DKIM record checker

Enter a domain and a selector to read the DKIM public key published at selector._domainkey.domain, or leave the selector blank to try about forty common ones. Free, no sign-up, runs in your browser.

The selector is the s= value in a message's DKIM-Signature header. Common ones: google, selector1/selector2 (Microsoft 365), k1 (Mailchimp), s1/s2 (SendGrid).

How it works

What DKIM proves, and what can go wrong

DKIM (RFC 6376) signs each message with a private key held by the sending server. The matching public key lives in DNS under a selector, a label that lets a domain run several keys at once, one per provider or per rotation. A receiver reads the selector from the signature, fetches the key, and verifies that the signed headers and body arrived unaltered.

Because the key is found by selector, there is no way to ask DNS for "all DKIM keys" of a domain. Auto-detect tries the names providers commonly use; if your platform uses another, take the s= value from a real message's DKIM-Signature header.

p=

The base64 public key. Empty means the key has been revoked and every signature using it fails.

k=

Key type: rsa (default) or ed25519. Ed25519 is strong, but some receivers only verify RSA, so pair it with an RSA key.

Key size

RSA keys under 1024 bits must be rejected (RFC 8301). 1024 still works; 2048 is the current recommendation.

t=y

Testing mode: receivers may treat signatures as if the message were unsigned. Remove it once DKIM works.

h=

Allowed hash algorithms. A record allowing only sha1 is no longer accepted.

CNAME selectors

Many platforms have you publish a CNAME to a key they host, so they can rotate it without asking you to edit DNS.

FAQ

Common questions.

How do I find my DKIM selector?

Open a message you sent and view its original source. In the DKIM-Signature header, d= is the signing domain and s= is the selector. Our header analyzer shows both, with a link back here.

Can a domain have several DKIM keys?

Yes, and most do: one per sending platform (your mailbox provider, your newsletter tool, your help desk), each under its own selector. All of them can be valid at once.

Does DKIM need to match my From domain?

For DMARC, yes. A signature from your platform's own domain (for example sendgrid.net) passes DKIM but does not align with your From domain. Set the platform up to sign as your domain.

Is a 1024-bit key a problem?

Not yet: receivers accept it. But 2048-bit keys are the recommendation, and if the key is yours (not a CNAME to your provider), rotating to 2048 is a quick DNS change.

For agents and pipelines

The same check, as an API and an MCP tool.

Point an MCP client (Claude, Cursor, any agent) at https://powerline.ai/mcp and call check_record, or hit the JSON endpoint directly. No key, no account.

dkim.sh
curl "https://powerline.ai/api/tools/dkim?domain=example.com&selector=google"
More free tools

Keep going.

DMARC Checker

Read the DMARC policy, alignment and reporting tags, and check that report addresses will accept reports.

SPF Checker

Validate the SPF record, follow every include, and count DNS lookups against the limit of 10.

Email Header Analyzer

Trace a message hop by hop, read the receiver's SPF/DKIM/DMARC verdicts and check DMARC alignment.

Email Domain Check

SPF, DKIM, DMARC, MX, MTA-STS, TLS-RPT, BIMI and blacklists in one run, scored out of 100 with a fix list.

Inbox Preview

See how your HTML email actually renders in real Gmail, Outlook.com and Yahoo Mail accounts. Free screenshots.

All email tools