Skip to content

DKIM Checker

Look up and validate a DKIM public key record for a domain and selector.

Leave the selector empty to try 30 common selectors. The selector is the s= value in an email's DKIM-Signature header.

Continue your work

Share this tool

Found it useful? Send it to a friend or teammate.

Rate this tool

0.0

0 ratings

  • 5 stars 0
  • 4 stars 0
  • 3 stars 0
  • 2 stars 0
  • 1 star 0

Click a star to rate this tool

Clear instructions

Find steps, examples and limitations below.

Use online

Open the tool in a supported web browser.

Free to use

No sign-up required. Tool-specific limits may apply.

How to use the DKIM Checker

Look up and validate a DKIM public key record for a domain and selector.

  1. 1 Enter the domain. Add the selector if you know it (it is the s= value in an email’s DKIM-Signature header).
  2. 2 Click Check DKIM. With no selector, common selectors such as google, selector1 and k1 are tried for you.
  3. 3 Review the key checks. RSA keys should be 2048 bits, and t=y testing mode should be removed once you are done.

Example and practical tips

For a Microsoft 365 domain, leave the selector empty: selector1 and selector2 are found automatically. A 1024-bit key is flagged as a warning, so generate a 2048-bit key in the admin centre.

Frequently asked questions

What is a DKIM selector?

A name that lets a domain publish several DKIM keys at selector._domainkey.domain, for example one per email service.

What does an empty p= tag mean?

An empty public key revokes that selector, so messages signed with it fail DKIM.

Report an issue

Something broken or not quite right? Tell us and we will look into it.