DKIM record checker
Enter your domain and, if you know it, your DKIM selector. With no selector, we try the selectors that common providers use.
Finding your DKIM selector
Open an email you sent from the domain, view the original message or headers, and find the DKIM-Signature line. The value after s= is the selector, and d= is the signing domain. The key lives at <selector>._domainkey.<domain>.
Common selectors: google (Google Workspace), selector1 and selector2 (Microsoft 365), s1 and s2 (SendGrid), k1 (Mailchimp), fm1 to fm3 (Fastmail), protonmail (Proton Mail).
What we flag
A missing key. An empty p= value, which means the key was revoked. RSA keys under 1024 bits, which major receivers reject. We also note 1024-bit keys, since 2048-bit is the current recommendation.
Monitor it instead of checking by hand
Get an email if your DKIM key goes missing after a DNS change. Plans from $9/month after a 14-day free trial. No card to start.
Questions
Can you list all DKIM selectors for a domain?
No one can. DNS has no way to list them, so any tool can only try known names. That is why the selector box exists.
My provider gave me CNAME records, not TXT. Is that OK?
Yes. Microsoft 365, SendGrid, Fastmail, Proton and Amazon SES publish DKIM as CNAMEs that point at a key they host and rotate. The lookup follows the CNAME.
More free checks
- Email domain health check
- SPF record checker
- SPF “too many DNS lookups” checker
- DMARC record checker
- MX record lookup
- SSL certificate expiry checker
- SPF record generator
- DMARC record generator