so a miss proves nothing about other selectors.
RSA key size
Estimated from the length of the p= value and rounded to a common size. Below 2048 bits warns. Rotate to a 2048-bit key.
Ed25519 key
k=ed25519 passes. Publish an RSA selector as well, because not every receiver supports Ed25519.
Empty public key
Fail. An empty p= marks the key as revoked, and signatures made with it fail.
Test mode
Warning when the record has t=y. Receivers may ignore failures for a selector flagged as testing. Remove the flag once the key is in production.

Find the selector in a real message

Send a message from the service you want to check to an inbox you control, then open its raw source (Gmail calls it Show original). Find the line that starts with DKIM-Signature. Read s=, the selector, and d=, the signing domain. Enter d= as the domain and s= as the selector. A message can carry several signatures, one per signing domain, so check each.

Many services sign with their own domain by default. That passes DKIM but does not align with your From domain, so DMARC cannot use it. Turn on signing with your own domain, then confirm the result with the DMARC checker and a fresh message header.

An annotated DKIM record

A signature with s=mail and d=example.com points receivers at the TXT record below.

Example DKIM record
mail._domainkey.example.com.  TXT  "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...IDAQAB"

What each part does

mail._domainkey
The selector (mail), the fixed _domainkey label, then the signing domain.
v=DKIM1
The version tag. Keep it as the first tag when present.
k=rsa
The key type. RSA is the default when the tag is missing; the other common value is ed25519.
p=
The base64 public key. Receivers use it to verify the signature. Empty means revoked.
t=y
Optional. Not in this example. It flags the selector as testing.

Common DKIM problems and fixes

No record at the selector
Copy s= and d= from a real message and check the exact name. Some DNS panels append your domain on their own, so a full name pasted in becomes mail._domainkey.example.com.example.com. Enter only the part before your domain.
The provider gave you a CNAME
Some services host the key and ask for a CNAME at the selector. The lookup follows it. Publish the record type the provider gives you.
Key cut off or malformed
A 2048-bit key is longer than one 255-character TXT string, so DNS panels split it. Paste the value exactly as given, with no added quotes or line breaks. The checker joins the strings before it reads the key.
Key under 2048 bits
Publish a new 2048-bit key under a new selector, switch your sender to it, and retire the old selector after in-flight mail has cleared.
Record found but mail still fails DKIM
DNS is only half of DKIM. Confirm the service is signing and uses this selector and domain, then read the Authentication-Results header on a fresh message. The email authentication checker shows SPF and DMARC for the same domain.

DKIM questions

Related Resources