DKIM record checker
Find a domain’s DKIM keys on common selectors or your own, and check key type, key length and revoked keys. Free DKIM lookup for any domain, no sign-up.
Look up DKIM keys
Enter a domain to probe the DKIM selectors that common email services use. Choose “Know your DKIM selector? Add it” to check your own selector too.
A DKIM key is a TXT record at <selector>._domainkey.yourdomain.com holding the public key receivers use to verify your signatures. DNS has no way to list a domain’s selectors, so a checker can only find keys whose selector it knows or guesses. This one tries the selectors that popular services use, plus any selector you add, and reports the key type, key length and revoked keys.
Why you might need to enter your selector
A DKIM signature names its key with two tags: d= (the signing domain) and s= (the selector). The receiver looks up s._domainkey.d. Every sending service picks its own selector names, and there’s no DNS query that returns “all selectors for this domain”. So the checker probes a list of well-known ones:
| Service | Selectors tried |
|---|---|
| Google Workspace | google |
| Microsoft 365 | selector1, selector2 |
| SendGrid | s1, s2 |
| Mailchimp and Mandrill | k1, k2, k3, mandrill |
| Zoho, Fastmail, Proton | zoho, zmail, fm1–fm3, protonmail… |
| Generic names | default, dkim, mail, key1… |
Some services generate a unique selector for every domain. Amazon SES Easy DKIM, for example, uses three random tokens (CNAMEs to dkim.amazonses.com), and HubSpot adds an account number to its selectors. If the checker says no key was found but you know you set DKIM up, add your selector.
How to find your DKIM selector
- Send a message from the service to a mailbox you can read (Gmail works well).
- Open the raw message: in Gmail, More (three dots) then Show original; in Outlook, View then View message source (or Message details).
- Find the
DKIM-Signature:header. The value afters=is the selector andd=is the domain it signs for.
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=example.com; s=s1; h=from:to:subject:date; bh=…; b=…If d= shows the service’s domain (for example sendgrid.net) instead of yours, the message is signed but not aligned, and it won’t pass DMARC through DKIM. Turn on domain authentication in that service so it signs with your domain. What DKIM is and how it works covers the setup.
Key length, key type and revoked keys
- 2048-bit RSA is the current standard. 1024-bit keys still verify (RFC 8301 sets 1024 as the minimum) but are weak, and the checker flags them so you can rotate. Keys under 1024 bits should be treated as broken.
- Ed25519 (
k=ed25519, RFC 8463) is a newer, shorter key type. Not every receiver verifies it, so RFC 8463 recommends signing with an RSA key as well. - Empty key (
p=) means the key is revoked. That’s normal for an old selector you’ve rotated away from. It’s a problem only if a service still signs with it. - Wildcard keys. A record at
*._domainkeyanswers for every selector. The checker detects it so it doesn’t report fake matches.
DKIM is what keeps mail passing DMARC when it’s forwarded, so it’s worth getting right for every sender. DMARC Dojo’s daily report processing shows which sources pass DKIM with your domain and which don’t. For the full picture, run the DMARC checker or read why DMARC fails.
Frequently asked questions
Why does the checker say no DKIM key was found when DKIM works?
Your service probably uses a selector that isn’t on the common list, such as Amazon SES’s random tokens. Look up the s= value in a message header and add it as your selector. If it still isn’t found, the record may be at the wrong name or not yet propagated.
Can a domain have more than one DKIM key?
Yes. Each sending service uses its own selector, and a service may publish two so it can rotate keys. There’s no limit, and extra selectors don’t affect each other.
Should I use a 1024-bit or 2048-bit DKIM key?
Use 2048-bit whenever your DNS host and email service support it. Some DNS hosts need the longer key split into two quoted strings in one TXT record; most handle that for you.
How do I revoke an old DKIM key?
Stop signing with it first, then publish the selector with an empty key (v=DKIM1; p=) or delete the record. An empty key tells receivers the key is revoked, per RFC 6376 section 3.6.1.
Does DKIM alone make DMARC pass?
DMARC passes if DKIM passes with a d= domain that aligns with your From domain, even when SPF fails. That’s why aligned DKIM is the most reliable way to pass DMARC.