🔐 DKIM Checker
Validate DKIM (DomainKeys Identified Mail) records to verify email authentication setup and signature configuration.
What the check actually looks up
This tool does query live DNS. Pressing Check DKIM Record posts the domain
and selector to SimpleMoney's network-tools API, which resolves the TXT record at the
selector's _domainkey name and returns what it found:
<selector>._domainkey.<domain> e.g. selector1._domainkey.example.com
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A...IDAQAB
You must supply the selector, because DNS gives no way to list them. The selector is
the label the sending system stamps into each message's DKIM-Signature
header as s=, so the receiver knows which key to fetch. The box defaults
to default; Google Workspace typically uses google,
Microsoft 365 selector1 and selector2.
Reading the record
v=DKIM1 | Version. Must come first. |
k=rsa | Key type. Optional, defaults to RSA; ed25519 also exists. |
p= | The base64 public key. An empty p= is the revoked-key signal, not a typo. |
t=y | Testing mode - tells receivers to treat failures leniently. Remove it once you are live. |
Frequently asked questions
How do I find my DKIM selector?
Open the raw headers of a message you sent and read the s= value in the
DKIM-Signature line. That string is the selector. Your sending platform's DNS setup
page lists it too.
Why does the lookup return nothing?
Either the selector is wrong, the record was never published, or the change has not
propagated yet. The name must be exactly
selector._domainkey.domain - a record placed at the bare domain or at
_domainkey alone will not be found.
Is a 1024-bit DKIM key still acceptable?
It verifies, but 2048-bit is the current recommendation and several large providers have said they prefer it. If your key is 1024-bit, rotate to a new selector with a 2048-bit key rather than editing the existing record in place.