DKIM checker: find and test your DKIM keys

Look up your DKIM public keys and check their length and format. Enter a selector, or let us try the names common email providers use.

Enter a domain name or an email address, then run the check. Results appear after the form and are announced when they finish.

DKIM options

Reads public DNS records only.

How it works

Find and test your DKIM keys

Check that the public keys behind your email signatures are published, readable and strong enough.

Enter your domain

Add your selector if you know it. Otherwise we try over 30 selector names used by common email providers.

We look up the key

The checker reads the key at selector._domainkey.yourdomain and checks its format and length.

See what to fix

Every key found is listed with its type and length, and any problem is explained.

Common selectors

Where providers store their keys

The selector is the s= value in the DKIM-Signature header of your email.

Google Workspace

Usually google.

Microsoft 365

selector1 and selector2.

Hostinger

hostingermail-a and similar names.

Mailchimp and Mandrill

k1, k2 and k3.

SendGrid

s1 and s2.

Others

Zoho, Mailjet, Brevo, Fastmail, Proton and more are tried automatically.

Good to know

Getting DKIM right

01

Use 2048-bit keys

Shorter keys are weaker, and keys under 1024 bits are rejected by many receivers.

02

One key per sending service

Each service that sends for you (mailbox, newsletter, CRM) should sign with its own key and selector.

03

Confirm with a real email

A published key does not prove your emails are signed. Send one to the mail tester to check the signature.

More email tools

Check the rest of your email setup

Domain scanner

SPF, DKIM, DMARC, BIMI, mail servers and blocklists in one scan.

SPF checker

Check your SPF record, its includes and the 10-lookup limit.

DMARC checker

See your DMARC policy, report addresses and next step.

BIMI checker

Check your logo record, SVG file and certificate.

Mail tester

Send one email and get a spam score out of 10.

Questions

DKIM, explained

Something else? Get in touch and we’ll answer.

DKIM (DomainKeys Identified Mail) adds a digital signature to every email you send. The receiving server checks it against the public key in your DNS, which proves the message came from your domain and was not changed.

The name under which a key is stored, for example google or selector1. You find it as the s= value in the DKIM-Signature header of any email you sent.

2048 bits is the recommended length. 1024-bit keys still work but are weaker, and shorter keys are rejected by many receivers.

It means the key is published correctly. To check that your emails are actually signed with it, send one to the mail tester.

Try it

Are your emails signed?

Check your DKIM keys now, then confirm with a real email.