🔐 DKIM Checker

Validate DKIM (DomainKeys Identified Mail) records to verify email authentication setup and signature configuration.

💡 Tip: Enter domain and DKIM selector, then click "Check DKIM Record".
Enter domain and selector, then click "Check DKIM Record" to view results.

What the check actually looks up

This tool does query live DNS. Pressing Check DKIM Record posts the domain and selector to SimpleMoney's network-tools API, which resolves the TXT record at the selector's _domainkey name and returns what it found:

<selector>._domainkey.<domain>     e.g. selector1._domainkey.example.com

v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A...IDAQAB

You must supply the selector, because DNS gives no way to list them. The selector is the label the sending system stamps into each message's DKIM-Signature header as s=, so the receiver knows which key to fetch. The box defaults to default; Google Workspace typically uses google, Microsoft 365 selector1 and selector2.

Reading the record

v=DKIM1Version. Must come first.
k=rsaKey type. Optional, defaults to RSA; ed25519 also exists.
p=The base64 public key. An empty p= is the revoked-key signal, not a typo.
t=yTesting mode - tells receivers to treat failures leniently. Remove it once you are live.
Finding a valid record proves the key is published, not that your mail is signed correctly. Verification also depends on the private key matching, the signed headers surviving in transit, and forwarders or list servers not rewriting the body.

Frequently asked questions

How do I find my DKIM selector?

Open the raw headers of a message you sent and read the s= value in the DKIM-Signature line. That string is the selector. Your sending platform's DNS setup page lists it too.

Why does the lookup return nothing?

Either the selector is wrong, the record was never published, or the change has not propagated yet. The name must be exactly selector._domainkey.domain - a record placed at the bare domain or at _domainkey alone will not be found.

Is a 1024-bit DKIM key still acceptable?

It verifies, but 2048-bit is the current recommendation and several large providers have said they prefer it. If your key is 1024-bit, rotate to a new selector with a 2048-bit key rather than editing the existing record in place.