Look up a domain’s DKIM public key, validate its syntax and strength, or let us detect common selectors automatically when you do not know yours.
DKIM (DomainKeys Identified Mail, RFC 6376) adds a digital signature to every outgoing message. The sending server signs selected headers and the body with a private key, and the receiving server verifies the signature with the public key published in DNS. A valid signature proves that the message was authorized by the domain and was not changed in transit.
The public key lives in a TXT record at <selector>._domainkey.<domain>. The selector lets a domain publish several keys at once — for example one for Google Workspace and another for a newsletter service.
Open any message sent from your domain, view the original source or full headers and find the DKIM-Signature header. The s= tag contains the selector and d= contains the signing domain. For example, s=google; d=example.com means the key is at google._domainkey.example.com.
If you leave the selector field empty, this checker tries the selectors most often used by popular providers, such as google, selector1 and selector2 (Microsoft 365), k1 (Mailchimp), s1 and s2 (SendGrid) and many more.
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA…
v identifies the record, k sets the key type and p contains the Base64-encoded public key. An empty p= means the key has been revoked.
Use 2048-bit RSA keys. 1024-bit keys are still accepted but are considered weak, and keys shorter than 1024 bits are rejected by Gmail, Outlook and other major providers. Some DNS providers limit a single TXT string to 255 characters; a 2048-bit key is split into several strings, which is normal and handled automatically.
Rotate keys regularly: publish a new key under a new selector, switch signing to it, and revoke the old key by publishing an empty p= value.
A valid DNS record is only half of the picture — your server must also sign messages with the matching private key. Send a message to a free TempBox temporary address and open its headers to confirm that DKIM, SPF and DMARC all pass.
Enter your domain and DKIM selector in the checker above. If you do not know the selector, leave it empty and the tool will test the most common selectors automatically.
A selector is a name that points to a specific DKIM key. Receivers find the key at <selector>._domainkey.<domain>. You can see the selector in the s= tag of the DKIM-Signature header of any message you send.
The most common reasons are a wrong selector, a record added at the wrong DNS name (for example with the domain appended twice), or a change that has not propagated yet. Check the s= and d= tags of a sent message and compare them with your DNS.
It still works, but 2048 bits is the recommended minimum today. Keys shorter than 1024 bits are rejected by major mailbox providers.
An empty p= value means the key has been revoked. Any message signed with the matching private key will fail DKIM verification.
Yes. Each sending service usually has its own selector and key, so a domain can publish many DKIM records under different selectors.
Yes. It is free, requires no registration, and we do not store the domains or selectors you check.