VMHeaven

Free tool

DKIM record checker

Find a domain's DKIM keys under your selector or nine common ones: key type and size, revoked and testing keys, delegated records and errors that break signing.

Find DKIM keys

The selector is the s= value in the DKIM-Signature header of a mail the domain sent. Without one, the common selectors are tried.

Try:

Read from DNS by our validating resolver in Amsterdam — this check never connects to the domain’s mail servers.

How DKIM works

The sending server signs each message with a private key and adds a DKIM-Signature header naming the signing domain (d=) and the selector (s=). The receiver fetches the public key from selector._domainkey.domain and checks that the signed headers and the body arrived unchanged. Because the signature travels with the message, DKIM survives forwarding, where SPF fails.

Finding the selector in a message

Message headers
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=example.com; s=s1; t=1760140800;
        h=from:to:subject:date:message-id;
        bh=…; b=…

Here the key lives at s1._domainkey.example.com. A message can carry several signatures — one from your domain and one from the provider that sent it; the one whose d= matches your From domain is the one DMARC counts.

Selectors of common providers

ProviderSelectorHow it is published
Google WorkspacegoogleTXT record with the key, generated in the admin console (the prefix can be changed)
Microsoft 365selector1, selector2CNAME records to keys Microsoft hosts for the tenant
Amazon SES (Easy DKIM)three generated namesCNAME records to dkim.amazonses.com
cPaneldefaultTXT record, created with the domain

A key published by CNAME stays with the provider, which can rotate it without you changing DNS; the check follows the CNAME and shows where it leads.

A key for your own server

With OpenDKIM, which most self-hosted setups use alongside Postfix, one command creates the key pair and the DNS record to publish:

Linux
opendkim-genkey -b 2048 -d example.com -s s1
cat s1.txt     # the TXT record for s1._domainkey.example.com
# s1.private is the private key: keep it on the server, readable by opendkim only

Pick a new selector for every new key — a date works well, such as s202610 — so that old and new key can be published side by side while you switch over.

Frequently asked

What is a DKIM selector, and where do I find mine?

The name a domain publishes a DKIM key under: the key for selector s1 of example.com lives at s1._domainkey.example.com. Open the headers of a message you sent (Show original in Gmail, View source in most other programs) and find the DKIM-Signature line: s= is the selector, d= the signing domain.

Why does the check not find my DKIM key?

DNS has no way to list the selectors a domain uses, so without yours the check can only try common names — default, google, selector1, selector2, k1, mail, dkim, s1 and s2. Providers that rotate their keys often use dated selectors instead. Enter the s= value from one of your messages and the key is looked up directly.

What size should a DKIM key be?

2048-bit RSA is the usual choice today. 1024-bit keys still verify but are considered weak, and RFC 8301 tells receivers to reject keys under 1024 bits. A 2048-bit key is longer than one 255-character TXT string, so it is published as several strings in one record; this check joins them, as receivers do.

What does t=y in a DKIM record mean?

The domain is testing DKIM: receivers may treat signed mail as if it were unsigned. Remove the flag once signing works.

How do I rotate a DKIM key?

Publish the new key under a new selector, switch the mail server or provider to sign with it, and leave the old selector in DNS for a few days so that messages still in transit can be verified. Then revoke the old key by publishing it with an empty p= value, or delete the record.

More free tools

All tools