Enter a domain and a selector to read the DKIM public key published at selector._domainkey.domain, or leave the selector blank to try about forty common ones. Free, no sign-up, runs in your browser.
DKIM (RFC 6376) signs each message with a private key held by the sending server. The matching public key lives in DNS under a selector, a label that lets a domain run several keys at once, one per provider or per rotation. A receiver reads the selector from the signature, fetches the key, and verifies that the signed headers and body arrived unaltered.
Because the key is found by selector, there is no way to ask DNS for "all DKIM keys" of a domain. Auto-detect tries the names providers commonly use; if your platform uses another, take the s= value from a real message's DKIM-Signature header.
p=The base64 public key. Empty means the key has been revoked and every signature using it fails.
k=Key type: rsa (default) or ed25519. Ed25519 is strong, but some receivers only verify RSA, so pair it with an RSA key.
RSA keys under 1024 bits must be rejected (RFC 8301). 1024 still works; 2048 is the current recommendation.
t=yTesting mode: receivers may treat signatures as if the message were unsigned. Remove it once DKIM works.
h=Allowed hash algorithms. A record allowing only sha1 is no longer accepted.
Many platforms have you publish a CNAME to a key they host, so they can rotate it without asking you to edit DNS.
Open a message you sent and view its original source. In the DKIM-Signature header, d= is the signing domain and s= is the selector. Our header analyzer shows both, with a link back here.
Yes, and most do: one per sending platform (your mailbox provider, your newsletter tool, your help desk), each under its own selector. All of them can be valid at once.
For DMARC, yes. A signature from your platform's own domain (for example sendgrid.net) passes DKIM but does not align with your From domain. Set the platform up to sign as your domain.
Not yet: receivers accept it. But 2048-bit keys are the recommendation, and if the key is yours (not a CNAME to your provider), rotating to 2048 is a quick DNS change.
Point an MCP client (Claude, Cursor, any agent) at https://powerline.ai/mcp and call check_record, or hit the JSON endpoint directly. No key, no account.
curl "https://powerline.ai/api/tools/dkim?domain=example.com&selector=google"
Read the DMARC policy, alignment and reporting tags, and check that report addresses will accept reports.
Validate the SPF record, follow every include, and count DNS lookups against the limit of 10.
Trace a message hop by hop, read the receiver's SPF/DKIM/DMARC verdicts and check DMARC alignment.
SPF, DKIM, DMARC, MX, MTA-STS, TLS-RPT, BIMI and blacklists in one run, scored out of 100 with a fix list.
See how your HTML email actually renders in real Gmail, Outlook.com and Yahoo Mail accounts. Free screenshots.