Skip to content

How to Use DKIM Checker

Look up and validate a DKIM record by domain and selector, or try 30 common selectors automatically. Checks key type, key length and test mode.

About this tool

Look up and validate a DKIM public key record for a domain and selector.

How to use DKIM Checker

  1. Enter the domain. Add the selector if you know it (it is the s= value in an email’s DKIM-Signature header).
  2. Click Check DKIM. With no selector, common selectors such as google, selector1 and k1 are tried for you.
  3. Review the key checks. RSA keys should be 2048 bits, and t=y testing mode should be removed once you are done.

Worked example

For a Microsoft 365 domain, leave the selector empty: selector1 and selector2 are found automatically. A 1024-bit key is flagged as a warning, so generate a 2048-bit key in the admin centre.

What is a DKIM selector?

A name that lets a domain publish several DKIM keys at selector._domainkey.domain, for example one per email service.

What does an empty p= tag mean?

An empty public key revokes that selector, so messages signed with it fail DKIM.

Put this guide into practice

  • DKIM Checker — Look up and validate a DKIM public key record for a domain and selector.

Explore DNS Tools · More practical guides

Accessibility Menu

Personalize your experience. Open with Ctrl+U (Option+U on Mac). Preferences stay in this browser when storage is available.

Move / Hide Widget

Restore at any time with Ctrl+U (Option+U on Mac).

Accessibility statement and help