DKIM Checker
Check a DKIM selector for a sending domain, follow common CNAME setups, find missing or revoked keys, and learn what to fix in DNS or in your email delivery service.
Start Here
Enter a domain and DKIM selector and run DKIM Checker.
Review the DKIM Checker Result
Review the status, warnings, and recommended actions shown in the result panel.
Ready When You Are
Run DKIM Checker to see the DKIM Checker result and next actions.
About DKIM Checker
DKIM adds a cryptographic signature to outgoing email. The receiving inbox uses a public key in DNS to check that the message was signed by a trusted sender and was not changed after signing. The DKIM checker reviews the selector and domain you enter, then explains whether the matching public key record is present and usable. The DKIM guide explains how selectors, keys, and email delivery services fit together.
DKIM problems are often fixable once you know which selector is being used. Some senders publish the wrong selector, leave the key empty, keep a short old key, or forget that a new email delivery service uses its own DKIM records. When DKIM is repaired, also check DMARC Alignment, because the signing domain must line up with your visible From domain for DMARC to trust it.
What DKIM Checker Checks
- Selector TXT lookup at selector._domainkey.domain
- Common selector scan when selector is blank
- Provider CNAME follow-up lookup
- Missing, empty, or revoked DKIM keys
- Test-mode and short-key warnings
- Plain-English DKIM fix steps
Questions
What is a DKIM selector?
A selector is the short name before ._domainkey in a DKIM DNS record. Providers use the selector to tell inboxes which public key to use for signature checks.
Can this scan every possible DKIM selector?
No. Selectors are arbitrary. The DKIM checker reviews the selector you enter and can try common names, but the selector shown by your email delivery service is the reliable source.