DKIM Checker

Look up a domain’s email signing key.

Live lookup

DKIM publishes a public key in DNS at selector._domainkey.yourdomain so receivers can verify the signature your mail server adds. A DKIM check fetches that record for a given selector and shows whether a usable key is published.

Start a check

Public internet targets only
No account needed for tools

Results

Ready when you are

Enter your details above and run the tool.

How DKIM Checker works

What it does

Look up a domain’s email signing key.

What you get

The selector’s public signing key and record checks.

Live data sources

The target is sent to a network provider. Results include their source; timeouts and unavailable data are clearly marked.

What if a check cannot finish?

Confirm your input and try again. A timeout, blocked request, or unavailable provider is not proof that a domain is broken. Internet measurements and third-party services have limits.

DKIM Checker — frequently asked questions

What is a selector and where do I find mine?

A label that lets one domain publish several keys. It appears in the s= tag of the DKIM-Signature header on any message you have sent — read it from a received copy.

Why does the lookup find nothing?

Usually the wrong selector, or the record was never published. Check the s= value from a real message and confirm the record sits at selector._domainkey, not on the root domain.

Does a valid key mean my DKIM passes?

No, it means the key is published. A signature can still fail if the message is modified in transit — mailing lists and some forwarders break DKIM routinely.