DKIM Record Checker
Is your DKIM key published, strong enough and usable? Check any selector.
Check a DKIM key
Checking…
DKIM result
About the DKIM Record Checker
DKIM signs each message your domain sends; receivers check the signature with a public key published in DNS at selector._domainkey.yourdomain. If the key is missing, revoked, too short or published with a typo, your signatures fail — and with them DMARC.
Enter your domain and selector to check one key, or leave the selector empty to try 36 common selectors used by Google Workspace, Microsoft 365, Mailchimp, SendGrid, Fastmail, Proton and others. For every key found the checker validates the record’s tags (RFC 6376 §3.6.1), decodes the key in your browser to show its type and size, applies the key-size and hash rules of RFC 8301, and flags revoked keys, testing mode and selectors delegated to a provider by CNAME.
How to use it
- Enter the signing domain — the
d=value of the DKIM-Signature header, usually your From domain. You can also paste a whole DKIM-Signature header, or a name likeselector1._domainkey.example.com. - Enter the selector (the
s=value) if you know it, or leave it empty to try the common ones. - Press Check DKIM. Each key shows its status, type and size, any provider it is delegated to, and every tag explained.
- Fix what the findings point out — for example, replace a 1024-bit key with a 2048-bit one at your provider — then check again.
Examples
github.com
11 selectors found: google, selector1, k1, k2, k3, s1, s2, smtpapi, zendesk1, zendesk2, cm
selector1 points to Microsoft 365, k1–k3 to Mailchimp, s1/s2 to SendGrid and zendesk1/2 to Zendesk — shown from each CNAME.
microsoft.com — selector2
Found — RSA 1024-bit, CNAME to selector2-microsoft-com._domainkey.microsoft.onmicrosoft.com
Microsoft 365 publishes two selectors so it can rotate keys; only one needs to hold a key at a time.
fastmail.com — fm3
Revoked (empty p=): mail signed with this selector fails DKIM
An empty p= is how a key is retired (RFC 6376 §3.6.1).
Common uses
- Confirming that a new provider’s DKIM records were added correctly before you switch on signing.
- Finding which selectors a domain uses before setting up DMARC.
- Checking key sizes: replacing 1024-bit keys with 2048-bit ones.
- Debugging “DKIM: fail (no key)” in a message’s Authentication-Results header.
Finding your selector
Open a message you sent (in Gmail: Show original; in Outlook: View message source) and find the DKIM-Signature: header. d= is the signing domain and s= the selector — paste the whole header into the domain box and the checker reads both. DNS cannot list all selectors of a domain, so scanning common names finds many but never proves that a key does not exist.
Key size and algorithms
- RSA keys must be at least 1024 bits; verifiers must treat signatures with smaller keys as invalid, and signers should use at least 2048 bits (RFC 8301 §3.2). Gmail requires 1024 or more (Google’s sender guidelines).
- Verifiers must support keys up to 4096 bits; larger ones may fail.
- rsa-sha1 must no longer be used (RFC 8301 §3.1): a key record with
h=sha1alone cannot produce a valid signature. - Ed25519 keys (
k=ed25519, RFC 8463) are 32 bytes. For verifiers that do not support them yet, sign with an RSA key under a second selector as well. - A 2048-bit key does not fit in one 255-character DNS string; it is published as several strings that are joined — the checker shows how many.
Revoked keys, testing mode and CNAMEs
- Revoked (
p=empty): the selector is retired; mail still signed with it fails. - Testing (
t=y): RFC 6376 tells verifiers not to treat such mail differently from unsigned mail — remove the flag once signing works. - CNAME delegation: providers such as Microsoft 365, Mailchimp, SendGrid, Fastmail and Proton ask you to point the selector at their DNS, so they can rotate keys themselves. The checker follows the alias and names the provider from the domain it points to.
Sources
- RFC 6376 — DKIM (key records in §3.6.1; tag lists in §3.2). Erratum 3017 notes that
p=may hold a SubjectPublicKeyInfo, the form nearly all signers publish. - RFC 8301 — key sizes and the end of rsa-sha1.
- RFC 8463 — Ed25519 for DKIM.
- Provider selector names were checked on the providers’ own domains; Google Workspace documents “google” as its default selector.
Limitations
- The checker validates the published key; it does not verify a signature on a message. A valid key does not prove your mail is signed with it.
- A scan only tries 36 common selector names — DNS has no way to list the others.
- If a domain answers for every name under _domainkey (a wildcard), the scan shows only selectors whose key differs from the wildcard’s.
- DNS answers can be cached for up to the record’s TTL, so a key you just published may not show yet.
Privacy
Each selector name is looked up from your browser through Cloudflare’s DNS-over-HTTPS resolver (Google’s as a fallback). Keys are decoded and fingerprinted in your browser. MySmartCoPilot’s servers are not involved and store nothing.
Frequently asked questions
Why can’t the checker find my DKIM key?
Most often the selector is different: read it from the s= tag of a sent message’s DKIM-Signature header and enter it. Otherwise the record may be in the wrong place (some DNS panels add the domain again, creating selector._domainkey.example.com.example.com), or a CNAME points to a provider that has not published the key yet because signing is not switched on there.
Should I use a 1024-bit or a 2048-bit key?
2048-bit. RFC 8301 recommends at least 2048 bits, and most providers offer it. 1024-bit keys are still accepted, but they are weaker; use them only if your DNS host cannot store a longer TXT record.
Why are there two selectors such as selector1 and selector2?
For key rotation: the provider signs with one while the other is prepared, then switches. Both names are set up in advance, and the inactive one may point to a record that holds no key yet — as selector1 of microsoft.com did.
Does DKIM alone make DMARC pass?
Only if the signing domain (d=) matches your From domain — the same domain, or under relaxed alignment a subdomain of the same organizational domain. A provider that signs with its own domain gives you a valid signature that does not count for your DMARC. Check your policy with the DMARC record checker.
What does the SHA-256 fingerprint show?
A short hash of the decoded public key. Two selectors with the same fingerprint publish the same key, and a changed fingerprint shows that a key was rotated.