Finding your selector
Each DKIM key lives under a selector name chosen by your email provider. Open an email you sent, view the original message and look for s= in the DKIM-Signature header — that is the selector. Common examples:
| Provider | Typical selectors |
|---|---|
| Google Workspace | |
| Microsoft 365 | selector1, selector2 |
| SendGrid / Mailchimp | s1, s2, k1 |
| Zoho | zoho, zmail |
Leave the selector empty and the checker tries more than 40 common names.
What is checked
- Key type — RSA or Ed25519.
- Key length — 2048-bit RSA is recommended; 1024-bit is considered weak.
- Revoked keys — an empty p= means the key was retired, which is normal after rotation.
- Testing mode — t=y asks receivers not to act on failures.
Frequently asked questions
Why is no DKIM key found?
Your provider probably uses a custom selector. Find it in the DKIM-Signature header of a sent email (s=…) and enter it.
Is a 1024-bit DKIM key safe?
It still works, but 2048-bit keys are recommended. Most providers let you rotate to a 2048-bit key in their DKIM settings.
What does "key revoked" mean?
The record exists but its public key is empty. Providers do this when they rotate to a new selector.

