Free DKIM Checker Verify DKIM Records by Selector

DKIM signs your mail cryptographically so receivers can verify it came from you. Enter your domain and selector (check your ESP's docs Google Workspace uses 'google') to verify the public key is published correctly at selector._domainkey.yourdomain.

How this check works

  1. 01

    Queries selector._domainkey.yourdomain for a TXT record.

  2. 02

    Validates the record contains a v=DKIM1 tag and a public key (p=).

  3. 03

    Flags empty keys (p= with nothing, meaning revoked) and reports key length when detectable.

How to fix common problems

Wrong selector

The selector is set by your sending service, not by you. Find it in your ESP's admin panel or in a received email's DKIM-Signature header (s= tag).

Record published but mail unsigned

DKIM must also be enabled in the sending platform. Publishing the DNS record alone does not turn on signing.

Example

Google Workspace: publish the provided TXT at google._domainkey, then click 'Start authentication' in Admin console this checker confirms the DNS side.

FAQ

What is a DKIM selector?
A selector is a label (like 'google' or 's1') that locates your DKIM public key in DNS at selector._domainkey.domain. A domain can have many selectors one per sending service.
How do I find my DKIM selector?
Open a received email from your domain, view headers, and read the s= value in the DKIM-Signature header.
What key length should DKIM use?
2048-bit RSA is the current standard. 1024-bit still passes but is being phased out rotate to 2048 where your ESP allows.

Want this handled end-to-end?

We build and run the whole outbound system infrastructure, lists, and copy live in 10 days.

See the cold email system