DKIM Checker
Look up a domain’s email signing key.
DKIM publishes a public key in DNS at selector._domainkey.yourdomain so receivers can verify the signature your mail server adds. A DKIM check fetches that record for a given selector and shows whether a usable key is published.
Start a check
Public internet targets onlyResults
Ready when you are
Enter your details above and run the tool.
How DKIM Checker works
What it does
Look up a domain’s email signing key.
What you get
The selector’s public signing key and record checks.
Live data sources
The target is sent to a network provider. Results include their source; timeouts and unavailable data are clearly marked.
What if a check cannot finish?
Confirm your input and try again. A timeout, blocked request, or unavailable provider is not proof that a domain is broken. Internet measurements and third-party services have limits.
DKIM Checker — frequently asked questions
What is a selector and where do I find mine?
A label that lets one domain publish several keys. It appears in the s= tag of the DKIM-Signature header on any message you have sent — read it from a received copy.
Why does the lookup find nothing?
Usually the wrong selector, or the record was never published. Check the s= value from a real message and confirm the record sits at selector._domainkey, not on the root domain.
Does a valid key mean my DKIM passes?
No, it means the key is published. A signature can still fail if the message is modified in transit — mailing lists and some forwarders break DKIM routinely.