DKIM Record Checker
Enter a domain and the DKIM selector to read the published key, check its size and spot a broken or revoked record.
How it works
DKIM adds a digital signature to every email you send. The matching public key lives in DNS at selector._domainkey.yourdomain.com, where the selector is a label your email provider chose. Receivers fetch that key to verify the signature.
The tool reads the TXT record at that name, parses its tags and decodes the key itself to find its real size, then reports anything that would make verification fail: an empty (revoked) key, broken base64, a weak 1024-bit key, testing mode or a wrong tag.
| Tag | Meaning |
|---|---|
v=DKIM1 | Version. Optional, but must come first if present. |
k=rsa | Key type: rsa (default) or ed25519. |
p=… | The public key. Empty means revoked. |
t=y | Testing mode. Remove it once signing works. |
t=s | Applies to this exact domain, not subdomains. |
Not sure of your selector? Open a message you sent and look for s= in the DKIM-Signature header, or paste the whole header into the Email Header Analyzer.
Frequently asked
What is a DKIM selector?
A short label that lets one domain publish several DKIM keys, for example one per email service. It forms part of the DNS name, selector._domainkey.yourdomain.com, and is also written as s= in each message's DKIM-Signature header.
Which selector does my provider use?
It varies: Google Workspace usually uses google, Microsoft 365 uses selector1 and selector2, and many others use default, s1, k1 or their own name. Your provider's setup page lists it, or find s= in a sent message's headers.
What key size should I use?
2048-bit RSA. 1024-bit still works with most receivers but is considered weak. If your DNS host cannot store a 2048-bit key in one record, the key must be split into several quoted strings inside the same TXT record.
What does an empty p= mean?
The key was deliberately revoked. Signatures made with it will fail. Publish a new key under a new selector, rather than editing the old one, when you rotate.
Does a valid record mean my mail is signed?
No. It only proves the public key is published correctly. Your email service still has to be switched on to sign with the matching private key. Send a test message and check its headers.