Free tool

DKIM checker: find the selector, key length and the fix

Enter a domain and, if you know it, the DKIM selector.

Try

Without a selector the checker tries the ones providers document and other common names. Lookups go from your browser to Cloudflare's public DNS resolver.

  • Selectors Google, Microsoft, SendGrid and others document
  • Key length read from the published key
  • Who hosts each key, from its CNAME
  • Where to generate a new key for your provider

About this tool

About the DKIM checker

A working DKIM key is a TXT record (or a CNAME to your provider) at <selector>._domainkey.<domain> with v=DKIM1 and a public key in p=, 2048 bits for RSA. Without a selector the checker tries the ones providers document, such as google for Google Workspace and selector1 and selector2 for Microsoft 365.

For every key found it shows who hosts it, the key type and length read from the key itself, its tags and what to fix. The selector of any email you sent is the s= value in its DKIM-Signature header.

How it works

How to read the DKIM result

DKIM has no single record per domain: each service that signs your mail publishes its own key under its own selector. The checker shows every key it finds; a service whose selector is missing from the list still fails DKIM even when other keys pass.

  • No key found (warning): your provider may use a selector nobody can guess; open a sent email, find s= in the DKIM-Signature header and enter it
  • No key at the selector you entered (error): mail signed with it fails DKIM; publish the record your provider shows
  • 1024-bit key (warning): it passes; 2048 bits is the current recommendation and the default in Google Workspace and Amazon SES
  • Under 1024 bits (error): receivers treat the key as invalid
  • Empty p= (warning): the key was revoked; mail still signed with it fails
  • t=y (warning): testing mode, which lets receivers treat failures as unsigned mail; remove it once signing works
  • A CNAME that points to nothing: the setup in the provider was never finished, or the provider rotated keys; Microsoft 365 publishes selector1 and selector2 and signs with one at a time
  • Keys present and mail still fails: read the Authentication-Results header; the causes are in fixing DKIM signature failures

Background

DKIM selectors by provider

  • Google Workspace: google by default; you can set another prefix in the Admin console (setup steps)
  • Microsoft 365: selector1 and selector2, as CNAME records to Microsoft, the same names in every tenant
  • SendGrid: s1 and s2; Mailchimp: k2 and k3; Mailchimp Transactional: mte1 and mte2; Fastmail: fm1, fm2 and fm3
  • Zoho Mail: you name the selector when you add the key
  • Amazon SES, Postmark, HubSpot and Proton Mail create a unique selector per account; read it from a sent email
  • Every provider value comes from the provider's own documentation, linked in the result

Background

DKIM on cold email domains

DKIM is the record that carries DMARC for cold email: SPF breaks when a message is forwarded, a DKIM signature survives. Gmail and Yahoo require both SPF and DKIM from bulk senders (what cold email domains need).

Check the SPF record and the DMARC policy of the same domain next, or every record with MX in the SPF, DKIM and DMARC checker.

Free guide19 min read

Send 100,000 cold emails a month

Domains and mailboxes you need, DNS, warm-up, lists, copy and follow-ups, with a launch checklist, sent to your inbox.

Unsubscribe in one click.

Questions

How do I find my DKIM selector?

Open an email you sent from the domain, show the original message and find the DKIM-Signature header. The value after s= is the selector and d= is the signing domain. Google Workspace uses google by default; Microsoft 365 uses selector1 and selector2.

How do I check a DKIM record?

Enter the domain and selector above. By hand: dig TXT selector._domainkey.example.com, for example dig TXT google._domainkey.example.com.

Is a 1024-bit DKIM key still OK?

It passes at Gmail, Outlook and Yahoo. 2048 bits is the current recommendation and the default in Google Workspace and Amazon SES. Keys under 1024 bits are treated as invalid.

Can a domain have more than one DKIM key?

Yes. Each service that signs your mail has its own selector and key, and providers rotate between two selectors. Every one of them must be published.

Why does the checker find no DKIM key?

Your provider uses a selector that is not on the common list (Amazon SES, Postmark and HubSpot create unique ones), or DKIM was never set up. Enter the s= value from a sent email to check that selector.

What does an empty p= mean in a DKIM record?

The key is revoked. Mail signed with that selector fails DKIM. Remove the record once no service signs with it.

Does this tool store the domains I check?

No. The lookups go from your browser to Cloudflare's public DNS resolver. We receive nothing unless you ask us to email you the fixes.

In your AI assistant

Run the same checks in Claude or ChatGPT

Free SKILL.md files with the rules behind this tool. Install them in Claude or Claude Code, or paste them into ChatGPT, Gemini, Grok or Cursor.

Mailboxes, warm-up and sending in one place

$2.50 a mailbox a month. DNS records are set for you, and every mailbox shows its warm-up numbers from day one.

Deliverability call

Talk to our deliverability team

Book a call with the people who run our mailbox infrastructure. We look at your current setup and tell you what to change. Running 1,000+ mailboxes? We also quote a volume price below every vendor list price in our comparisons, warm-up and sending included.

  • Review your domains, DNS records and current inbox placement
  • Size the setup: domains, mailboxes per domain and daily volume per mailbox
  • Plan warm-up and the move from your current provider or sequencer
  • 1,000+ mailboxes: a volume price per mailbox for your setup

Free call

See open times in your time zone and book on this page.

Or open the booking page