DKIM Record Checker

Find DKIM keys on common selectors or a selector you enter, and check key type and size.

What is DKIM?

DKIM (DomainKeys Identified Mail) adds a cryptographic signature to every email. The matching public key is published in DNS at selector._domainkey.yourdomain, so receivers can verify the message was not forged or altered.

Finding your selector

Each DKIM key lives under a selector name chosen by your email provider. Open an email you sent, view the original message and look for s= in the DKIM-Signature header — that is the selector. Common examples:

ProviderTypical selectors
Google Workspacegoogle
Microsoft 365selector1, selector2
SendGrid / Mailchimps1, s2, k1
Zohozoho, zmail

Leave the selector empty and the checker tries more than 40 common names.

What is checked

  • Key type — RSA or Ed25519.
  • Key length — 2048-bit RSA is recommended; 1024-bit is considered weak.
  • Revoked keys — an empty p= means the key was retired, which is normal after rotation.
  • Testing mode — t=y asks receivers not to act on failures.

Frequently asked questions

Why is no DKIM key found?

Your provider probably uses a custom selector. Find it in the DKIM-Signature header of a sent email (s=…) and enter it.

Is a 1024-bit DKIM key safe?

It still works, but 2048-bit keys are recommended. Most providers let you rotate to a 2048-bit key in their DKIM settings.

What does "key revoked" mean?

The record exists but its public key is empty. Providers do this when they rotate to a new selector.