DKIM Checker
Look up and validate a DKIM public key record for a domain and selector.
Continue your work
- SPF Record Checker — Check SPF for the same domain.
- DMARC Checker — Check the DMARC policy that relies on DKIM.
Share this tool
Found it useful? Send it to a friend or teammate.
Rate this tool
0.0
0 ratings
- 5 stars 0
- 4 stars 0
- 3 stars 0
- 2 stars 0
- 1 star 0
Clear instructions
Find steps, examples and limitations below.
Use online
Open the tool in a supported web browser.
Free to use
No sign-up required. Tool-specific limits may apply.
How to use the DKIM Checker
Look up and validate a DKIM public key record for a domain and selector.
- 1 Enter the domain. Add the selector if you know it (it is the s= value in an email’s DKIM-Signature header).
- 2 Click Check DKIM. With no selector, common selectors such as google, selector1 and k1 are tried for you.
- 3 Review the key checks. RSA keys should be 2048 bits, and t=y testing mode should be removed once you are done.
Example and practical tips
For a Microsoft 365 domain, leave the selector empty: selector1 and selector2 are found automatically. A 1024-bit key is flagged as a warning, so generate a 2048-bit key in the admin centre.
Frequently asked questions
What is a DKIM selector?
A name that lets a domain publish several DKIM keys at selector._domainkey.domain, for example one per email service.
What does an empty p= tag mean?
An empty public key revokes that selector, so messages signed with it fail DKIM.
Report an issue
Something broken or not quite right? Tell us and we will look into it.