Enter a domain, and a selector if you have one, to look up its DKIM key and test it the way Gmail and Outlook read it: is a key published, what type and size is it, and is it stuck in test mode. Each problem comes with the exact change to make.
Want SPF, DMARC and MX in one go? The free deliverability checker reads all four.
DKIM (DomainKeys Identified Mail) puts a cryptographic signature on every message you send. The matching public key is one TXT record in your DNS, and the receiving server uses it to check that the message really came from your domain and was not altered on the way. A record is a short list of tags:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQ…
The selector is the label in front of ._domainkey. The fastest way to find yours is to send an email from the domain to a Gmail address, open it, choose Show original, and read the s= value in the DKIM-Signature header. Common defaults:
| Sent through | Usual selector |
|---|---|
| Google Workspace | |
| Microsoft 365 | selector1 and selector2 |
| SendGrid | s1 and s2 |
| Mailchimp | k1, k2 and k3 |
Amazon SES and several other services generate a random selector for each domain, so for those the email header is the only reliable place to read it.
Either DKIM is off, or the key is at a selector we did not try. Read the selector from a sent message's header and check again. If there is no DKIM-Signature header, turn DKIM on with your email provider and publish the record it gives you.
A record with t=y asks receivers to treat signed and unsigned mail alike, so you get none of DKIM's benefit while it looks healthy. Remove the t=y flag once you have confirmed signing works.
It still works, but it is the weaker size. Ask your email provider to rotate to a 2048-bit key and publish the new record.
DKIM keys live at your DNS host (Cloudflare, GoDaddy, Namecheap, Route 53), but your email provider generates them. In the provider's admin screen, turn on DKIM signing and copy the record it shows you. Then add it at your DNS host as the type it asks for, usually TXT and sometimes CNAME, with the name selector._domainkey. Changes usually show up within minutes and always within the record's TTL. Run this check again to confirm.
DKIM on its own does not get cold email into the inbox. Gmail and Yahoo also want SPF and a DMARC record, and they judge alignment between all three. The walkthrough in SPF, DKIM and DMARC for cold email has the exact values for Google Workspace and Microsoft 365. Check the other two records with the SPF checker and the DMARC checker.
Enter your domain above, and your DKIM selector if you know it. The checker looks up the TXT record at selector._domainkey.yourdomain.com, tries your selector first and then the ones the major email providers use, and reports the key it finds: its type, its size, and whether it is still in test mode. If you do not know the selector, send yourself an email, view the original message and read the s= value in the DKIM-Signature header.
A selector is a label that says which of your domain's DKIM keys signed a message. The key is published in DNS at selector._domainkey.yourdomain.com. A domain can have many selectors at once, one for each service that sends as it, and the owner chooses the names, so there is no public way to list them. That is why this checker asks for one and also tries the common ones.
Either DKIM is not set up, or the key sits at a selector we did not try. Find the real selector in the DKIM-Signature header of a message you sent (the s= value), enter it above and check again. If the header has no DKIM-Signature at all, your provider is not signing yet and you need to turn DKIM on there and publish the record it gives you.
It works, and receivers still accept it, but 2048-bit is what Google and Microsoft now recommend, and a 1024-bit key is the weaker choice. Ask your email provider to rotate to a 2048-bit key and publish the new record. Some DNS hosts limit how long one TXT value can be, in which case the key has to be split into two quoted strings in the same record.
It marks the key as being in test mode, which asks receivers to treat signed and unsigned mail the same. The record looks healthy but gives you none of DKIM's benefit. Remove t=y once you have confirmed that signing works.
No. Gmail and Yahoo expect SPF, DKIM and a DMARC record together, and DMARC only passes when SPF or DKIM aligns with your From domain. DKIM is the one that survives forwarding, which is why it matters most. Check the other two with the SPF checker and the DMARC checker.
Check any domain's SPF, DKIM, DMARC, and MX records in seconds.
Validate an SPF record: one record, 10-lookup limit, and a safe ending.
Look up a DMARC policy, reporting address, pct and alignment.
Check a domain or mail server IP against Spamhaus, SURBL, URIBL and more.
Scan a subject line and email body for spam-trigger phrases.
Get a day-by-day sending ramp schedule for a new or existing mailbox.
Check text-to-HTML ratio, images, links, and tracking pixels in an email.
Warmerly re-checks SPF, DKIM, DMARC and blocklists on every sending domain daily and warms your mailboxes while it does. Free plan, no card. Paid plans from $19/month.