DKIM checker

Check whether your email is digitally signed. We search the common key names automatically, or you can enter your own.

How the DKIM check works

DKIM keys are published at selector._domainkey.yourdomain, and the selector name is chosen by your email service. Selectors can’t be listed from outside, so we try the names used by the provider we detect (for example selector1 and selector2 for Microsoft 365, google for Google Workspace), plus more than 20 common names used by email platforms. We follow CNAME records to the published key, then check the key type and estimate its length.

What the results mean

  • Key found: your email can be signed. To confirm messages really are signed, paste a message’s headers into the header analyser.
  • Not confirmed: we couldn’t find a key under any common name. Many services, and security gateways such as Proofpoint or Mimecast, use custom names. Enter your selector in the box above to check it directly.
  • Weak key: keys under 1024 bits can be forged and are rejected by some inboxes. Generate a 2048-bit key.
  • Broken key pointer: a CNAME points at a key that no longer exists, often after changing provider.

Finding your selector

Your email service shows it in its DKIM or domain authentication settings. You can also find it in any email you’ve sent: open the message headers and look for s= in the DKIM-Signature line. The d= value in the same line is the domain doing the signing, which should be your own for DMARC to pass. See how DKIM fits with SPF and DMARC.

What is DKIM?

A digital signature added to every email you send. The matching public key is published in your DNS, so inboxes can confirm the message really came from you and wasn’t changed on the way.

What is a selector?

The name your key is published under, such as selector1 for Microsoft 365 or google for Google Workspace. The record lives at selector._domainkey.yourdomain.

Why can’t you find my key?

Some services use custom selector names that can’t be guessed from outside. Your email service shows the selector in its DKIM settings. Enter it above to check that exact key.

Is a 1024-bit key OK?

It still works, but 2048-bit is recommended and is the default for most providers today. Keys shorter than 1024-bit should be replaced.