Skip to main content
Free tool

Check a DKIM record

See the DKIM keys a domain publishes, each key's type and length, and anything that would make signatures fail. No account.

Leave the selector empty to try common names. That can miss a key on a custom selector: the s= value in a sent message's DKIM-Signature header is the exact one.

Want DKIM keys you never have to rotate by hand?

Email Digit generates a 2048 bit key for your domain, signs your mail with it, and rotates it behind two records you publish once. We also keep your SPF and DMARC records maintained.

About DKIM records

What a DKIM record does

DKIM signs each message with a private key, and publishes the matching public key in DNS so receivers can check that the message was not changed and that your domain sent it. A DKIM pass on your own domain is what lets DMARC pass even when mail is forwarded.

Key length

The length is read from the key itself, not guessed from the length of the record. 2048 bit RSA is the current recommendation; keys under 1024 bits fail at large mailbox providers.

What the checker looks for

Missing keys, revoked keys (an empty p=), keys left in testing mode, short keys, values that do not decode to a key, a wrong version tag, and two records at one selector.

DKIM record questions

What is a DKIM selector?

A name that says which key signed a message, so a domain can have several keys at once. The key lives at the selector, then _domainkey, then your domain. You can read a message's selector in its DKIM-Signature header, as the s= value.

Why can't the checker find my key?

Without a selector we try a list of common names only. Many services use their own, so a key can exist where we did not look. Enter the s= value from a message you sent to check that exact selector.

Is a 1024 bit key still OK?

It still verifies, but 2048 bits is the current recommendation. Keys under 1024 bits are treated as unsigned or rejected by large mailbox providers.

What does t=y mean?

The key is in testing mode, and receivers may treat signatures made with it as if the message were unsigned. Remove it once signing works.