Play Video

Oppora's Claude MCP is Live. Connect our Email Database & Outreach features with any tool to build smart automations inside Claude. Start for Free

DKIM record checker

Enter a domain and, if you know it, the DKIM selector. We check the public key and explain any problems.

Free, no signup. Up to 10 checks per hour.

Leave the selector empty and we try 27 common ones, such as google, selector1 and s1.

How DKIM records work

DKIM (DomainKeys Identified Mail) adds a signature to each message you send. Receivers check it with a public key you publish in DNS.

Selectors point to keys

The public key lives at selector._domainkey.yourdomain.com. The selector is a name your provider picks, so one domain can have a key for each service that sends for it.

Google Workspace uses google by default. Microsoft 365 uses selector1 and selector2, published as CNAME records that point to keys Microsoft hosts.

Reading the key

The p= tag holds the public key. An empty p= means the key was revoked, and mail signed with it fails DKIM.

Key size matters. RFC 8301 requires at least 1024 bits and recommends 2048, and Google gives the same advice. t=y marks a domain that is still testing DKIM.

Fixing common problems

If no key shows up, find your selector in a sent message: view the original and read the s= value in the DKIM-Signature header.

For a 1024-bit key, generate a 2048-bit one in your provider and publish it under a new selector, then switch signing over. If a key is too long for one DNS string, split it into several quoted strings in the same TXT record.

Need more than one check?

Warm up new mailboxes and watch SPF, DKIM, DMARC and blacklists for every inbox you connect. See Email Warmup

Free plan, no credit card

DKIM Checker FAQ

What is a DKIM record?

A DKIM record is a TXT record that publishes the public key receivers use to check the DKIM signature on your mail. It sits at a selector name under _domainkey on your domain.

How do I find my DKIM selector?

Open an email sent from the domain, view the original message or headers, and find the DKIM-Signature line. The value after s= is the selector, and d= is the signing domain.

Why does the checker not find my DKIM record?

Most often the domain uses a selector that is not on our common list. Enter the selector from a sent message header. If that also fails, the key was never published or the record name has a typo.

Should my DKIM key be 1024 or 2048 bits?

Use 2048 bits. Gmail accepts 1024-bit keys, but RFC 8301 and Google both recommend 2048. Some DNS hosts need the longer key split into several strings, which works fine.

What does an empty p= tag mean?

The key has been revoked. Receivers fail any signature made with that selector. That is normal for a selector you retired, but a problem if your mail still uses it.

Does DKIM need to match my From domain?

For DMARC, yes. DMARC passes on DKIM only when the d= domain in the signature matches the From domain, or shares its organizational domain under relaxed alignment.

Let’s Vibe Sales too!