DKIM Record Checker

Look up a domain's DKIM keys. Enter the selector if you know it, or leave it empty to try the selectors common providers use.

  • Free
  • No Sign-Up
  • Live Lookup

Examples:

How to Use

How to use the DKIM Checker

  1. 01

    Enter a domain

    The domain in the d= tag of the DKIM-Signature, usually your email domain.

  2. 02

    Add the selector

    The s= value from a message's DKIM-Signature header. Leave empty to search common selectors.

  3. 03

    Check

    Each key found is shown with its size; SPF and DMARC are checked too.

Email Authentication

About the DKIM Checker

How DKIM works

DKIM signs each outgoing message with a private key held by your mail server. The matching public key sits in DNS at selector._domainkey.yourdomain. The receiver fetches it and checks the signature, which proves the message came through a server you trust and was not changed on the way.

The selector lets a domain have several keys at once: one per provider, or a new one during a key change. That is why you need the selector to find a key; DNS has no way to list them all.

Finding your selector

Open any email you sent, view the original or the full headers, and find the DKIM-Signature header. The s= tag is the selector and d= is the domain. Google Workspace uses google, Microsoft 365 uses selector1 and selector2, and many hosts use default.

Key size

Use 2048-bit RSA keys. 1024-bit keys still validate but are considered weak, and keys below that are rejected by many receivers. An empty p= means the key has been revoked.

What it can't tell you

  • Without the selector it can only try common names; a custom selector will not be found unless you enter it.
  • It checks that the key is published, not that your server is signing with it.

Frequently asked questions

Where do I find my DKIM selector?
In the DKIM-Signature header of an email you sent: the s= tag. Your email provider's DKIM set-up page also shows it.
Can a domain have more than one DKIM key?
Yes, one per selector. Each sending service usually has its own, and keys can be rotated by adding a new selector before removing the old one.
What does DKIM fail mean?
The signature did not match: the key was missing, the message was changed in transit (often by a mailing list or forwarding), or the server signed with a different key from the one published.

Your customers' VMs sending spam?

Frabs spots outbound spam from any VM within seconds and stops it, before your IPs end up on a blocklist.