What this checker looks at
DKIM lets a receiving mail server verify that a message was really sent — and signed — by your domain. The public half of the signing key lives in DNS at selector._domainkey.yourdomain.com. This tool queries those TXT records, confirms the record parses correctly, verifies the public key is valid base64, estimates the RSA key size and flags common mistakes like test-mode flags, revoked keys and truncated records.
Frequently asked questions
- Where do I find my selector?
- In your mail provider's admin console next to the DKIM setting. Google Workspace uses “google”, Microsoft 365 uses “selector1” and “selector2”. If in doubt, leave the field blank and we try the common ones.
- DKIM passes here but mail still fails DMARC?
- Signing is only half of it — the domain in the DKIM signature must also align with your From: domain. Check alignment with our DMARC generator and make sure the d= domain matches.
- Can a domain have several DKIM records?
- Yes — one per selector, and most domains use several (one per sending service). Rotating keys means publishing a new selector while the old one still verifies.
- Is 1024-bit DKIM still OK?
- It passes verification, but 2048-bit is the current recommendation. Anything at or below 768 bits is considered breakable and must be replaced.
Related free tools
Need a better domain for your project?
Premium names, was $9,999 — now $1,000.